Report #5311 check_circle

  • Creation Date: Nov. 21, 2019, 5:42 p.m.
  • Last Update: Nov. 21, 2019, 5:52 p.m.
  • File: 002
  • Results:
Binary
DLL
False cancel
Size
165.00KB
trid
50.8% Win32 Executable MS Visual C++
21.3% Windows screen saver
10.7% Win32 Dynamic Link Library
7.3% Win32 Executable
3.3% OS/2 Executable
type
PE
wordsize
32
Subsystem
Windows GUI
Hashes
md5
27cd0ab02b1244188ede241ea1e087f5
sha1
19f150d1615da6b79d120cbc6fb857b0a8577c40
crc32
0x28ff4411
sha224
119f5fc3976f40e3ca8d6c23b14c1baaaf0d0662cfc21b3fb1660cd8
sha256
defdfb21f88faa2c9c674737742f28c620c8939acd51ea237bfd54ac4a7d6656
sha384
c314d23a1eb2a7b6fddd122f33402354f29e94f9806434637df8a1d6228a62c77bde52b8d3b16530a8f62f616608bdba
sha512
803ab429ddb123392ff8db0b0b9b2987b1092935172d0999d6ea4984cae7f5a9b2b5ef703e82f17c0c7b7d2e808e4caf3138c0f2228c654f4d4169cca8ffd55d
ssdeep
3072:E9HnBQqT54fdN7GHw32q59Bu8yB7kiPBPjGENdR7roi8Yweas1p:E9HnBQqmLZ2qrBY7LjGk/7romgsX
Community
Google
True check_circle
HashLib
False cancel
YARA
Matches
VC8_Microsoft_Corporation, domain, contentis_base64, anti_dbg, VM_Generic_Detection, IP, url, IsWindowsGUI, win_mutex, Microsoft_Visual_Cpp_8, win_registry, Advapi_Hash_API, win_files_operation, IsPE32, HasRichSignature

Suspicious
True check_circle

Strings
List
http://timenowis1.top/E32HGDGFD65.exe
http://timenowis1.top/E976HDGFD65.exe
_NT.download
{"algo": "cryptonight","api": {"port": 0,"access-token": null,"id": null,"worker-id": null,"ipv6": false, "restricted": true },"asm": true, "autosave": false,"av": 1,"background": true,"colors": false,"cpu-affinity": null,"cpu-priority": null, "donate-level": 1, "huge-pages": null,"hw-aes": null, "log-file": "CN39KPIMASK" ,"max-cpu-usage": 55,"pools": [ { "url": "51.68.28.138:8080", "user": "4476TbUZa5cffKCzE6njxZBMUudCbsuvSVt7Woy23SKajYZibqwCPD8f3EYS8pXBimUzjkfXu7v4oJCoN1ry9GfsTWgkyEt","pass": "NtCall:", "rig-id": null,"nicehash": true, "keepalive": true, "variant": -1,"tls": false,"tls-fingerprint": null }],"print-time": 20,"retries": 5,"retry-pause": 5,"safe": true,"threads": null,"user-agent": null,"watch": false}
/wvyahs/nhaldhf/jvtthuk/pukle.wow
_NT.au
/wvyahs/nhaldhf/mllkihjr/pukle.wow
/wvyahs/nhaldhf/hspcl/pukle.wow
%sconfig.json
%AppData%
Software\microsoft\windows\currentversion\explorer\advanced\folder\superhidden
Aptluvdpz4.avw
Netapi32.dll
WAdvapi32.dll
Wininet.dll
Urlmon.dll
_HttpSendRequestA Failed with Error Code [%d]
MSASCuiL.exe
_HttpOpenRequestA Failed with Error Code [%d]
]eventvwr.exe
NT99KPIMASK.exe
HARDWARE\DESCRIPTION\System\CentralProcessor\0
HARDWARE\DESCRIPTION\System\CentralProcessor\0
Activated by Admin
SOFTWARE\Microsoft\Windows NT\CurrentVersion
Failed to (InternetOpenA) [%d]
Failed to (InternetConnectA) [%d]
No such process
No such device or address
Detected by AV
/c Taskkill /PID %d /F & del /A:H %s > nul
Too many open files in system
Too many links
Too many open files
Result too large
No such device
Resource device
OERR.1 [%d]
ERR.2 [%d]
Failed to CreateProcess(Miner) [%d]
Operation not permitted
Failed to (InternetConnectA) with code [%d]
Failed to (InternetOpenA) with code [%d]
Software\Microsoft\EngineIndicator\
Dpukvdz-ZlhyjoLunpull.lel
Http()
_HttpPost()
HttpSendRequestA
HttpOpenRequestA
mscoree.dll
<requestedPrivileges>
GetShortPathNameW Failed with error code [%d]
Miner Thread()
- abort() has been called
IsProcessorFeaturePresent
GetProcAddress
I succeed with CopyFileW, But i cannot Run_Process with error code [%d]
COMSPEC
Main Folder not Exist, also i failed to CreateDirectoryW with Error code [%d], Home Path: [%ws]
Exe is already in Target Path, But not able to Run_Process with error code [%d]
GetModuleFileNameW Failed with error code [%d]
ExitProcess
_RegCreateKeyExW_ Failed with error code [%d]
_RegSetValueExW_ Failed with error code [%d]
Process32FirstW
tWSSh
Process32NextW
Error: Cannot create connection thread with code [%d]
PSSh
PSSh
IsDebuggerPresent
OpenProcess
TerminateProcess
CreateProcessW
ShellExecuteW
ShellExecuteExW
Permission denied
&SHA18=
&SHA17=
&SHA10=
&SHA13=
&SHA16=
&SHA15=
&SHA12=
&SHA11=
&SHA14=
InternetReadFile
CreateMutexW
CreateDirectoryW
RegSetValueExA
RegCreateKeyExA
RegQueryValueExA
HeapCreate
TerminateThread
SetFilePointer
QueryPerformanceCounter
WriteFile
GetModuleFileNameW
DeleteFileW
GetModuleHandleW

Foremost
Matches
0.exe, 165 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: True check_circle
Allowed: 51.68.28.138, 1, gnosis.systems.
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

URLs
Allowed
hasURLs: True check_circle
Suspicious: http://timenowis1.top/e32hgdgfd65.exe, http://timenowis1.top/e976hdgfd65.exe
hasAllowed: False cancel
hasSuspicious: True check_circle

Files
Allowed: Shell32.dll, Kernel32.dll, WAdvapi32.dll, Urlmon.dll, Netapi32.dll, Wininet.dll, WUSER32.DLL, Shlwapi.dll, mscoree.dll, ADVAPI32.dll, USER32.dll
hasFiles: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 37888
Suspicious: False cancel
Image
Address: 4194304
Suspicious: False cancel
Stack
Stack: 4096
Suspicious: False cancel
Headers
Headers: 4096
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 0
Suspicous: True check_circle

Sections
Allowed: .text, .rdata, .data, .rsrc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 5
Suspicious: False cancel
Image
Version: True check_circle
Suspicious: 5
Linker
Version: 10.0
Suspicious: False cancel
Subsystem
Version: 5.1
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 58975
Suspicious: False cancel

Anomalies
Anomalies: The header checksum and the calculated checksum do not match.
hasAnomalies: True check_circle

Libraries
Allowed: shell32.dll, kernel32.dll, urlmon.dll, netapi32.dll, wininet.dll, shlwapi.dll, mscoree.dll, advapi32.dll, user32.dll
hasLibs: True check_circle
Suspicious: wadvapi32.dll, wuser32.dll
hasAllowed: True check_circle
hasSuspicious: True check_circle

Timestamp
Past: False cancel
Valid: True check_circle
Value: 2018-11-04 18:53:13
Future: False cancel

Compilation
Packed: False cancel
Missing: False cancel
Packers
Compiled: True check_circle
Compilers: Microsoft Visual C++ 8, VC8 -> Microsoft Corporation

Obfuscation
XOR: False cancel
Fuzzing: True check_circle

PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
pushret
.data: 1
.text: 3

pushpopmath
.text: 5
.rdata: 7

garbagebytes
.data: 1
.text: 3

stealthimport
.rdata: 1

programcontrolflowchange
.data: 1
.text: 3

cpuinstructionsresultscomparison
.data: 1

AVclass
cerber
1
VirusTotal
md5
27cd0ab02b1244188ede241ea1e087f5
sha1
19f150d1615da6b79d120cbc6fb857b0a8577c40
SCANS
AVG
result: Win32:Malware-gen
update: 20191020
version: 18.4.3895.0
detected: True check_circle

CMC
update: 20190321
version: 1.1.0.977
detected: False cancel

MAX
result: malware (ai score=100)
update: 20191020
version: 2019.9.16.1
detected: True check_circle

APEX
result: Malicious
update: 20191019
version: 5.75
detected: True check_circle

Bkav
update: 20191018
version: 1.3.0.10239
detected: False cancel

K7GW
result: Trojan ( 004889a31 )
update: 20191010
version: 11.72.32236
detected: True check_circle

ALYac
result: Trojan.Agent.Miner
update: 20191020
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:Malware-gen
update: 20191020
version: 18.4.3895.0
detected: True check_circle

Avira
update: 20191020
version: 8.3.3.8
detected: False cancel

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cyren
result: W32/Trojan.WOOS-1680
update: 20191020
version: 6.2.2.2
detected: True check_circle

DrWeb
result: Trojan.MulDrop8.58100
update: 20191020
version: 7.0.41.7240
detected: True check_circle

GData
result: Gen:Variant.Ransom.Cerber.324
update: 20191020
version: A:25.23726B:26.16353
detected: True check_circle

Panda
result: Trj/CI.A
update: 20191019
version: 4.6.4.2
detected: True check_circle

VBA32
update: 20191018
version: 4.2.0
detected: False cancel

Zoner
update: 20191020
version: 1.0.0.1
detected: False cancel

ClamAV
result: Win.Coinminer.Generic-7151253-0
update: 20191019
version: 0.102.0.0
detected: True check_circle

Comodo
result: Malware@#2yrl05rl5pez6
update: 20191020
version: 31624
detected: True check_circle

F-Prot
update: 20191020
version: 4.7.1.166
detected: False cancel

Ikarus
result: Trojan.Win32.Crypt
update: 20191019
version: 0.1.5.2
detected: True check_circle

McAfee
result: GenericRXGO-MJ!27CD0AB02B12
update: 20191020
version: 6.0.6.653
detected: True check_circle

Rising
result: Dropper.Generic!8.35E (TFE:5:iuGN0bZsk4M)
update: 20191020
version: 25.0.0.24
detected: True check_circle

Sophos
result: Generic PUA BJ (PUA)
update: 20191020
version: 4.98.0
detected: True check_circle

Yandex
result: Trojan.Agent!fTrC+xMVKkg
update: 20191018
version: 5.5.2.24
detected: True check_circle

Zillya
result: Trojan.Generic.Win32.316010
update: 20191018
version: 2.0.0.3929
detected: True check_circle

Acronis
result: suspicious
update: 20191018
version: 1.1.1.58
detected: True check_circle

Alibaba
result: Trojan:Win32/BitMiner.dc4e0e1e
update: 20190527
version: 0.3.0.5
detected: True check_circle

Arcabit
result: Trojan.Ransom.Cerber.324
update: 20191020
version: 1.0.0.859
detected: True check_circle

Cylance
result: Unsafe
update: 20191020
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (high confidence)
update: 20190918
version: 3.0.15
detected: True check_circle

FireEye
result: Generic.mg.27cd0ab02b124418
update: 20191020
version: 29.7.0.0
detected: True check_circle

TACHYON
update: 20191020
version: 2019-10-20.01
detected: False cancel

Tencent
update: 20191020
version: 1.0.0.1
detected: False cancel

ViRobot
update: 20191019
version: 2014.3.20.0
detected: False cancel

Webroot
result: PUA.Gen
update: 20191020
version: 1.0.0.403
detected: True check_circle

eGambit
result: Unsafe.AI_Score_58%
update: 20191020
version: v5.0.6
detected: True check_circle

Ad-Aware
result: Gen:Variant.Ransom.Cerber.324
update: 20191020
version: 3.0.5.370
detected: True check_circle

AegisLab
update: 20191020
version: 4.2
detected: False cancel

Emsisoft
result: Gen:Variant.Ransom.Cerber.324 (B)
update: 20191020
version: 2018.12.0.1641
detected: True check_circle

F-Secure
update: 20191020
version: 12.0.86.52
detected: False cancel

Fortinet
result: W32/Kryptik.GMGV!tr
update: 20191020
version: 5.4.247.0
detected: True check_circle

Invincea
result: heuristic
update: 20190904
version: 6.3.6.26157
detected: True check_circle

Jiangmin
result: RiskTool.BitMiner.bkll
update: 20191020
version: 16.0.100
detected: True check_circle

Kingsoft
update: 20191020
version: 2013.8.14.323
detected: False cancel

Paloalto
result: generic.ml
update: 20191020
version: 1.0
detected: True check_circle

Symantec
result: PUA.Gen.2
update: 20191019
version: 1.11.0.0
detected: True check_circle

Trapmine
update: 20190826
version: 3.1.81.800
detected: False cancel

AhnLab-V3
update: 20191019
version: 3.16.3.25410
detected: False cancel

Antiy-AVL
result: RiskWare[RiskTool]/Win32.BitMiner
update: 20191020
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: not-a-virus:HEUR:RiskTool.Win32.BitMiner.gen
update: 20191020
version: 15.0.1.13
detected: True check_circle

Microsoft
result: Trojan:Win32/Occamy.C
update: 20191020
version: 1.1.16500.1
detected: True check_circle

Qihoo-360
result: Win32/Trojan.Ransom.704
update: 20191020
version: 1.0.0.1120
detected: True check_circle

ZoneAlarm
result: not-a-virus:HEUR:RiskTool.Win32.BitMiner.gen
update: 20191020
version: 1.0
detected: True check_circle

Cybereason
result: malicious.02b124
update: 20190616
version: 1.2.449
detected: True check_circle

ESET-NOD32
result: a variant of Win32/Agent.TKP
update: 20191020
version: 20209
detected: True check_circle

TrendMicro
result: Coinminer_MALREP.THAAAEAH
update: 20191020
version: 11.0.0.1006
detected: True check_circle

BitDefender
result: Gen:Variant.Ransom.Cerber.324
update: 20191020
version: 7.2
detected: True check_circle

CrowdStrike
result: win/malicious_confidence_100% (D)
update: 20190702
version: 1.0
detected: True check_circle

K7AntiVirus
result: Trojan ( 004889a31 )
update: 20191020
version: 11.73.32320
detected: True check_circle

SentinelOne
result: DFI - Suspicious PE
update: 20190807
version: 1.0.31.22
detected: True check_circle

Avast-Mobile
update: 20191012
version: 191012-04
detected: False cancel

Malwarebytes
result: Trojan.Downloader
update: 20191020
version: 2.1.1.1115
detected: True check_circle

TotalDefense
update: 20191020
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
result: Trojan.Wacatac
update: 20191019
version: 14.00
detected: True check_circle

NANO-Antivirus
result: Trojan.Win32.Kryptik.fkcexs
update: 20191020
version: 1.0.134.24859
detected: True check_circle

MicroWorld-eScan
result: Gen:Variant.Ransom.Cerber.324
update: 20191020
version: 14.0.297.0
detected: True check_circle

SUPERAntiSpyware
update: 20191019
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
result: GenericRXGO-MJ!27CD0AB02B12
update: 20191019
version: v2017.3010
detected: True check_circle

TrendMicro-HouseCall
result: Coinminer_MALREP.THAAAEAH
update: 20191020
version: 10.0.0.1040
detected: True check_circle

total
69
sha256
defdfb21f88faa2c9c674737742f28c620c8939acd51ea237bfd54ac4a7d6656
scan_id
defdfb21f88faa2c9c674737742f28c620c8939acd51ea237bfd54ac4a7d6656-1571543260
resource
27cd0ab02b1244188ede241ea1e087f5
positives
51
scan_date
2019-10-20 03:47:40
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Windows\Globalization\Sorting\SortDefault.nls
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\malware.exe
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\malware.exe
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\malware.exe
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Read1480C:\malware.exeC:\malware.exe
21/11/2019 - 16:45:54.668Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Read1480C:\malware.exeC:\malware.exe
21/11/2019 - 16:45:54.668Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\malware.exe
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Monitor
21/11/2019 - 16:45:54.668Unknown1480C:\malware.exeC:\Monitor
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Windows\SysWOW64\rpcss.dll
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Windows\SysWOW64\rpcss.dll
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Windows\SysWOW64\uxtheme.dll
21/11/2019 - 16:45:54.668Open1480C:\malware.exeC:\Windows\SysWOW64\uxtheme.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:54.731Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\PROPSYS.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\SysWOW64\shell32.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\malware.exe.Local
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:54.731Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\WindowsShell.Manifest
21/11/2019 - 16:45:54.731Unknown1480C:\malware.exeC:\Windows\WindowsShell.ManifestWindowsShell.Manifest
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Users\Behemot\Desktop\desktop.ini
21/11/2019 - 16:45:54.731Read1480C:\malware.exeC:\Users\Behemot\Desktop\desktop.ini
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\System32\propsys.dll
21/11/2019 - 16:45:54.731Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Windows\System32\propsys.dll
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.747Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users\desktop.ini
21/11/2019 - 16:45:54.747Read1480C:\malware.exeC:\Users\desktop.ini
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.747Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.747Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users\Behemot\Searches\desktop.ini
21/11/2019 - 16:45:54.747Read1480C:\malware.exeC:\Users\Behemot\Searches\desktop.ini
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.747Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.747Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.747Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users\Behemot\Videos\desktop.ini
21/11/2019 - 16:45:54.747Read1480C:\malware.exeC:\Users\Behemot\Videos\desktop.ini
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.747Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.747Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.747Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.747Open1480C:\malware.exeC:\Users\Behemot\Pictures\desktop.ini
21/11/2019 - 16:45:54.747Read1480C:\malware.exeC:\Users\Behemot\Pictures\desktop.ini
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot\Contacts\desktop.ini
21/11/2019 - 16:45:54.762Read1480C:\malware.exeC:\Users\Behemot\Contacts\desktop.ini
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot\Favorites\desktop.ini
21/11/2019 - 16:45:54.762Read1480C:\malware.exeC:\Users\Behemot\Favorites\desktop.ini
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot\Music\desktop.ini
21/11/2019 - 16:45:54.762Read1480C:\malware.exeC:\Users\Behemot\Music\desktop.ini
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot\Downloads\desktop.ini
21/11/2019 - 16:45:54.762Read1480C:\malware.exeC:\Users\Behemot\Downloads\desktop.ini
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot\Documents\desktop.ini
21/11/2019 - 16:45:54.762Read1480C:\malware.exeC:\Users\Behemot\Documents\desktop.ini
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot\Links\desktop.ini
21/11/2019 - 16:45:54.762Read1480C:\malware.exeC:\Users\Behemot\Links\desktop.ini
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Users\Behemot\Saved Games\desktop.ini
21/11/2019 - 16:45:54.762Read1480C:\malware.exeC:\Users\Behemot\Saved Games\desktop.ini
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\apphelp.dll
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:54.762Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:54.762Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Read1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Read1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Windows\SysWOW64\shell32.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Windows\SysWOW64\shell32.dll
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.28Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.28Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.28Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.28Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.43Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.43Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.43Unknown1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.43Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.43Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Read1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Read1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.43Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.215Open1480C:\malware.exeC:\Windows\SysWOW64\twext.dll
21/11/2019 - 16:45:55.231Open1480C:\malware.exeC:\malware.exe.Local
21/11/2019 - 16:45:55.231Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.231Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.231Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\CRYPTSP.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\cryptsp.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\cryptsp.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\RpcRtRemote.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dll
21/11/2019 - 16:45:55.325Unknown1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
21/11/2019 - 16:45:55.325Open1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dll
21/11/2019 - 16:45:55.325Unknown1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\desktop.ini
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
21/11/2019 - 16:45:55.372Read1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
21/11/2019 - 16:45:55.372Read1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\ProgramData
21/11/2019 - 16:45:55.372Unknown1480C:\malware.exeC:\ProgramData
21/11/2019 - 16:45:55.372Open1480C:\malware.exeC:\ProgramData\Microsoft\desktop.ini
21/11/2019 - 16:45:55.387Open1480C:\malware.exeC:\ProgramData\Microsoft
21/11/2019 - 16:45:55.387Unknown1480C:\malware.exeC:\ProgramData\Microsoft
21/11/2019 - 16:45:55.387Open1480C:\malware.exeC:\ProgramData\Microsoft\Windows
21/11/2019 - 16:45:55.387Unknown1480C:\malware.exeC:\ProgramData\Microsoft\Windows
21/11/2019 - 16:45:55.387Open1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
21/11/2019 - 16:45:55.387Read1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
21/11/2019 - 16:45:55.387Open1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
21/11/2019 - 16:45:55.387Unknown1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
21/11/2019 - 16:45:55.387Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.387Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.387Open1480C:\malware.exeC:\ProgramData
21/11/2019 - 16:45:55.387Unknown1480C:\malware.exeC:\ProgramData
21/11/2019 - 16:45:55.387Open1480C:\malware.exeC:\ProgramData\Microsoft
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\ProgramData\Microsoft
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\ProgramData\Microsoft\Windows
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\ProgramData\Microsoft\Windows
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
21/11/2019 - 16:45:55.403Read1480C:\malware.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Users\Behemot\Desktop
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\Users\Behemot\Desktop
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Users\Public\Desktop
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\Users\Public\Desktop
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Users\Public\desktop.ini
21/11/2019 - 16:45:55.403Read1480C:\malware.exeC:\Users\Public\desktop.ini
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Users\Public
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\Users\Public
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Users\Public\Desktop\desktop.ini
21/11/2019 - 16:45:55.403Read1480C:\malware.exeC:\Users\Public\Desktop\desktop.ini
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.403Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.403Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.512Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.512Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.512Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.512Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.512Read1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.512Read1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.559Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.559Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.559Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.606Open1480C:\malware.exeC:\Windows\SysWOW64\gameux.dll
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\malware.exe.Local
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.622Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\malware.exe.Local
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be
21/11/2019 - 16:45:55.622Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be\GdiPlus.dll
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be\GdiPlus.dll
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\SysWOW64\xmllite.dll
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\SysWOW64\xmllite.dll
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\SysWOW64\wer.dll
21/11/2019 - 16:45:55.622Open1480C:\malware.exeC:\Windows\SysWOW64\wer.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Monitor\gameux.dll
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
21/11/2019 - 16:45:55.637Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.637Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.637Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.637Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.637Unknown1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.637Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.637Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
21/11/2019 - 16:45:55.653Read1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
21/11/2019 - 16:45:55.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Windows\SysWOW64\shell32.dll
21/11/2019 - 16:45:55.653Open1480C:\malware.exeC:\Windows\SysWOW64\shell32.dll
21/11/2019 - 16:45:55.668Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.668Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.668Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.668Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.668Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.668Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:55.668Open1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:55.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:55.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:55.684Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.684Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
21/11/2019 - 16:45:55.684Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.684Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.684Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.700Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.700Unknown1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.700Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.700Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.700Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.700Read1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.700Read1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.715Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.715Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.715Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.731Open1480C:\malware.exeC:\cscapi.dll
21/11/2019 - 16:45:55.731Open1480C:\malware.exeC:\Windows\SysWOW64\cscapi.dll
21/11/2019 - 16:45:55.731Open1480C:\malware.exeC:\Windows\SysWOW64\cscapi.dll
21/11/2019 - 16:45:55.747Open1480C:\malware.exeC:\slc.dll
21/11/2019 - 16:45:55.747Open1480C:\malware.exeC:\Windows\SysWOW64\slc.dll
21/11/2019 - 16:45:55.747Open1480C:\malware.exeC:\Windows\SysWOW64\slc.dll
21/11/2019 - 16:45:55.747Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.747Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:55.747Open1480C:\malware.exeC:\Users\Public
21/11/2019 - 16:45:55.747Unknown1480C:\malware.exeC:\Users\Public
21/11/2019 - 16:45:55.747Open1480C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\malware.exe.Local
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.809Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.809Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.809Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.809Unknown1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.809Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.809Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.809Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.809Read1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.809Read1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.825Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.825Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.825Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\Windows\SysWOW64\synceng.dll
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\Windows\SysWOW64\synceng.dll
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\malware.exe.Local
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
21/11/2019 - 16:45:55.840Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\Windows\SysWOW64\linkinfo.dll
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\Windows\SysWOW64\linkinfo.dll
21/11/2019 - 16:45:55.840Open1480C:\malware.exeC:\Windows\SysWOW64\syncui.dll
21/11/2019 - 16:45:55.856Open1480C:\malware.exeC:\malware.exe.Local
21/11/2019 - 16:45:55.856Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.856Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.856Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:55.856Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.856Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
21/11/2019 - 16:45:55.856Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.856Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\
21/11/2019 - 16:45:55.872Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.872Unknown1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.872Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.872Unknown1480C:\malware.exeC:\Windows\SysWOW64
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.872Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.872Read1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.872Read1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.981Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.981Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.981Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:55.981Unknown1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:56.43Open1480C:\malware.exeC:\Windows\SysWOW64\sfc.dll
21/11/2019 - 16:45:56.43Open1480C:\malware.exeC:\Windows\SysWOW64\sfc.dll
21/11/2019 - 16:45:56.43Open1480C:\malware.exeC:\sfc_os.DLL
21/11/2019 - 16:45:56.43Open1480C:\malware.exeC:\Windows\SysWOW64\sfc_os.dll
21/11/2019 - 16:45:56.43Open1480C:\malware.exeC:\Windows\SysWOW64\sfc_os.dll
21/11/2019 - 16:45:56.43Open1480C:\malware.exeC:\Windows\SysWOW64\msi.dll
21/11/2019 - 16:45:56.43Open1480C:\malware.exeC:\Windows\SysWOW64\msi.dll
21/11/2019 - 16:45:56.43Open1480C:\malware.exeC:\Windows\SysWOW64\version.dll
21/11/2019 - 16:45:56.43Open1480C:\malware.exeC:\Windows\SysWOW64\version.dll
21/11/2019 - 16:45:56.90Open1480C:\malware.exeC:\Windows\SysWOW64\acppage.dll
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\malware.exe.Local
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:56.106Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\Windows\winsxs\FileMaps\users_behemot_appdata_roaming_microsoft_a851a1047c421b2c.cdf-ms
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\DEVRTL.dll
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\Windows\SysWOW64\devrtl.dll
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\Windows\SysWOW64\devrtl.dll
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\imageres.dll
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\Windows\SysWOW64\imageres.dll
21/11/2019 - 16:45:56.106Open1480C:\malware.exeC:\Windows\SysWOW64\imageres.dll
21/11/2019 - 16:45:56.309Open1480C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
21/11/2019 - 16:45:56.309Open1480C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
21/11/2019 - 16:45:56.309Open1480C:\malware.exeC:\Windows\SysWOW64\pt\imageres.dll.mui
21/11/2019 - 16:45:56.309Unknown1480C:\malware.exeC:\Windows\SysWOW64\en-US
21/11/2019 - 16:45:56.309Open1480C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
21/11/2019 - 16:45:56.309Read1480C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Windows\SysWOW64\urlmon.dll
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Windows\SysWOW64\urlmon.dll
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Secur32.dll
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Windows\SysWOW64\secur32.dll
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Windows\SysWOW64\secur32.dll
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:56.356Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\api-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:45:56.356Open1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe:Zone.Identifier
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Monitor
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Monitor
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Users
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Read1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:45:56.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\ui\SwDRM.dll
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:56.418Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\Prefetch\WINDOWS-SEARCHENGINEE.EXE-371F48E4.pf
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\System32\wow64.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\System32\wow64.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\System32\wow64win.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\System32\wow64win.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\System32\wow64cpu.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\System32\wow64cpu.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\System32\wow64log.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows
21/11/2019 - 16:45:56.481Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Monitor
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\sechost.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\sechost.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\imm32.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\imm32.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\imm32.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\imm32.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\imm32.dll
21/11/2019 - 16:45:56.481Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\imm32.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Netapi32.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netapi32.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netapi32.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\netutils.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netutils.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netutils.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\srvcli.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\srvcli.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\srvcli.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\wkscli.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wkscli.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wkscli.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\SAMCLI.DLL
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\samcli.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\samcli.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\SAMLIB.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\samlib.dll
21/11/2019 - 16:45:56.497Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\samlib.dll
21/11/2019 - 16:45:56.512Unknown1480C:\malware.exeC:\Windows
21/11/2019 - 16:45:56.512Unknown1480C:\malware.exeC:\Monitor
21/11/2019 - 16:45:56.512Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:45:56.512Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be
21/11/2019 - 16:45:56.512Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
21/11/2019 - 16:45:56.559Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\Globalization\Sorting\SortDefault.nls
21/11/2019 - 16:45:56.559Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
21/11/2019 - 16:46:8.684Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:46:8.684Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:46:8.684Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:46:8.684Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:46:8.684Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:46:8.684Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:46:8.684Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:46:8.684Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe
21/11/2019 - 16:46:8.731Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeWindows-SearchEnginee.exe
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:46:8.731Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:46:8.731Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\version.DLL
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\version.dll
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\version.dll
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Secur32.dll
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\secur32.dll
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\secur32.dll
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 16:46:8.731Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\api-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:46:8.731Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:46:8.731Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\winhttp.dll
21/11/2019 - 16:46:8.731Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\winhttp.dll
21/11/2019 - 16:46:8.747Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\webio.dll
21/11/2019 - 16:46:8.747Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\webio.dll
21/11/2019 - 16:46:8.793Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
21/11/2019 - 16:46:8.809Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5
21/11/2019 - 16:46:8.809Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5
21/11/2019 - 16:46:8.856Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\mswsock.dll
21/11/2019 - 16:46:8.856Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\mswsock.dll
21/11/2019 - 16:46:8.856Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wship6.dll
21/11/2019 - 16:46:8.856Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wship6.dll
21/11/2019 - 16:46:8.856Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\IPHLPAPI.DLL
21/11/2019 - 16:46:8.856Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
21/11/2019 - 16:46:8.856Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
21/11/2019 - 16:46:8.856Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\WINNSI.DLL
21/11/2019 - 16:46:8.856Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\winnsi.dll
21/11/2019 - 16:46:8.872Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\winnsi.dll
21/11/2019 - 16:46:8.872Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\api-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 16:46:8.872Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 16:46:8.872Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 16:46:8.872Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 16:46:8.872Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 16:46:8.872Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\DNSAPI.dll
21/11/2019 - 16:46:8.872Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\dnsapi.dll
21/11/2019 - 16:46:8.872Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\dnsapi.dll
21/11/2019 - 16:46:8.981Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rpcss.dll
21/11/2019 - 16:46:8.981Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rpcss.dll
21/11/2019 - 16:46:9.28Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netprofm.dll
21/11/2019 - 16:46:9.28Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netprofm.dll
21/11/2019 - 16:46:9.28Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\nlaapi.dll
21/11/2019 - 16:46:9.28Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\nlaapi.dll
21/11/2019 - 16:46:9.75Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\dhcpcsvc6.DLL
21/11/2019 - 16:46:9.75Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\dhcpcsvc6.dll
21/11/2019 - 16:46:9.75Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\dhcpcsvc6.dlldhcpcsvc6.dll
21/11/2019 - 16:46:9.75Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\dhcpcsvc6.dll
21/11/2019 - 16:46:9.75Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\dhcpcsvc6.dlldhcpcsvc6.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\dhcpcsvc.DLL
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\dhcpcsvc.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\dhcpcsvc.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\CRYPTSP.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\cryptsp.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\cryptsp.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.122Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.137Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.137Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 16:46:9.137Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\RpcRtRemote.dll
21/11/2019 - 16:46:9.137Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\RpcRtRemote.dll
21/11/2019 - 16:46:9.137Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
21/11/2019 - 16:46:9.137Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\RpcRtRemote.dll
21/11/2019 - 16:46:9.137Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
21/11/2019 - 16:46:9.184Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\rasadhlp.dll
21/11/2019 - 16:46:9.184Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rasadhlp.dll
21/11/2019 - 16:46:9.184Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\rasadhlp.dll
21/11/2019 - 16:46:9.231Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\npmproxy.dll
21/11/2019 - 16:46:9.231Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\npmproxy.dll
21/11/2019 - 16:46:10.309Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wininet.dll
21/11/2019 - 16:46:10.309Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wininet.dll
21/11/2019 - 16:46:10.606Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\FWPUCLNT.DLL
21/11/2019 - 16:46:10.606Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\FWPUCLNT.DLL
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wininet.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe.Local
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:46:10.700Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\WindowsShell.Manifest
21/11/2019 - 16:46:10.700Unknown804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\WindowsShell.ManifestWindowsShell.Manifest
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\ws2_32.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\ws2_32.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wship6.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wship6.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wship6.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wshqos.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wshqos.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wshqos.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wshqos.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wshqos.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wshqos.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wshqos.dll
21/11/2019 - 16:46:10.700Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wshqos.dll
21/11/2019 - 16:47:16.137Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netprofm.dll
21/11/2019 - 16:47:16.137Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netprofm.dll
21/11/2019 - 16:47:16.137Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\nlaapi.dll
21/11/2019 - 16:47:16.137Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\nlaapi.dll
21/11/2019 - 16:47:16.325Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\npmproxy.dll
21/11/2019 - 16:47:16.325Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\npmproxy.dll
21/11/2019 - 16:47:17.512Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wininet.dll
21/11/2019 - 16:47:17.512Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wininet.dll
21/11/2019 - 16:48:52.840Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netprofm.dll
21/11/2019 - 16:48:52.840Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\netprofm.dll
21/11/2019 - 16:48:52.840Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\nlaapi.dll
21/11/2019 - 16:48:52.840Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\nlaapi.dll
21/11/2019 - 16:48:53.28Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\npmproxy.dll
21/11/2019 - 16:48:53.28Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\npmproxy.dll
21/11/2019 - 16:48:54.184Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wininet.dll
21/11/2019 - 16:48:54.184Open804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeC:\Windows\SysWOW64\wininet.dll

Process
Trace
21/11/2019 - 16:45:56.418Create1480C:\malware.exe804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe

Analysis
Reason
Timeout

Status
Sucessfully Executed

Results
1

Registry
Trace
21/11/2019 - 16:45:42.497Write1480C:\malware.exeHKCU\Software\Microsoft\EngineIndicatorSearchID
21/11/2019 - 16:45:55.372Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.372Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.372Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.387Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.637Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.653Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.653Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.653Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.653Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:55.809Write1480C:\malware.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
21/11/2019 - 16:45:56.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
21/11/2019 - 16:45:56.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
21/11/2019 - 16:45:56.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
21/11/2019 - 16:45:56.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
21/11/2019 - 16:45:56.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
21/11/2019 - 16:45:56.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
21/11/2019 - 16:45:56.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
21/11/2019 - 16:45:56.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
21/11/2019 - 16:46:8.684Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\RunMicrosoft Windows Search Indexer
21/11/2019 - 16:46:8.731Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\RunMicrosoft Windows Search Indexer
21/11/2019 - 16:46:8.731Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\ExplorerShellState
21/11/2019 - 16:46:8.731Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\SuperHiddenUncheckedValue
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedHidden
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedShowCompColor
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedHideFileExt
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedDontPrettyPath
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedShowInfoTip
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedHideIcons
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedMapNetDrvBtn
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedWebView
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedFilter
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedSuperHidden
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedSeparateProcess
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedAutoCheckSelect
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedIconsOnly
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedShowTypeOverlay
21/11/2019 - 16:46:8.793Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ContentCachePrefix
21/11/2019 - 16:46:8.809Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\CookiesCachePrefix
21/11/2019 - 16:46:8.809Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\HistoryCachePrefix
21/11/2019 - 16:46:8.872Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyEnable
21/11/2019 - 16:46:8.872Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyServer
21/11/2019 - 16:46:8.872Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyOverride
21/11/2019 - 16:46:8.872Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsAutoConfigURL
21/11/2019 - 16:46:8.872Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsAutoDetect
21/11/2019 - 16:46:8.872Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectionsSavedLegacySettings
21/11/2019 - 16:46:9.122Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
21/11/2019 - 16:46:9.122Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
21/11/2019 - 16:46:9.122Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
21/11/2019 - 16:46:9.122Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
21/11/2019 - 16:46:9.122Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
21/11/2019 - 16:46:9.122Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
21/11/2019 - 16:46:9.122Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
21/11/2019 - 16:46:9.122Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
21/11/2019 - 16:46:9.278Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 16:46:9.278Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 16:46:9.278Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 16:46:9.278Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 16:46:10.559Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 16:46:10.559Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 16:46:10.559Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 16:46:10.559Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 16:47:16.325Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 16:47:16.325Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 16:47:16.325Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 16:47:16.325Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 16:47:17.622Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 16:47:17.622Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 16:47:17.622Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 16:47:17.622Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 16:48:53.28Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 16:48:53.28Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 16:48:53.28Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 16:48:53.28Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 16:48:54.340Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 16:48:54.340Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 16:48:54.340Write804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 16:48:54.340Delete804C:\Users\Behemot\AppData\Roaming\Microsoft\Windows-SearchEnginee.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl

File Summary
Created
Identified: True check_circle

Deleted
Identified: False cancel

Process Summary
Created
Identified: True check_circle

Deleted
Identified: False cancel

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: True check_circle

Deleted
Identified: True check_circle

Browsers
Identified: False cancel

Internet
Identified: True check_circle

Loading...

DNS
Query
computer localhost arrow_forward computer gateway:DNS code timenowis1.top.
computer localhost arrow_forward computer gateway:50273 code timenowis1.top.

Response
computer gateway:DNS arrow_forward computer localhost code timenowis1.top. reply_all 127.0.0.1


TCP
Info

UDP
Info
computer localhost:53 arrow_forward computer localhost:50273
computer localhost:50273 arrow_forward computer localhost:53
computer localhost:67 arrow_forward computer localhost:68
computer localhost:68 arrow_forward help_outline 255.255.255.255:67

HTTP
Info

Summary
DNS
True check_circle

TCP
False cancel

UDP
True check_circle

HTTP
False cancel

Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

SVC (Kernel=Linear, NFS-BRMalware)
confidence: 97.72%
suspicious: False cancel

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 96.28%
suspicious: True check_circle

Random Forest (100 estimators, NFS-BRMalware)
confidence: 70.50%
suspicious: False cancel

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 36.04%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 99.91%
suspicious: True check_circle

Add to Collection
Download