Report #5317 check_circle

  • Creation Date: Nov. 21, 2019, 5:42 p.m.
  • Last Update: Nov. 21, 2019, 6:19 p.m.
  • File: 008
  • Results:
Binary
DLL
False cancel
Size
65.50KB
trid
38.4% Win32 Dynamic Link Library
26.3% Win32 Executable
11.8% OS/2 Executable
11.6% Generic Win/DOS Executable
11.6% DOS Executable Generic
type
PE
wordsize
32
Subsystem
Windows GUI
Hashes
md5
0a397a2b88338e7b6adb6f548dcf3f27
sha1
82ef09e7bf0dff159ec993e0d1d3ec2706614703
crc32
0x8fc8f226
sha224
14beddac7f10b9e8a77473e87ca8cbd73c211fa630b5377bd8e326b1
sha256
4d12ad00ce27e092e49ad72599bda5d0882aa878c124ddd7d5b8feebff08c50a
sha384
a3779dca301f2e2d7906d561bbf95b7912553094c8583156d2b5c9b8a1409d5d8dc981a7dfc75a7d2f291b1a67c3ce29
sha512
4ba432be67130bc3cea65ffba4b66281363cd6fc04eaa2f557c30f8beb418ef4f7376004125209780c8466ff5751feb7ddacd72d307dde16be1970b4811fd50e
ssdeep
768:88m1Sq4NQErBsH1tzoisBKQI6dObAG/dq8uW29Ifnca/yyR+P2ujfGiXsbs8HszA:esq+QV4rObAdXWpf/y+Ya8oox
Community
Google
True check_circle
HashLib
False cancel
YARA
Matches
xtremrat, domain, borland_delphi, Borland, contentis_base64, ThreadControl__Context, win_hook, win_mutex, keylogger, win_registry, Microsoft_Visual_Cpp_v50v60_MFC, Delphi_CompareCall, xtreme_rat, network_dropper, win_files_operation, IsPE32, Xtreme, IsWindowsGUI, Dropper_Strings

Suspicious
True check_circle

Strings
List
t.Ht
autorun.inf
svchost.exe
[Delete]
Software\Microsoft\Active Setup\Installed Components\
Software\Microsoft\Active Setup\Installed Components\
P.rsrc
SOFTWARE\Borland\Delphi\RTL
msimg32.dll
msimg32.dll
opengl32.dll
comctl32.dll
comctl32.dll
opengl32.dll
version.dll
version.dll
wininet.dll
[Execute]
icon=shell32.dll,4
wintrust.dll
wintrust.dll
ntdll.dll
mpr.dll
mpr.dll
[autorun]
[Sleep]
SOFTWARE\
SOFTWARE\
SOFTWARE\
SOFTWARE\
SOFTWARE\
SOFTWARE\
SOFTWARE\
SOFTWARE\
[Volume Up]
[Volume Mute]
[Volume Down]
%NOINJECT%
%DEFAULTBROWSER%
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
http://
HKEY_CLASSES_ROOT
%SERVER%
HKEY_LOCAL_MACHINE
FtpPutFileW
SOFTWARE\XtremeRAT
FtpSetCurrentDirectoryW
[Process]
[Backspace]
[Select]
[Finish]
[Accept]
[Media]
[Pause]
[Separator]
[Numpad +]
[Numpad -]
[Print]
[Left Alt]
<meta http-equiv="Content-Type" content="text/html;charset=UTF-8">
[Num Lock]
[Mail]
[Home]
[Back Tab]
[Arrow Up]
[Stop]
[Play]
[Help]
[Esc]
[Tab]
[End]
[Arrow Left]
[Caps Lock]
[Page Down]
[Page Up]
[Print Screen]
[Left Ctrl]
shellexecute=
[Mode Change]
[Context Menu]
[Arrow Down]
shell\Open=Open
[Scrol Lock]
[Right Alt]
[Next Track]
[Arrow Right]
[Right Ctrl]
UnitInjectProcess
ExitProcess
ExitProcess
CallNextHookEx
HKEY_CURRENT_USER
ENDSERVERBUFFER
STARTSERVERBUFFER
XTREMEBINDER
TServerKeylogger
XtremeKeylogger
ServerStarted
GetForegroundWindow

Foremost
Matches
0.exe, 65 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancel
Allowed
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

URLs
Allowed
hasURLs: True check_circle
Suspicious: http://
hasAllowed: False cancel
hasSuspicious: True check_circle

Files
Allowed: ntdll.dll, user32.dll, shlwapi.dll, opengl32.dll, URLMON.DLL, gdi32.dll, msimg32.dll, wintrust.dll, wininet.dll, advapi32.dll, kernel32.dll, oleaut32.dll, version.dll, mpr.dll, comctl32.dll, shell32.dll
hasFiles: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 14336
Suspicious: False cancel
Image
Address: 268435456
Suspicious: False cancel
Stack
Stack: 16384
Suspicious: False cancel
Headers
Headers: 4096
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 0
Suspicous: True check_circle

Sections
Allowed: code, data, bss, .idata, .tls, .rdata, .reloc, .rsrc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 4
Suspicious: False cancel
Image
Version: True check_circle
Suspicious: 4
Linker
Version: 2.25
Suspicious: False cancel
Subsystem
Version: 4.0
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 53492
Suspicious: False cancel

Anomalies
Anomalies: The header checksum and the calculated checksum do not match.
hasAnomalies: True check_circle

Libraries
Allowed: ntdll.dll, user32.dll, shlwapi.dll, opengl32.dll, urlmon.dll, gdi32.dll, msimg32.dll, wintrust.dll, wininet.dll, advapi32.dll, kernel32.dll, oleaut32.dll, version.dll, mpr.dll, comctl32.dll, shell32.dll
hasLibs: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Timestamp
Past: True check_circle
Valid: True check_circle
Value: 1992-06-19 19:22:17
Future: False cancel

Compilation
Packed: False cancel
Missing: True check_circle
Packers
Compiled: False cancel
Compilers

Obfuscation
XOR: False cancel
Fuzzing: False cancel

PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
False cancel
Tricks
AVclass
xtrat
1
VirusTotal
md5
0a397a2b88338e7b6adb6f548dcf3f27
sha1
82ef09e7bf0dff159ec993e0d1d3ec2706614703
SCANS (DETECTION RATE = 95.65%)
AVG
result: Win32:AutoRun-CCW [Wrm]
update: 20191024
version: 18.4.3895.0
detected: True check_circle

CMC
result: Backdoor.Win32.Xtrat.1!O
update: 20190321
version: 1.1.0.977
detected: True check_circle

MAX
result: malware (ai score=100)
update: 20191024
version: 2019.9.16.1
detected: True check_circle

APEX
result: Malicious
update: 20191022
version: 5.76
detected: True check_circle

Bkav
result: W32.AclemitB.Trojan
update: 20191023
version: 1.3.0.10239
detected: True check_circle

K7GW
result: Backdoor ( 0027fe5a1 )
update: 20191023
version: 11.74.32341
detected: True check_circle

ALYac
result: Trojan.Delf.Agent.AH
update: 20191024
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:AutoRun-CCW [Wrm]
update: 20191024
version: 18.4.3895.0
detected: True check_circle

Avira
result: TR/Agent.ssnsz
update: 20191024
version: 8.3.3.8
detected: True check_circle

Baidu
result: Win32.Backdoor.Agent.ag
update: 20190318
version: 1.0.0.2
detected: True check_circle

Cyren
result: W32/Xtrat.A.gen!Eldorado
update: 20191024
version: 6.2.2.2
detected: True check_circle

DrWeb
result: Trojan.DownLoader22.2485
update: 20191024
version: 7.0.41.7240
detected: True check_circle

GData
result: Win32.Backdoor.Xtrat.L
update: 20191024
version: A:25.23753B:26.16399
detected: True check_circle

Panda
result: Trj/Keylogger.GM
update: 20191023
version: 4.6.4.2
detected: True check_circle

VBA32
result: BScope.Backdoor.Xtreme
update: 20191023
version: 4.2.0
detected: True check_circle

Zoner
result: Trojan.Win32.22107
update: 20191021
version: 1.0.0.1
detected: True check_circle

ClamAV
result: Win.Trojan.Keylogger-192
update: 20191023
version: 0.102.0.0
detected: True check_circle

Comodo
result: Backdoor.Win32.Xbot.SP@4k8169
update: 20191024
version: 31639
detected: True check_circle

F-Prot
result: W32/Xtrat.A.gen!Eldorado
update: 20191024
version: 4.7.1.166
detected: True check_circle

Ikarus
result: Trojan-Spy.Win32.KeyLogger
update: 20191023
version: 0.1.5.2
detected: True check_circle

McAfee
result: BackDoor-FAJ
update: 20191024
version: 6.0.6.653
detected: True check_circle

Rising
result: Backdoor.Xtrat!1.6A25 (CLASSIC)
update: 20191024
version: 25.0.0.24
detected: True check_circle

Sophos
result: Mal/SillyFDC-A
update: 20191024
version: 4.98.0
detected: True check_circle

Yandex
result: Backdoor.XTrat.Gen
update: 20191023
version: 5.5.2.24
detected: True check_circle

Zillya
result: Trojan.Xtreme.Win32.81
update: 20191023
version: 2.0.0.3931
detected: True check_circle

Acronis
result: suspicious
update: 20191018
version: 1.1.1.58
detected: True check_circle

Alibaba
result: Backdoor:Win32/Xtreme.7ec0c908
update: 20190527
version: 0.3.0.5
detected: True check_circle

Arcabit
result: Trojan.Delf.Agent.AH
update: 20191024
version: 1.0.0.861
detected: True check_circle

Cylance
result: Unsafe
update: 20191024
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (high confidence)
update: 20190918
version: 3.0.15
detected: True check_circle

FireEye
result: Generic.mg.0a397a2b88338e7b
update: 20191024
version: 29.7.0.0
detected: True check_circle

TACHYON
result: Backdoor/W32.DP-Xtreme.67072
update: 20191024
version: 2019-10-24.01
detected: True check_circle

Tencent
result: Trojan.Win32.Injector.r
update: 20191024
version: 1.0.0.1
detected: True check_circle

ViRobot
result: Backdoor.Win32.A.Xtreme.67072
update: 20191023
version: 2014.3.20.0
detected: True check_circle

Webroot
update: 20191024
version: 1.0.0.403
detected: False cancel

eGambit
result: RAT.Xtreme
update: 20191024
version: v5.0.6
detected: True check_circle

Ad-Aware
result: Trojan.Delf.Agent.AH
update: 20191024
version: 3.0.5.370
detected: True check_circle

AegisLab
result: Trojan.Win32.Xtreme.tnah
update: 20191024
version: 4.2
detected: True check_circle

Emsisoft
result: Trojan.Delf.Agent.AH (B)
update: 20191024
version: 2018.12.0.1641
detected: True check_circle

F-Secure
result: Trojan.TR/Agent.ssnsz
update: 20191024
version: 12.0.86.52
detected: True check_circle

Fortinet
result: W32/Injector.fam!tr
update: 20191024
version: 5.4.247.0
detected: True check_circle

Invincea
result: heuristic
update: 20190904
version: 6.3.6.26157
detected: True check_circle

Jiangmin
result: Trojan/Generic.fwrt
update: 20191024
version: 16.0.100
detected: True check_circle

Kingsoft
update: 20191024
version: 2013.8.14.323
detected: False cancel

Paloalto
result: generic.ml
update: 20191024
version: 1.0
detected: True check_circle

Symantec
result: W32.Extrat!gen1
update: 20191023
version: 1.11.0.0
detected: True check_circle

Trapmine
result: malicious.high.ml.score
update: 20190826
version: 3.1.81.800
detected: True check_circle

AhnLab-V3
result: Spyware/Win32.KeyLogger.C77144
update: 20191024
version: 3.16.3.25410
detected: True check_circle

Antiy-AVL
result: Trojan[Backdoor]/Win32.Xtreme.bqj
update: 20191024
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: Backdoor.Win32.Xtreme.bqj
update: 20191024
version: 15.0.1.13
detected: True check_circle

Microsoft
result: Backdoor:Win32/Xtrat.A
update: 20191024
version: 1.1.16500.1
detected: True check_circle

Qihoo-360
result: Backdoor.Win32.Xtreme.A
update: 20191024
version: 1.0.0.1120
detected: True check_circle

ZoneAlarm
result: Backdoor.Win32.Xtreme.bqj
update: 20191024
version: 1.0
detected: True check_circle

Cybereason
result: malicious.b88338
update: 20190616
version: 1.2.449
detected: True check_circle

ESET-NOD32
result: Win32/AutoRun.Remtasu.E
update: 20191024
version: 20232
detected: True check_circle

TrendMicro
result: TSPY_KEYLOG.SMC
update: 20191024
version: 11.0.0.1006
detected: True check_circle

BitDefender
result: Trojan.Delf.Agent.AH
update: 20191024
version: 7.2
detected: True check_circle

CrowdStrike
result: win/malicious_confidence_100% (W)
update: 20190702
version: 1.0
detected: True check_circle

K7AntiVirus
result: Backdoor ( 0027fe5a1 )
update: 20191023
version: 11.74.32344
detected: True check_circle

SentinelOne
result: DFI - Malicious PE
update: 20190807
version: 1.0.31.22
detected: True check_circle

Avast-Mobile
update: 20191012
version: 191012-04
detected: False cancel

Malwarebytes
result: Backdoor.XTRat
update: 20191024
version: 2.1.1.1115
detected: True check_circle

TotalDefense
result: Win32/Xtrat.B!generic
update: 20191023
version: 37.1.62.1
detected: True check_circle

CAT-QuickHeal
result: Backdoor.Xtrat.AA8
update: 20191022
version: 14.00
detected: True check_circle

NANO-Antivirus
result: Trojan.Win32.Xtreme.dpkuuc
update: 20191024
version: 1.0.134.24859
detected: True check_circle

MicroWorld-eScan
result: Trojan.Delf.Agent.AH
update: 20191024
version: 14.0.297.0
detected: True check_circle

SUPERAntiSpyware
result: Trojan.Agent/Gen-Patcher
update: 20191019
version: 5.6.0.1032
detected: True check_circle

McAfee-GW-Edition
result: BehavesLike.Win32.Backdoor.kh
update: 20191024
version: v2017.3010
detected: True check_circle

TrendMicro-HouseCall
result: TSPY_KEYLOG.SMC
update: 20191024
version: 10.0.0.1040
detected: True check_circle

total
69
sha256
4d12ad00ce27e092e49ad72599bda5d0882aa878c124ddd7d5b8feebff08c50a
scan_id
4d12ad00ce27e092e49ad72599bda5d0882aa878c124ddd7d5b8feebff08c50a-1571882704
resource
0a397a2b88338e7b6adb6f548dcf3f27
positives
66
scan_date
2019-10-24 02:05:04
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
21/11/2019 - 17:45:43.543Open1480C:\malware.exeC:\GLU32.dll
21/11/2019 - 17:45:43.543Open1480C:\malware.exeC:\Windows\SysWOW64\glu32.dll
21/11/2019 - 17:45:43.543Open1480C:\malware.exeC:\Windows\SysWOW64\glu32.dll
21/11/2019 - 17:45:43.653Open1480C:\malware.exeC:\DDRAW.dll
21/11/2019 - 17:45:43.653Open1480C:\malware.exeC:\Windows\SysWOW64\ddraw.dll
21/11/2019 - 17:45:43.653Open1480C:\malware.exeC:\Windows\SysWOW64\ddraw.dll
21/11/2019 - 17:45:43.747Open1480C:\malware.exeC:\DCIMAN32.dll
21/11/2019 - 17:45:43.747Open1480C:\malware.exeC:\Windows\SysWOW64\dciman32.dll
21/11/2019 - 17:45:43.747Open1480C:\malware.exeC:\Windows\SysWOW64\dciman32.dll
21/11/2019 - 17:45:43.793Open1480C:\malware.exeC:\dwmapi.dll
21/11/2019 - 17:45:43.793Open1480C:\malware.exeC:\Windows\SysWOW64\dwmapi.dll
21/11/2019 - 17:45:43.793Open1480C:\malware.exeC:\Windows\SysWOW64\dwmapi.dll
21/11/2019 - 17:45:44.122Open1480C:\malware.exeC:\msimg32.dll
21/11/2019 - 17:45:44.122Open1480C:\malware.exeC:\Windows\SysWOW64\msimg32.dll
21/11/2019 - 17:45:44.122Open1480C:\malware.exeC:\Windows\SysWOW64\msimg32.dll
21/11/2019 - 17:45:44.122Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:44.122Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:44.168Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\api-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 17:45:44.168Unknown1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 17:45:44.168Unknown1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\Secur32.dll
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\Windows\SysWOW64\secur32.dll
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\Windows\SysWOW64\secur32.dll
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 17:45:44.168Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\api-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 17:45:44.168Unknown1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 17:45:44.168Open1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 17:45:44.168Unknown1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
21/11/2019 - 17:45:44.231Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat
21/11/2019 - 17:45:44.231Open1480C:\malware.exeC:\Windows\SysWOW64\winhttp.dll
21/11/2019 - 17:45:44.231Open1480C:\malware.exeC:\Windows\SysWOW64\winhttp.dll
21/11/2019 - 17:45:44.231Open1480C:\malware.exeC:\Windows\SysWOW64\webio.dll
21/11/2019 - 17:45:44.231Open1480C:\malware.exeC:\Windows\SysWOW64\webio.dll
21/11/2019 - 17:45:44.247Open1480C:\malware.exeC:\IPHLPAPI.DLL
21/11/2019 - 17:45:44.247Open1480C:\malware.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
21/11/2019 - 17:45:44.247Open1480C:\malware.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
21/11/2019 - 17:45:44.247Open1480C:\malware.exeC:\WINNSI.DLL
21/11/2019 - 17:45:44.247Open1480C:\malware.exeC:\Windows\SysWOW64\winnsi.dll
21/11/2019 - 17:45:44.247Open1480C:\malware.exeC:\Windows\SysWOW64\winnsi.dll
21/11/2019 - 17:45:44.247Open1480C:\malware.exeC:\DNSAPI.dll
21/11/2019 - 17:45:44.247Open1480C:\malware.exeC:\Windows\SysWOW64\dnsapi.dll
21/11/2019 - 17:45:44.247Open1480C:\malware.exeC:\Windows\SysWOW64\dnsapi.dll
21/11/2019 - 17:45:44.325Open1480C:\malware.exeC:\Windows\SysWOW64\mswsock.dll
21/11/2019 - 17:45:44.325Open1480C:\malware.exeC:\Windows\SysWOW64\mswsock.dll
21/11/2019 - 17:45:44.325Open1480C:\malware.exeC:\Windows\SysWOW64\wship6.dll
21/11/2019 - 17:45:44.325Open1480C:\malware.exeC:\Windows\SysWOW64\wship6.dll
21/11/2019 - 17:45:44.372Open1480C:\malware.exeC:\Windows\SysWOW64\netprofm.dll
21/11/2019 - 17:45:44.372Open1480C:\malware.exeC:\Windows\SysWOW64\netprofm.dll
21/11/2019 - 17:45:44.372Open1480C:\malware.exeC:\Windows\SysWOW64\nlaapi.dll
21/11/2019 - 17:45:44.372Open1480C:\malware.exeC:\Windows\SysWOW64\nlaapi.dll
21/11/2019 - 17:45:44.418Open1480C:\malware.exeC:\dhcpcsvc6.DLL
21/11/2019 - 17:45:44.418Open1480C:\malware.exeC:\Windows\SysWOW64\dhcpcsvc6.dll
21/11/2019 - 17:45:44.418Unknown1480C:\malware.exeC:\Windows\SysWOW64\dhcpcsvc6.dlldhcpcsvc6.dll
21/11/2019 - 17:45:44.418Open1480C:\malware.exeC:\Windows\SysWOW64\dhcpcsvc6.dll
21/11/2019 - 17:45:44.418Unknown1480C:\malware.exeC:\Windows\SysWOW64\dhcpcsvc6.dlldhcpcsvc6.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\CRYPTSP.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\cryptsp.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\cryptsp.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.465Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\RpcRtRemote.dll
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dll
21/11/2019 - 17:45:44.481Unknown1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dll
21/11/2019 - 17:45:44.481Unknown1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\dhcpcsvc.DLL
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\Windows\SysWOW64\dhcpcsvc.dll
21/11/2019 - 17:45:44.481Open1480C:\malware.exeC:\Windows\SysWOW64\dhcpcsvc.dll
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5
21/11/2019 - 17:45:44.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\rasadhlp.dll
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Windows\SysWOW64\rasadhlp.dll
21/11/2019 - 17:45:44.543Open1480C:\malware.exeC:\Windows\SysWOW64\rasadhlp.dll
21/11/2019 - 17:45:44.653Open1480C:\malware.exeC:\Windows\SysWOW64\npmproxy.dll
21/11/2019 - 17:45:44.653Open1480C:\malware.exeC:\Windows\SysWOW64\npmproxy.dll
21/11/2019 - 17:45:44.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:45.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:45.700Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:45.840Open1480C:\malware.exeC:\Windows\SysWOW64\wininet.dll
21/11/2019 - 17:45:45.840Open1480C:\malware.exeC:\Windows\SysWOW64\wininet.dll
21/11/2019 - 17:45:45.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:46.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:46.950Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:47.28Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:48.28Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:48.28Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:48.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:49.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:49.106Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:49.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:50.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:50.184Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:50.278Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:51.278Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:51.278Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:51.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:52.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:52.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:52.434Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:53.434Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:53.434Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:53.512Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:54.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:54.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:54.637Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:55.637Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:55.637Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:55.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:56.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:56.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:56.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:57.793Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:57.793Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:57.872Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:58.887Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:58.887Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:58.997Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:45:59.997Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:45:59.997Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:0.75Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:1.75Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:1.75Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:1.153Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:2.153Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:2.153Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:2.231Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:3.231Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:3.231Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:3.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:4.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:4.309Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:4.387Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:5.387Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:5.387Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:5.465Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:6.465Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:6.465Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:6.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:7.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:7.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:7.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:8.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:8.622Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:8.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:9.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:9.700Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:9.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:10.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:10.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:10.856Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:11.856Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:11.856Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:11.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:12.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:12.934Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:13.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:14.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:14.12Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:14.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:15.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:15.90Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:15.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:16.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:16.168Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:16.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:17.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:17.247Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:17.325Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:18.325Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:18.325Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:18.403Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:19.403Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:19.403Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:19.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:20.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:20.450Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:20.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:21.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:21.528Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:21.606Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:22.606Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:22.606Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:22.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:23.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:23.684Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:23.747Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:24.747Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:24.747Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:24.825Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:25.825Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:25.825Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:25.903Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:26.903Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:26.903Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:26.981Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:27.981Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:27.981Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:28.59Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:29.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:29.90Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:29.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:30.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:30.184Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:30.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:31.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:31.262Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:31.340Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:32.340Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:32.340Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:32.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:33.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:33.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:33.497Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:34.512Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:34.512Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:34.606Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:35.606Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:35.606Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:35.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:36.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:36.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:36.747Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:37.747Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:37.747Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:37.825Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:38.825Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:38.825Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:38.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:39.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:39.950Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:40.28Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:41.28Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:41.28Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:41.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:42.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:42.106Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:42.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:43.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:43.184Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:43.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:44.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:44.262Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:44.325Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:45.325Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:45.325Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:45.403Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:46.403Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:46.403Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:46.481Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:47.481Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:47.481Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:47.559Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:48.559Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:48.559Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:48.637Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:49.637Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:49.637Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:49.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:50.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:50.731Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:50.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:51.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:51.809Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:51.887Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:52.903Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:52.903Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:52.997Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:53.997Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:53.997Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:54.75Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:55.75Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:55.75Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:55.153Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:56.153Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:56.153Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:56.231Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:57.231Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:57.231Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:57.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:58.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:58.309Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:58.387Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:46:59.387Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:59.387Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:46:59.465Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:0.465Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:0.465Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:0.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:1.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:1.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:1.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:2.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:2.622Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:2.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:3.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:3.700Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:3.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:4.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:4.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:4.856Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:5.856Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:5.856Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:5.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:6.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:6.934Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:7.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:8.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:8.12Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:8.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:9.122Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:9.122Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:9.215Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:10.215Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:10.215Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:10.293Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:11.293Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:11.293Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:11.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:12.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:12.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:12.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:13.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:13.450Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:13.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:14.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:14.528Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:14.590Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:15.590Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:15.590Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:15.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:16.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:16.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:16.747Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:17.747Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:17.747Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:17.825Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:18.825Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:18.825Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:18.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:19.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:19.950Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:20.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:21.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:21.12Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:21.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:22.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:22.90Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:22.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:23.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:23.168Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:23.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:24.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:24.247Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:24.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:25.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:25.309Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:25.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:26.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:26.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:26.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:27.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:27.450Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:27.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:28.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:28.528Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:28.606Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:29.606Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:29.606Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:29.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:30.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:30.684Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:30.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:31.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:31.762Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:31.825Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:32.840Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:32.840Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:32.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:33.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:33.934Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:34.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:35.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:35.12Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:35.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:36.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:36.90Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:36.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:37.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:37.168Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:37.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:38.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:38.247Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:38.325Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:39.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:39.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:39.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:40.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:40.450Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:40.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:41.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:41.528Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:41.606Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:42.606Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:42.606Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:42.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:43.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:43.684Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:43.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:44.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:44.762Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:44.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:45.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:45.809Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:45.887Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:46.887Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:46.887Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:46.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:47.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:47.950Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:48.28Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:49.28Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:49.28Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:49.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:50.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:50.106Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:50.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:51.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:51.184Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:51.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:52.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:52.262Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:52.340Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:53.340Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:53.340Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:53.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:54.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:54.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:54.497Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:55.497Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:55.497Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:55.575Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:56.575Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:56.575Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:56.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:57.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:57.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:57.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:58.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:58.731Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:58.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:47:59.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:59.809Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:47:59.872Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:0.872Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:0.872Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:0.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:1.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:1.950Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:2.28Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:3.28Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:3.28Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:3.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:4.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:4.106Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:4.215Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:5.215Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:5.215Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:5.293Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:6.293Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:6.293Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:6.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:7.372Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:7.372Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:7.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:8.450Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:8.450Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:8.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:9.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:9.528Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:9.575Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:10.575Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:10.575Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:10.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:11.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:11.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:11.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:12.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:12.731Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:12.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:13.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:13.809Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:13.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:14.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:14.934Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:15.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:16.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:16.12Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:16.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:17.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:17.90Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:17.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:18.168Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:18.168Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:18.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:19.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:19.247Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:19.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:20.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:20.309Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:20.387Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:21.387Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:21.387Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:21.465Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:22.465Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:22.465Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:22.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:23.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:23.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:23.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:24.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:24.622Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:24.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:25.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:25.684Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:25.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:26.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:26.762Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:26.840Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:27.840Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:27.840Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:27.903Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:28.903Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:28.903Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:28.981Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:29.981Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:29.981Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:30.59Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:31.59Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:31.59Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:31.137Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:32.137Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:32.137Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:32.215Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:33.215Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:33.215Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:33.278Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:34.278Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:34.278Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:34.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:35.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:35.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:35.434Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:36.434Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:36.434Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:36.512Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:37.512Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:37.512Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:37.590Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:38.590Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:38.590Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:38.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:39.668Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:39.668Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:39.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:40.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:40.731Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:40.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:41.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:41.809Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:41.887Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:42.887Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:42.887Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:42.965Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:43.965Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:43.965Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:44.43Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:45.43Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:45.43Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:45.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:46.106Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:46.106Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:46.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:47.184Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:47.184Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:47.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:48.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:48.262Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:48.340Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:49.340Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:49.340Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:49.403Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:50.403Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:50.403Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:50.481Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:51.481Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:51.481Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:51.559Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:52.559Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:52.559Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:52.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:53.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:53.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:53.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:54.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:54.731Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:54.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:55.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:55.809Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:55.887Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:56.887Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:56.887Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:56.965Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:57.965Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:57.965Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:58.43Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:48:59.43Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:59.43Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:48:59.122Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:0.122Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:0.122Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:0.200Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:1.200Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:1.200Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:1.278Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:2.278Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:2.278Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:2.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:3.356Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:3.356Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:3.434Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:4.434Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:4.434Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:4.497Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:5.497Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:5.497Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:5.575Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:6.575Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:6.575Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:6.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:7.653Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:7.653Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:7.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:8.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:8.762Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:8.903Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:9.903Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:9.903Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:9.965Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:10.965Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:10.965Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:11.43Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:12.43Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:12.43Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:12.122Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:13.122Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:13.122Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:13.200Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:14.200Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:14.200Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:14.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:15.262Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:15.262Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:15.340Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:16.340Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:16.340Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:16.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:17.418Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:17.418Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:17.497Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:18.528Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:18.528Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:18.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:19.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:19.622Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:19.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:20.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:20.684Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:20.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:21.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:21.762Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:21.840Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:22.840Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:22.840Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:22.918Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:23.918Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:23.918Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:23.997Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:24.997Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:24.997Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:25.75Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:26.75Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:26.75Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:26.153Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:27.153Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:27.153Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:27.231Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:28.231Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:28.231Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:28.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:29.309Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:29.309Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:29.387Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:30.387Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:30.387Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:30.465Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:31.465Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:31.465Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:31.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:32.543Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:32.543Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:32.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:33.622Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:33.622Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:33.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:34.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:34.700Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:34.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:35.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:35.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:35.856Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:36.856Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:36.856Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:36.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:37.934Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:37.934Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:38.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:39.12Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:39.12Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:39.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:40.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:40.90Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:40.153Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:41.153Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:41.153Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:41.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:42.247Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:42.247Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:42.325Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr
21/11/2019 - 17:49:43.325Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:43.325Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
21/11/2019 - 17:49:43.403Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\B6JqeKo69y.xtr

Process
Trace

Analysis
Reason
Timeout

Status
Sucessfully Executed

Results
1

Registry
Trace
21/11/2019 - 17:45:44.122Write1480C:\malware.exeHKCU\Software\B6JqeKo69yServerStarted
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyEnable
21/11/2019 - 17:45:44.247Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyServer
21/11/2019 - 17:45:44.247Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyOverride
21/11/2019 - 17:45:44.247Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsAutoConfigURL
21/11/2019 - 17:45:44.247Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsAutoDetect
21/11/2019 - 17:45:44.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectionsSavedLegacySettings
21/11/2019 - 17:45:44.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ContentCachePrefix
21/11/2019 - 17:45:44.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\CookiesCachePrefix
21/11/2019 - 17:45:44.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\HistoryCachePrefix
21/11/2019 - 17:45:44.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:44.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:44.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:44.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:45.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:45.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:45.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:45.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:45:46.90Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:46.90Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:46.90Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:45:46.90Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:46.90Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:46.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:46.90Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:47.122Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:47.122Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:47.122Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:47.122Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:45:47.309Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:47.309Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:47.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:47.309Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:50.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:50.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:50.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:50.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:45:50.559Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:50.559Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:50.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:50.559Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:53.606Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:53.606Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:53.606Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:53.606Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:45:53.793Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:53.793Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:53.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:53.793Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:56.887Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:56.887Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:56.887Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:56.887Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:45:57.75Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:57.75Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:45:57.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:45:57.75Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:0.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:0.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:0.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:0.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:0.356Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:0.356Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:0.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:0.356Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:3.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:3.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:3.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:3.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:3.590Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:3.590Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:3.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:3.590Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:6.637Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:6.637Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:6.637Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:6.637Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:6.825Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:6.825Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:6.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:6.825Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:9.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:9.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:9.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:9.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:10.59Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:10.59Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:10.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:10.59Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:13.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:13.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:13.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:13.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:13.293Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:13.293Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:13.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:13.293Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:16.340Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:16.340Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:16.340Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:16.340Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:16.528Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:16.528Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:16.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:16.528Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:19.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:19.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:19.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:19.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:19.731Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:19.731Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:19.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:19.731Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:22.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:22.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:22.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:22.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:22.997Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:22.997Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:22.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:22.997Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:25.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:25.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:25.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:25.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:26.184Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:26.184Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:26.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:26.184Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:29.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:29.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:29.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:29.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:29.465Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:29.465Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:29.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:29.465Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:32.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:32.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:32.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:32.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:32.700Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:32.700Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:32.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:32.700Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:35.762Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:35.762Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:35.762Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:35.762Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:35.950Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:35.950Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:35.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:35.950Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:39.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:39.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:39.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:39.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:39.231Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:39.231Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:39.231Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:39.231Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:42.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:42.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:42.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:42.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:42.465Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:42.465Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:42.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:42.465Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:45.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:45.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:45.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:45.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:46.12Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:46.12Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:46.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:46.12Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:48.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:48.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:48.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:48.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:48.965Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:48.965Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:48.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:48.965Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:51.981Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:51.981Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:51.981Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:51.981Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:52.168Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:52.168Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:52.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:52.168Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:55.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:55.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:55.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:55.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:55.434Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:55.434Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:55.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:55.434Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:58.481Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:58.481Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:58.481Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:58.481Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:46:58.622Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:58.622Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:46:58.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:46:58.622Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:1.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:1.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:1.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:1.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:1.903Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:1.903Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:1.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:1.903Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:4.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:4.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:4.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:4.950Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:5.137Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:5.137Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:5.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:5.137Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:8.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:8.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:8.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:8.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:8.372Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:8.372Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:8.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:8.372Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:11.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:11.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:11.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:11.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:11.653Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:11.653Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:11.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:11.653Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:14.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:14.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:14.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:14.731Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:14.872Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:14.872Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:14.872Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:14.872Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:17.918Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:17.918Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:17.918Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:17.918Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:18.106Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:18.106Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:18.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:18.106Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:21.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:21.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:21.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:21.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:21.372Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:21.372Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:21.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:21.372Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:24.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:24.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:24.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:24.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:24.590Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:24.590Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:24.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:24.590Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:27.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:27.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:27.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:27.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:27.809Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:27.809Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:27.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:27.809Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:30.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:30.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:30.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:30.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:31.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:31.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:31.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:31.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:34.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:34.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:34.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:34.106Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:34.293Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:34.293Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:34.293Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:34.293Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:37.340Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:37.340Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:37.340Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:37.340Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:37.528Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:37.528Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:37.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:37.528Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:40.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:40.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:40.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:40.622Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:40.809Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:40.809Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:40.809Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:40.809Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:43.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:43.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:43.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:43.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:44.75Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:44.75Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:44.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:44.75Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:47.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:47.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:47.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:47.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:47.512Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:47.512Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:47.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:47.512Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:50.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:50.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:50.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:50.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:50.512Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:50.512Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:50.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:50.512Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:53.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:53.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:53.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:53.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:53.700Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:53.700Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:53.700Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:53.700Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:56.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:56.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:56.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:56.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:47:56.934Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:56.934Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:56.934Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:56.934Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:47:59.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:47:59.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:47:59.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:47:59.965Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:0.153Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:0.153Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:0.153Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:0.153Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:3.200Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:3.200Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:3.200Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:3.200Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:3.387Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:3.387Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:3.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:3.387Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:6.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:6.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:6.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:6.465Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:6.653Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:6.653Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:6.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:6.653Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:9.668Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:9.668Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:9.668Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:9.668Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:9.856Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:9.856Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:9.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:9.856Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:12.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:12.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:12.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:12.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:13.90Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:13.90Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:13.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:13.90Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:16.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:16.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:16.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:16.184Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:16.372Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:16.372Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:16.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:16.372Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:19.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:19.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:19.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:19.403Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:19.590Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:19.590Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:19.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:19.590Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:22.637Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:22.637Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:22.637Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:22.637Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:22.825Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:22.825Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:22.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:22.825Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:25.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:25.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:25.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:25.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:26.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:26.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:26.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:26.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:29.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:29.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:29.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:29.75Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:29.262Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:29.262Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:29.262Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:29.262Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:32.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:32.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:32.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:32.309Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:32.497Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:32.497Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:32.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:32.497Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:35.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:35.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:35.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:35.528Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:35.715Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:35.715Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:35.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:35.715Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:38.762Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:38.762Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:38.762Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:38.762Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:38.997Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:38.997Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:38.997Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:38.997Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:41.981Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:41.981Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:41.981Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:41.981Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:42.168Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:42.168Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:42.168Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:42.168Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:45.200Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:45.200Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:45.200Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:45.200Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:45.387Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:45.387Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:45.387Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:45.387Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:48.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:48.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:48.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:48.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:49.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:49.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:49.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:49.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:49.28Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:49.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:49.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:49.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:49.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:49.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:49.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:49.59Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:49.59Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:51.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:51.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:51.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:51.653Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:51.840Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:51.840Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:51.840Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:51.840Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:54.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:54.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:54.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:54.903Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:55.137Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:55.137Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:55.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:55.137Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:58.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:58.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:58.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:58.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:48:58.325Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:58.325Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:48:58.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:48:58.325Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:1.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:1.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:1.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:1.372Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:1.559Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:1.559Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:1.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:1.559Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:4.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:4.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:4.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:4.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:4.778Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:4.778Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:4.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:4.778Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:7.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:7.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:7.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:7.825Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:8.12Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:8.12Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:8.12Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:8.12Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:11.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:11.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:11.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:11.137Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:11.325Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:11.325Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:11.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:11.325Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:14.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:14.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:14.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:14.356Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:14.543Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:14.543Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:14.543Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:14.543Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:17.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:17.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:17.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:17.590Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:17.778Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:17.778Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:17.778Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:17.778Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:20.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:20.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:20.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:20.856Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:21.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:21.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:21.43Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:21.43Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:24.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:24.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:24.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:24.90Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:24.278Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:24.278Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:24.278Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:24.278Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:27.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:27.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:27.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:27.325Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:27.512Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:27.512Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:27.512Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:27.512Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:30.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:30.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:30.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:30.559Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:30.747Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:30.747Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:30.747Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:30.747Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:33.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:33.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:33.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:33.793Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:34.28Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:34.28Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:34.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:34.28Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:37.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:37.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:37.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:37.28Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:37.215Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:37.215Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:37.215Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:37.215Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:40.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:40.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:40.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:40.247Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
21/11/2019 - 17:49:40.434Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:40.434Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:40.434Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:40.434Delete1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
21/11/2019 - 17:49:43.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
21/11/2019 - 17:49:43.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
21/11/2019 - 17:49:43.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
21/11/2019 - 17:49:43.497Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl

File Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Process Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: True check_circle

Deleted
Identified: True check_circle

Browsers
Identified: False cancel

Internet
Identified: True check_circle

Loading...

DNS
Query
computer localhost arrow_forward computer gateway:50273 code hacku11.ddns.net.
computer localhost arrow_forward computer gateway:DNS code hacku11.ddns.net.

Response

TCP
Info

UDP
Info
computer localhost:67 arrow_forward computer localhost:68
computer localhost:50273 arrow_forward computer localhost:53
computer localhost:68 arrow_forward help_outline 255.255.255.255:67
computer localhost:53 arrow_forward computer localhost:50273

HTTP
Info

Summary
DNS
True check_circle

TCP
False cancel

UDP
True check_circle

HTTP
False cancel

Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

SVC (Kernel=Linear, NFS-BRMalware)
confidence: 97.41%
suspicious: False cancel

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 99.90%
suspicious: True check_circle

Random Forest (100 estimators, NFS-BRMalware)
confidence: 52.00%
suspicious: False cancel

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 49.73%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 100.00%
suspicious: True check_circle

Add to Collection
Download