• Nenhum resultado encontrado

Report #432

N/A
N/A
Protected

Academic year: 2023

Share "Report #432"

Copied!
224
0
0

Texto

(1)

Binary

DLL False

Size 1.14MB

trid 35.0% InstallShield setup

33.8% Win32 EXE PECompact compressed 22.4% Win64 Executable

3.6% Win32 Executable 1.6% OS/2 Executable

type PE

wordsize 32

Subsystem Windows CLI

Hashes

md5 3b7e22e97a6856fb6843704c9452ad87

sha1 c721ec219a9d6836bf12ac24cf4e22aa822fcb67

crc32 0x924e52ec

sha224 9625529e902294429a0dead35c7847d9266ee36b3959b34fc27ca9a1

sha256 cac61bfaf19636a4db63b11eca87a84e79e37b0d230354a11a37878927faaa e5

sha384 841860d393635b6659eb8dedb5fb4990db1623a8f12d007758cb2c796a65e b8cd15d7f1731b86c47470781542450f2a3

sha512 4d588d389c4117033cbf9b4807d212389507c974983a8e0bcb56c0303c587 2830460f409547521e72348968fd90a87adab345ef8e51381b6410061431b 960164

ssdeep 24576:Fp+6k/gxr/nIiYWMf9dQnPoY20k0XgBq/bPEUpPhOZy+hz7FFUj9SD+s w4LOTc:qFgxr/nIiYWMf9dQnPoY20k0XgBq/bPg

Report #432

Creation Date: Oct. 12, 2019, 3:39 p.m.

Last Update: Oct. 12, 2019, 3:43 p.m.

File:

044 Results:

(2)

Community

Google False

HashLib False

YARA

Matches maldoc_getEIP_method_1, domain, IP, win_private_profile, Dropper_Strings, Intel_Virtualization_Wizard_exe, HasDebugData, network_dropper, Antivirus , BASE64_table, escalate_priv, HasRichSignature, possible_includes_base64 _packed_functions, VM_Generic_Detection, VC8_Microsoft_Corporation, Deb uggerException__SetConsoleCtrl, spreading_share, IsConsole, create_servic e, network_dns, cred_local, network_http, win_files_operation, IsPE32, win_

hook, disable_dep, contentis_base64, network_tcp_socket, SEH__vectored, screenshot, win_token, win_mutex, keylogger, Misc_Suspicious_Strings, mal doc_find_kernel32_base_method_1, migrate_apc, antisb_threatExpert, Debu ggerHiding__Thread, anti_dbg, network_tcp_listen, DebuggerCheck__QueryI nfo, url, Microsoft_Visual_Cpp_8, win_registry, Typical_Malware_String_Trans forms, HasOverlay, network_dga, Advapi_Hash_API, Big_Numbers5, Crypt32 _CryptBinaryToString_API, create_com_service, Big_Numbers0

Suspicious True

Strings

List

<rdf:Description rdf:about="uuid:cf09c8e3-7814-11dc-b3b7-80a45141ec24" xmlns:pdf="http://ns.adobe.com/pdf/

1.3/">

<rdf:Description rdf:about="uuid:b58a55db-7817-11dc-b3b7-80a45141ec24" xmlns:pdf="http://ns.adobe.com/pdf/

1.3/">

<rdf:Description rdf:about="uuid:880b6202-923d-11dc-bf0f-889ae1191ecf" xmlns:pdf="http://ns.adobe.com/pdf/1.

3/">

<rdf:Description rdf:about="uuid:6f03c386-7819-11dc-b3b7-80a45141ec24" xmlns:pdf="http://ns.adobe.com/pdf/

1.3/">

<rdf:Description rdf:about="uuid:b1be9614-923d-11dc-bf0f-889ae1191ecf" xmlns:pdf="http://ns.adobe.com/pdf/1.

3/">

<rdf:Description rdf:about="uuid:9ec20a53-923d-11dc-bf0f-889ae1191ecf" xmlns:pdf="http://ns.adobe.com/pdf/1.

3/">

<rdf:Description rdf:about="uuid:0bbddd83-7818-11dc-b3b7-80a45141ec24" xmlns:stRef="http://ns.adobe.com/x ap/1.0/sType/ResourceRef#" xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">

<rdf:Description rdf:about="uuid:0bbddd7d-7818-11dc-b3b7-80a45141ec24" xmlns:stRef="http://ns.adobe.com/x ap/1.0/sType/ResourceRef#" xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">

<rdf:Description rdf:about="uuid:df90b7af-923d-11dc-bf0f-889ae1191ecf" xmlns:pdf="http://ns.adobe.com/pdf/1.3 /">

<rdf:Description rdf:about="uuid:0bbddd7d-7818-11dc-b3b7-80a45141ec24" xmlns:pdf="http://ns.adobe.com/pdf/

1.3/">

<rdf:Description rdf:about="uuid:0bbddd83-7818-11dc-b3b7-80a45141ec24" xmlns:pdf="http://ns.adobe.com/pdf/

1.3/">

<rdf:Description rdf:about="uuid:b58a55db-7817-11dc-b3b7-80a45141ec24" xmlns:stRef="http://ns.adobe.com/x

(3)

ap/1.0/sType/ResourceRef#" xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">

<rdf:Description rdf:about="uuid:6f03c386-7819-11dc-b3b7-80a45141ec24" xmlns:stRef="http://ns.adobe.com/xa p/1.0/sType/ResourceRef#" xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">

<rdf:Description rdf:about="uuid:70e4755a-7818-11dc-b3b7-80a45141ec24" xmlns:xap="http://ns.adobe.com/xa p/1.0/">

<rdf:Description rdf:about="uuid:cf09c8e3-7814-11dc-b3b7-80a45141ec24" xmlns:xap="http://ns.adobe.com/xap/

1.0/">

<rdf:Description rdf:about="uuid:70e47554-7818-11dc-b3b7-80a45141ec24" xmlns:xap="http://ns.adobe.com/xa p/1.0/">

<rdf:Description rdf:about="uuid:b58a55db-7817-11dc-b3b7-80a45141ec24" xmlns:xap="http://ns.adobe.com/xa p/1.0/">

<rdf:Description rdf:about="uuid:6f03c386-7819-11dc-b3b7-80a45141ec24" xmlns:xap="http://ns.adobe.com/xap /1.0/">

<rdf:Description rdf:about="uuid:70e47554-7818-11dc-b3b7-80a45141ec24" xmlns:stRef="http://ns.adobe.com/x ap/1.0/sType/ResourceRef#" xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">

<rdf:Description rdf:about="uuid:70e4755a-7818-11dc-b3b7-80a45141ec24" xmlns:stRef="http://ns.adobe.com/x ap/1.0/sType/ResourceRef#" xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">

<rdf:Description rdf:about="uuid:70e4755a-7818-11dc-b3b7-80a45141ec24" xmlns:pdf="http://ns.adobe.com/pdf/

1.3/">

<rdf:Description rdf:about="uuid:70e47554-7818-11dc-b3b7-80a45141ec24" xmlns:pdf="http://ns.adobe.com/pdf/

1.3/">

<rdf:Description rdf:about="uuid:1acf7d56-923e-11dc-bf0f-889ae1191ecf" xmlns:pdf="http://ns.adobe.com/pdf/1.

3/">

</dc:rights></rdf:Description><rdf:Description rdf:about="uuid:faf5bdd5-ba3d-11da-ad31-d33d75182f1b" xmlns:

tiff="http://ns.adobe.com/tiff/1.0/"/><rdf:Description rdf:about="uuid:faf5bdd5-ba3d-11da-ad31-d33d75182f1b" x mlns:exif="http://ns.adobe.com/exif/1.0/"/></rdf:RDF></x:xmpmeta>

</dc:rights></rdf:Description><rdf:Description rdf:about="uuid:faf5bdd5-ba3d-11da-ad31-d33d75182f1b" xmlns:

tiff="http://ns.adobe.com/tiff/1.0/"/><rdf:Description rdf:about="uuid:faf5bdd5-ba3d-11da-ad31-d33d75182f1b" x mlns:exif="http://ns.adobe.com/exif/1.0/"/></rdf:RDF></x:xmpmeta>

<rdf:Description rdf:about="uuid:880b6202-923d-11dc-bf0f-889ae1191ecf" xmlns:xapMM="http://ns.adobe.com/x ap/1.0/mm/">

<rdf:Description rdf:about="uuid:df90b7af-923d-11dc-bf0f-889ae1191ecf" xmlns:xapMM="http://ns.adobe.com/xa p/1.0/mm/">

<rdf:Description rdf:about="uuid:b1be9614-923d-11dc-bf0f-889ae1191ecf" xmlns:xap="http://ns.adobe.com/xap/

1.0/">

<rdf:Description rdf:about="uuid:9ec20a53-923d-11dc-bf0f-889ae1191ecf" xmlns:xapMM="http://ns.adobe.com/x ap/1.0/mm/">

<rdf:Description rdf:about="uuid:9ec20a53-923d-11dc-bf0f-889ae1191ecf" xmlns:xap="http://ns.adobe.com/xap/1 .0/">

<rdf:Description rdf:about="uuid:b1be9614-923d-11dc-bf0f-889ae1191ecf" xmlns:xapMM="http://ns.adobe.com/x ap/1.0/mm/">

<rdf:Description rdf:about="uuid:1acf7d56-923e-11dc-bf0f-889ae1191ecf" xmlns:xapMM="http://ns.adobe.com/xa p/1.0/mm/">

<rdf:Description rdf:about="uuid:c8e53c53-923d-11dc-bf0f-889ae1191ecf" xmlns:xapMM="http://ns.adobe.com/x ap/1.0/mm/">

<rdf:Description rdf:about="uuid:c8e53c53-923d-11dc-bf0f-889ae1191ecf" xmlns:xap="http://ns.adobe.com/xap/1 .0/">

<rdf:Description rdf:about="uuid:1acf7d56-923e-11dc-bf0f-889ae1191ecf" xmlns:xap="http://ns.adobe.com/xap/1 .0/">

<rdf:Description rdf:about="uuid:880b6202-923d-11dc-bf0f-889ae1191ecf" xmlns:xap="http://ns.adobe.com/xap/

1.0/">

<rdf:Description rdf:about="uuid:df90b7af-923d-11dc-bf0f-889ae1191ecf" xmlns:xap="http://ns.adobe.com/xap/1.

0/">

<rdf:Description rdf:about="uuid:cf09c8e3-7814-11dc-b3b7-80a45141ec24" xmlns:xapMM="http://ns.adobe.com/

xap/1.0/mm/">

<rdf:Description rdf:about="uuid:9ec20a53-923d-11dc-bf0f-889ae1191ecf" xmlns:tiff="http://ns.adobe.com/tiff/1.0 /">

<rdf:Description rdf:about="uuid:df90b7af-923d-11dc-bf0f-889ae1191ecf" xmlns:tiff="http://ns.adobe.com/tiff/1.0/

">

(4)

<rdf:Description rdf:about="uuid:b1be9614-923d-11dc-bf0f-889ae1191ecf" xmlns:tiff="http://ns.adobe.com/tiff/1.

0/">

<rdf:Description rdf:about="uuid:c8e53c53-923d-11dc-bf0f-889ae1191ecf" xmlns:pdf="http://ns.adobe.com/pdf/1.

3/">

<rdf:Description rdf:about="uuid:880b6202-923d-11dc-bf0f-889ae1191ecf" xmlns:tiff="http://ns.adobe.com/tiff/1.

0/">

<rdf:Description rdf:about="uuid:70e4755a-7818-11dc-b3b7-80a45141ec24" xmlns:tiff="http://ns.adobe.com/tiff/

1.0/">

<rdf:Description rdf:about="uuid:b58a55db-7817-11dc-b3b7-80a45141ec24" xmlns:tiff="http://ns.adobe.com/tiff/

1.0/">

<rdf:Description rdf:about="uuid:c8e53c53-923d-11dc-bf0f-889ae1191ecf" xmlns:exif="http://ns.adobe.com/exif/1 .0/">

<rdf:Description rdf:about="uuid:cf09c8e3-7814-11dc-b3b7-80a45141ec24" xmlns:tiff="http://ns.adobe.com/tiff/1.

0/">

<rdf:Description rdf:about="uuid:6f03c386-7819-11dc-b3b7-80a45141ec24" xmlns:tiff="http://ns.adobe.com/tiff/1 .0/">

<rdf:Description rdf:about="uuid:70e47554-7818-11dc-b3b7-80a45141ec24" xmlns:tiff="http://ns.adobe.com/tiff/

1.0/">

<rdf:Description rdf:about="uuid:1acf7d56-923e-11dc-bf0f-889ae1191ecf" xmlns:tiff="http://ns.adobe.com/tiff/1.0 /">

<rdf:Description rdf:about="uuid:0bbddd83-7818-11dc-b3b7-80a45141ec24" xmlns:xap="http://ns.adobe.com/xa p/1.0/">

<rdf:Description rdf:about="uuid:0bbddd7d-7818-11dc-b3b7-80a45141ec24" xmlns:xap="http://ns.adobe.com/xa p/1.0/">

<rdf:Description rdf:about="uuid:0bbddd83-7818-11dc-b3b7-80a45141ec24" xmlns:tiff="http://ns.adobe.com/tiff/

1.0/">

<rdf:Description rdf:about="uuid:0bbddd7d-7818-11dc-b3b7-80a45141ec24" xmlns:tiff="http://ns.adobe.com/tiff/

1.0/">

<rdf:Description rdf:about="uuid:c8e53c53-923d-11dc-bf0f-889ae1191ecf" xmlns:tiff="http://ns.adobe.com/tiff/1.0 /">

<rdf:Description rdf:about="uuid:df90b7af-923d-11dc-bf0f-889ae1191ecf" xmlns:exif="http://ns.adobe.com/exif/1.

0/">

<rdf:Description rdf:about="uuid:9ec20a53-923d-11dc-bf0f-889ae1191ecf" xmlns:exif="http://ns.adobe.com/exif/1 .0/">

<rdf:Description rdf:about="uuid:880b6202-923d-11dc-bf0f-889ae1191ecf" xmlns:exif="http://ns.adobe.com/exif/

1.0/">

<rdf:Description rdf:about="uuid:1acf7d56-923e-11dc-bf0f-889ae1191ecf" xmlns:exif="http://ns.adobe.com/exif/1.

0/">

<rdf:Description rdf:about="uuid:b1be9614-923d-11dc-bf0f-889ae1191ecf" xmlns:exif="http://ns.adobe.com/exif/

1.0/">

<rdf:Description rdf:about="uuid:9ec20a53-923d-11dc-bf0f-889ae1191ecf" xmlns:photoshop="http://ns.adobe.co m/photoshop/1.0/">

<rdf:Description rdf:about="uuid:1acf7d56-923e-11dc-bf0f-889ae1191ecf" xmlns:photoshop="http://ns.adobe.com /photoshop/1.0/">

<rdf:Description rdf:about="uuid:70e4755a-7818-11dc-b3b7-80a45141ec24" xmlns:photoshop="http://ns.adobe.c om/photoshop/1.0/">

<rdf:Description rdf:about="uuid:880b6202-923d-11dc-bf0f-889ae1191ecf" xmlns:photoshop="http://ns.adobe.co m/photoshop/1.0/">

<rdf:Description rdf:about="uuid:cf09c8e3-7814-11dc-b3b7-80a45141ec24" xmlns:photoshop="http://ns.adobe.co m/photoshop/1.0/">

<rdf:Description rdf:about="uuid:70e47554-7818-11dc-b3b7-80a45141ec24" xmlns:photoshop="http://ns.adobe.c om/photoshop/1.0/">

<rdf:Description rdf:about="uuid:b58a55db-7817-11dc-b3b7-80a45141ec24" xmlns:photoshop="http://ns.adobe.c om/photoshop/1.0/">

<rdf:Description rdf:about="uuid:c8e53c53-923d-11dc-bf0f-889ae1191ecf" xmlns:photoshop="http://ns.adobe.co m/photoshop/1.0/">

<rdf:Description rdf:about="uuid:6f03c386-7819-11dc-b3b7-80a45141ec24" xmlns:photoshop="http://ns.adobe.co m/photoshop/1.0/">

<rdf:Description rdf:about="uuid:b1be9614-923d-11dc-bf0f-889ae1191ecf" xmlns:photoshop="http://ns.adobe.co

(5)

m/photoshop/1.0/">

<rdf:Description rdf:about="uuid:df90b7af-923d-11dc-bf0f-889ae1191ecf" xmlns:photoshop="http://ns.adobe.com /photoshop/1.0/">

<rdf:Description rdf:about="uuid:b58a55db-7817-11dc-b3b7-80a45141ec24" xmlns:exif="http://ns.adobe.com/exif /1.0/">

<rdf:Description rdf:about="uuid:cf09c8e3-7814-11dc-b3b7-80a45141ec24" xmlns:exif="http://ns.adobe.com/exif/

1.0/">

<rdf:Description rdf:about="uuid:70e47554-7818-11dc-b3b7-80a45141ec24" xmlns:exif="http://ns.adobe.com/exif /1.0/">

<rdf:Description rdf:about="uuid:70e4755a-7818-11dc-b3b7-80a45141ec24" xmlns:exif="http://ns.adobe.com/exif /1.0/">

<rdf:Description rdf:about="uuid:6f03c386-7819-11dc-b3b7-80a45141ec24" xmlns:exif="http://ns.adobe.com/exif/

1.0/">

<rdf:Description rdf:about="uuid:0bbddd7d-7818-11dc-b3b7-80a45141ec24" xmlns:exif="http://ns.adobe.com/exi f/1.0/">

<rdf:Description rdf:about="uuid:0bbddd83-7818-11dc-b3b7-80a45141ec24" xmlns:exif="http://ns.adobe.com/exi f/1.0/">

<rdf:Description rdf:about="uuid:0bbddd83-7818-11dc-b3b7-80a45141ec24" xmlns:photoshop="http://ns.adobe.c om/photoshop/1.0/">

<rdf:Description rdf:about="uuid:0bbddd7d-7818-11dc-b3b7-80a45141ec24" xmlns:photoshop="http://ns.adobe.c om/photoshop/1.0/">

1. Visit https://tox.chat/download.html qhttp://ns.adobe.com/xap/1.0/

qhttp://ns.adobe.com/xap/1.0/

http://ns.adobe.com/xap/1.0/

http://ns.adobe.com/xap/1.0/

http://ns.adobe.com/xap/1.0/

http://ns.adobe.com/xap/1.0/

http://ns.adobe.com/xap/1.0/

http://ns.adobe.com/xap/1.0/

http://ns.adobe.com/xap/1.0/

=http://ns.adobe.com/xap/1.0/

=http://ns.adobe.com/xap/1.0/

=http://ns.adobe.com/xap/1.0/

=http://ns.adobe.com/xap/1.0/

=http://ns.adobe.com/xap/1.0/

=http://ns.adobe.com/xap/1.0/

1. Download Tor browser - https://www.torproject.org/

<rdf:Description rdf:about="uuid:1acf7d56-923e-11dc-bf0f-889ae1191ecf" xmlns:dc="http://purl.org/dc/elements/

1.1/">

<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>

<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>

Foremost

Matches 0.exe, 94 KB

Suspicious True

Heuristics

IPs hasIPs: False

Allowed Suspicious

hasAllowed: False

(6)

hasSuspicious: False

URLs Allowed

hasURLs: True

Suspicious: http://gdcbghvjyqy7jclk.onion/3a23db8448d3b2b, https://tox.c hat/download.html, https://www.torproject.org/

hasAllowed: False hasSuspicious: True

Files Allowed: 2ntdll.dll, WININET.dll, shlwapi.dll, MSVCR110.dll, CRYPT32.dll, SH ELL32.dll, user32.dll, ADVAPI32.dll, PSAPI.DLL, kernel32.dll, GDI32.dll, msvc rt.dll, urlmon.dll, encryption.dll

hasFiles: True

Suspicious: GDCB-DECRYPT.txt, %s\GDCB-DECRYPT.txt, ntuser.dat, ntuser.

dat.log, thumbs.db, iconcache.db hasAllowed: True

hasSuspicious: True

Binary

Sizes RVA

RVA: 16

Suspicious: False Code

Size: 93696

Suspicious: False Image

Address: 4194304 Suspicious: False Stack

Stack: 4096 Suspicious: False Headers

Headers: 1024 Suspicious: False Suspicious: False

Symbols Number

Number: 0

Suspicious: True Pointer

Pointer: 0

Suspicious: True Directories Number: 16 Suspicious: False

Checksum Value: 0

Suspicous: True

Sections Allowed: .text, .rdata, .data, .rsrc, .reloc

(7)

Suspicious

hasAllowed: True hasSections: True hasSuspicious: False

Versions OS

Version: 6

Suspicious: False Image

Version: True Suspicious: 6 Linker

Version: 11.0 Suspicious: False Subsystem

Version: 6.0 Suspicious: False Suspicious: False

EntryPoint Address: 4951

Suspicious: False

Anomalies Anomalies: The header checksum and the calculated checksum do not ma tch.

hasAnomalies: True

Libraries Allowed: wininet.dll, shlwapi.dll, crypt32.dll, shell32.dll, user32.dll, advapi 32.dll, psapi.dll, kernel32.dll, gdi32.dll, msvcrt.dll, urlmon.dll

hasLibs: True

Suspicious: 2ntdll.dll, msvcr110.dll, encryption.dll hasAllowed: True

hasSuspicious: True

Timestamp Past: False

Valid: True

Value: 2019-08-28 13:35:58 Future: False

Compilation Packed: False

Missing: False Packers

Compiled: True

Compilers: Microsoft Visual C++ 8, VC8 -> Microsoft Corporation

Obfuscation XOR: True

Fuzzing: False

PEDetector

(8)

Matches 6304, 78097

Suspicious True

Disassembly

hasTricks True

Tricks

ldr .rsrc: 2

pushret .rsrc: 11

.text: 1

nopsequence .rsrc: 2

pushpopmath .rsrc: 13

sizeofimage .rsrc: 2

garbagebytes .rsrc: 4

.text: 1

hookdetection .rsrc: 1

programcontrolflowchange .rsrc: 4 .text: 1

cpuinstructionsresultscomparison .rdata: 1

AVclass

wapomi 1

VirusTotal

md5 3b7e22e97a6856fb6843704c9452ad87

sha1 c721ec219a9d6836bf12ac24cf4e22aa822fcb67

SCANS (DETECTION RATE = 71.43%)

(9)

AVG result: Win32:Rootkit-gen [Rtk]

update: 20190910 version: 18.4.3895.0 detected: True

CMC update: 20190321

version: 1.1.0.977 detected: False

MAX result: malware (ai score=82)

update: 20190910 version: 2018.9.12.1 detected: True

APEX result: Malicious

update: 20190910 version: 5.62 detected: True

Bkav update: 20190910

version: 1.3.0.10239 detected: False

K7GW update: 20190910

version: 11.66.31967 detected: False

ALYac result: Win32.VJadtre.3

update: 20190910 version: 1.1.1.5 detected: True

Avast result: Win32:Rootkit-gen [Rtk]

update: 20190910 version: 18.4.3895.0 detected: True

Avira result: W32/Jadtre.B

update: 20190910 version: 8.3.3.8 detected: True

Baidu result: Win32.Virus.Otwycal.d

update: 20190318 version: 1.0.0.2 detected: True

(10)

Cyren result: W32/PatchLoad.E update: 20190910 version: 6.2.0.1 detected: True

DrWeb result: Trojan.Encoder.24384

update: 20190910 version: 7.0.41.7240 detected: True

GData result: Win32.VJadtre.3

update: 20190910

version: A:25.23339B:26.15997 detected: True

Panda result: Generic Suspicious

update: 20190910 version: 4.6.4.2 detected: True

VBA32 result: Virus.Nimnul.19209

update: 20190910 version: 4.0.0 detected: True

VIPRE result: Trojan.Win32.Generic!BT

update: 20190910 version: 77768 detected: True

Zoner update: 20190910

version: 1.0.0.1 detected: False

ClamAV result: Win.Ransomware.Gandcrab-6502432-0

update: 20190910 version: 0.101.4.0 detected: True

Comodo update: 20190910

version: 31455 detected: False

F-Prot result: W32/PatchLoad.E

update: 20190910 version: 4.7.1.166 detected: True

(11)

Ikarus result: Virus.Win32.Wapomi update: 20190910

version: 0.1.5.2 detected: True

McAfee result: Artemis!3B7E22E97A68

update: 20190910 version: 6.0.6.653 detected: True

Rising result: Ransom.GandCrab!1.B8D6 (CLASSIC)

update: 20190910 version: 25.0.0.24 detected: True

Sophos result: Mal/Generic-S

update: 20190910 version: 4.98.0 detected: True

Yandex update: 20190910

version: 5.5.2.24 detected: False

Zillya update: 20190910

version: 2.0.0.3897 detected: False

Acronis update: 20190904

version: 1.1.1.56 detected: False

Alibaba result: Virus:Win32/Nimnul.e04fd7e6

update: 20190527 version: 0.3.0.5 detected: True

Arcabit result: Win32.VJadtre.3

update: 20190910 version: 1.0.0.856 detected: True

Cylance update: 20190910

version: 2.3.1.101 detected: False

(12)

Endgame result: malicious (high confidence) update: 20190819

version: 3.0.14 detected: True

FireEye result: Generic.mg.3b7e22e97a6856fb

update: 20190910 version: 29.7.0.0 detected: True

TACHYON update: 20190910

version: 2019-09-10.02 detected: False

Tencent result: Virus.Win32.Loader.aab

update: 20190910 version: 1.0.0.1 detected: True

ViRobot update: 20190910

version: 2014.3.20.0 detected: False

Webroot update: 20190910

version: 1.0.0.403 detected: False

eGambit result: Trojan.Generic

update: 20190910 version: v5.0.5 detected: True

Ad-Aware result: Win32.VJadtre.3

update: 20190910 version: 3.0.5.370 detected: True

AegisLab result: Virus.Win32.Nimnul.n!c

update: 20190910 version: 4.2 detected: True

Emsisoft result: Win32.VJadtre.3 (B)

update: 20190910 version: 2018.12.0.1641 detected: True

(13)

F-Secure result: Malware.W32/Jadtre.B update: 20190910

version: 12.0.86.52 detected: True

Fortinet result: W32/Wapomi.BA!tr

update: 20190910 version: 5.4.247.0 detected: True

Invincea update: 20190904

version: 6.3.6.26157 detected: False

Jiangmin update: 20190910

version: 16.0.100 detected: False

Kingsoft update: 20190910

version: 2013.8.14.323 detected: False

Paloalto result: generic.ml

update: 20190910 version: 1.0 detected: True

Symantec result: ML.Attribute.HighConfidence update: 20190910

version: 1.10.0.0 detected: True

Trapmine update: 20190826

version: 3.1.81.800 detected: False

AhnLab-V3 result: Trojan/Win32.Xtrat.C3450632 update: 20190910

version: 3.16.1.25089 detected: True

Antiy-AVL result: Virus/Win32.Nimnul.f

update: 20190910 version: 3.0.0.1 detected: True

(14)

Kaspersky result: Virus.Win32.Nimnul.f update: 20190910

version: 15.0.1.13 detected: True

Microsoft result: Ransom:Win32/GandCrab.AE

update: 20190910 version: 1.1.16300.1 detected: True

Qihoo-360 result: Win32/Virus.IM.01a

update: 20190910 version: 1.0.0.1120 detected: True

ZoneAlarm result: Virus.Win32.Nimnul.f

update: 20190910 version: 1.0 detected: True

Cybereason result: malicious.97a685

update: 20190616 version: 1.2.449 detected: True

ESET-NOD32 result: Win32/Wapomi.BA

update: 20190910 version: 19995 detected: True

TrendMicro result: PE_WAPOMI.BM

update: 20190910 version: 11.0.0.1006 detected: True

BitDefender result: Win32.VJadtre.3

update: 20190910 version: 7.2 detected: True

CrowdStrike result: win/malicious_confidence_60% (W) update: 20190702

version: 1.0 detected: True

K7AntiVirus update: 20190910

version: 11.66.31969 detected: False

(15)

SentinelOne result: DFI - Malicious PE update: 20190807 version: 1.0.31.22 detected: True

Avast-Mobile update: 20190910

version: 190910-00 detected: False

Malwarebytes result: Virus.Wapomi

update: 20190910 version: 2.1.1.1115 detected: True

TotalDefense result: Win32/Nimnul.A

update: 20190910 version: 37.1.62.1 detected: True

CAT-QuickHeal update: 20190909

version: 14.00 detected: False

NANO-Antivirus result: Trojan.Win32.Banload.cstqaj update: 20190910

version: 1.0.134.24859 detected: True

MicroWorld-eScan result: Win32.VJadtre.3 update: 20190910 version: 14.0.297.0 detected: True

SUPERAntiSpyware update: 20190906

version: 5.6.0.1032 detected: False

McAfee-GW-Edition result: BehavesLike.Win32.Ramnit.tm update: 20190910

version: v2017.3010 detected: True

TrendMicro-HouseCall result: PE_WAPOMI.BM update: 20190910 version: 10.0.0.1040

(16)

total 70

sha256 cac61bfaf19636a4db63b11eca87a84e79e37b0d230354a11a37878927faaa e5

scan_id cac61bfaf19636a4db63b11eca87a84e79e37b0d230354a11a37878927faaa e5-1568144177

resource 3b7e22e97a6856fb6843704c9452ad87

permalink https://www.virustotal.com/file/cac61bfaf19636a4db63b11eca87a84e79e3 7b0d230354a11a37878927faaae5/analysis/1568144177/

positives 50

scan_date 2019-09-10 19:36:17

verbose_msg Scan finished, information embedded

response_code 1

File

Trace

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Windows\SysWOW64\apphelp.dll

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Windows\SysWOW64\apphelp.dll

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Windows\AppPatch\sysmain.sdb

3/5/20 18 - 1 8:45:4

O p e

C:\malware.ex

e C:\Monitor

(17)

3.512 n

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\Monitor

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Monitor

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\Monitor

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Monitor

3/5/20 U n

(18)

18 - 1 8:45:4 3.512

n o w n

C:\malware.ex e

C:\Monitor

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

R e a d

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Monitor\ui\SwDRM.dll

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

O p e n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4

U n k n o

C:\malware.ex

e C:\Monitor\proc.exe

(19)

3.512 w n

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\Windows

3/5/20 18 - 1 8:45:4 3.512

U n k n o w n

C:\malware.ex

e C:\Monitor

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\Prefetch\PROC.EXE-5509F567.pf

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\System32\wow64.dll

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\System32\wow64.dll

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\System32\wow64win.dll

3/5/20 18 - 1 8:45:4

O p

e C:\Monitor\pro

c.exe C:\Windows\System32\wow64win.dll

(20)

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\System32\wow64cpu.dll

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\System32\wow64cpu.dll

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\System32\wow64log.dll

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows

3/5/20 18 - 1 8:45:4 3.528

U n k n o w n

C:\Monitor\pro

c.exe C:\Windows

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Monitor

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.528

U n k n o w n

C:\Monitor\pro

c.exe C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\sechost.dll

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\sechost.dll

(21)

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Monitor\version.DLL

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\version.dll

3/5/20 18 - 1 8:45:4 3.528

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\version.dll

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

W ri t e

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

(22)

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

W ri t e

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\apphelp.dll

(23)

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Windows\SysWOW64\apphelp.dll

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Windows\AppPatch\sysmain.sdb

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users

3/5/20 U n

(24)

18 - 1 8:45:4 3.543

n o w n

C:\Monitor\pro

c.exe C:\Users

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp

(25)

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp

3/5/20 18 - 1 8:45:4 3.543

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp

3/5/20 18 - 1 8:45:4 3.543

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.543

R e a d

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.559

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\ui\SwDRM.dll

3/5/20 18 - 1 8:45:4 3.559

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.559

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.559

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.559

O p e n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1

U n k

n C:\Monitor\pro C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

(26)

3.559 o w n

3/5/20 18 - 1 8:45:4 3.559

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.559

U n k n o w n

C:\Monitor\pro

c.exe C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\Prefetch\VSQSHX.EXE-1464A4CE.pf

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\System32\wow64.dll

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\System32\wow64.dll

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\System32\wow64win.dll

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\System32\wow64win.dll

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\System32\wow64cpu.dll

3/5/20 O C:\Users\Behe

(27)

18 - 1 8:45:4 3.653

p e n

mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\System32\wow64cpu.dll

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\System32\wow64log.dll

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows

3/5/20 18 - 1 8:45:4 3.653

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows

3/5/20 18 - 1 8:45:4 3.653

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\sechost.dll

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\sechost.dll

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\version.DLL

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\version.dll

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\version.dll

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\imm32.dll

(28)

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\imm32.dll

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.668

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.668

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.668

R e a d

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\vSQshX.exe

3/5/20 18 - 1 8:45:4 3.731

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\Globalization\Sorting\SortDefault.nls

3/5/20 U n

C:\Users\Behe

(29)

18 - 1 8:45:4 3.731

k n o w n

mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\Globalization\Sorting\SortDefault.nls SortDefault.nls

3/5/20 18 - 1 8:45:4 3.731

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\uxtheme.dll

3/5/20 18 - 1 8:45:4 3.731

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\uxtheme.dll

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\api-ms-win-downlev el-shlwapi-l2-1-0.dll

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1- 0.dll

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1- 0.dll

api-ms-win-downlevel-sh lwapi-l2-1-0.dll

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1- 0.dll

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1- 0.dll

api-ms-win-downlevel-sh lwapi-l2-1-0.dll

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\Secur32.dll

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\secur32.dll

(30)

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\secur32.dll

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\Tempor ary Internet Files

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\Tempor ary Internet Files

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\api-ms-win-downlev el-advapi32-l2-1-0.dll

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1 -0.dll

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1 -0.dll

api-ms-win-downlevel-a dvapi32-l2-1-0.dll

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1 -0.dll

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1 -0.dll

api-ms-win-downlevel-a dvapi32-l2-1-0.dll

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\

3/5/20 18 - 1

O p

C:\Users\Behe

mot\AppData\L C:\$Recycle.Bin

(31)

8:45:4 3.778

e n

ocal\Temp\vSQ shX.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\$Recycle.Bin\S-1-5-21-2148495166-3420019059-128609 3062-1001

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\$Recycle.Bin\S-1-5-21-2148495166-3420019059-128609 3062-1001

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\$Recycle.Bin

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Arquivos de Programas

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Arquivos de Programas

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\Files

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\Files\DeletedFiles

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\Files\DeletedFiles

(32)

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\Files\Logs

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\Files\Logs

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\Files

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\Malware

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\malware.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\malware.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\malware.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\malware.exe

3/5/20 18 - 1 8:45:4

U n k n o

C:\Users\Behe mot\AppData\L

ocal\Temp\vSQ C:\malware.exe

(33)

3.778 w n

shX.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\malware.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\Malware

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\proc.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WindowsKernelCaptureDriver Package

3/5/20 18 - 1 8:45:4 3.778

U n k n o w

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WindowsKernelCaptureDriver Package

(34)

n

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WKCDController.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WKCDController.exe WKCDController.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WKCDController.exe WKCDController.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WKCDController.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WKCD_Load_Use.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WKCD_Load_Use.exe WKCD_Load_Use.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WKCD_Load_Use.exe WKCD_Load_Use.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\WKCD_Load_Use.exe

3/5/20 18 - 1 8:45:4

O p e

C:\Users\Behe mot\AppData\L

ocal\Temp\vSQ C:\Monitor\zip.exe

(35)

3.778 n shX.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

W ri t e

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

W ri t e

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

(36)

3/5/20 18 - 1 8:45:4 3.778

W ri t e

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor\zip.exe

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Monitor

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\PerfLogs

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\PerfLogs\Admin

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\PerfLogs\Admin

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\PerfLogs

3/5/20 O C:\Users\Behe

(37)

18 - 1 8:45:4 3.778

p e n

mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\Arquivos Comuns

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\Arquivos Comuns

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\DVDMaker.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\DVDMaker.exe

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\pt-BR

3/5/20 18 - 1 8:45:4 3.778

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\pt-BR

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared

3/5/20 18 - 1 8:45:4 3.778

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles

3/5/20 18 - 1 8:45:4 3.793

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy

(38)

3/5/20 18 - 1 8:45:4 3.793

R e a d

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy

3/5/20 18 - 1 8:45:4 3.856

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\Tempor ary Internet Files\counters.dat

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\winhttp.dll

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\winhttp.dll

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\webio.dll

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\webio.dll

3/5/20 18 - 1 8:45:4 3.872

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\BabyBoy

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\IPHLPAPI.DLL

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\IPHLPAPI.DLL

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\IPHLPAPI.DLL

3/5/20 18 - 1

O p

C:\Users\Behe

mot\AppData\L C:\Users\Behemot\AppData\Local\Temp\WINNSI.DLL

(39)

8:45:4 3.872

e n

ocal\Temp\vSQ shX.exe

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\winnsi.dll

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\winnsi.dll

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\DNSAPI.dll

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\dnsapi.dll

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\dnsapi.dll

3/5/20 18 - 1 8:45:4 3.872

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl

3/5/20 18 - 1 8:45:4 3.872

R e a d

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\mswsock.dll

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\mswsock.dll

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\wship6.dll

3/5/20 18 - 1 8:45:4

O p e

C:\Users\Behe mot\AppData\L

ocal\Temp\vSQ C:\Windows\SysWOW64\wship6.dll

(40)

3.918 n shX.exe

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\Tempor ary Internet Files

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\Tempor ary Internet Files

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\Tempor ary Internet Files

(41)

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\Tempor ary Internet Files\Content.IE5

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\Tempor ary Internet Files\Content.IE5

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Roaming

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Roaming

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Roaming

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Coo kies

3/5/20 18 - 1

O p

C:\Users\Behe

mot\AppData\L C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Coo

(42)

3.918 n shX.exe

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Coo kies

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Coo kies

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Coo kies

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local

3/5/20 18 - 1 8:45:4 3.918

U n k n o

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local

(43)

w n

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\History

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\History

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\History

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\History

\History.IE5

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Microsoft\Windows\History

\History.IE5

3/5/20 18 - 1 8:45:4 3.918

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\BabyGirl

3/5/20 18 - 1 8:45:4 3.918

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage

3/5/20 18 - 1 8:45:4 3.918

R e a d

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage

3/5/20 18 - 1 8:45:4 3.965

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\rpcss.dll

(44)

3/5/20 18 - 1 8:45:4 3.965

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\rpcss.dll

3/5/20 18 - 1 8:45:4 3.965

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\FlipPage

3/5/20 18 - 1 8:45:4 3.965

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\Full

3/5/20 18 - 1 8:45:4 3.965

R e a d

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\Full

3/5/20 18 - 1 8:45:4 4.12

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\netprofm.dll

3/5/20 18 - 1 8:45:4 4.12

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\netprofm.dll

3/5/20 18 - 1 8:45:4 4.12

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\nlaapi.dll

3/5/20 18 - 1 8:45:4 4.12

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\nlaapi.dll

3/5/20 18 - 1 8:45:4 4.12

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\Full

3/5/20 18 - 1 8:45:4 4.12

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle

(45)

3/5/20 18 - 1 8:45:4 4.12

R e a d

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle

3/5/20 18 - 1 8:45:4 4.59

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\dhcpcsvc6.DLL

3/5/20 18 - 1 8:45:4 4.59

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\dhcpcsvc6.dll

3/5/20 18 - 1 8:45:4 4.59

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\dhcpcsvc6.dll dhcpcsvc6.dll

3/5/20 18 - 1 8:45:4 4.59

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\dhcpcsvc6.dll

3/5/20 18 - 1 8:45:4 4.59

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\dhcpcsvc6.dll dhcpcsvc6.dll

3/5/20 18 - 1 8:45:4 4.59

U n k n o w n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\HueCycle

3/5/20 18 - 1 8:45:4 4.59

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles

3/5/20 18 - 1 8:45:4 4.59

R e a d

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Program Files\DVD Maker\Shared\DvdStyles\LayeredTitles

3/5/20 O C:\Users\Behe

(46)

18 - 1 8:45:4 4.106

p e n

mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\WSHTCPIP.DLL

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\WSHTCPIP.DLL

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\dhcpcsvc.DLL

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\dhcpcsvc.dll

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\dhcpcsvc.dll

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Users\Behemot\AppData\Local\Temp\CRYPTSP.dll

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\cryptsp.dll

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\cryptsp.dll

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\rsaenh.dll

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\rsaenh.dll

3/5/20 18 - 1 8:45:4 4.106

O p e n

C:\Users\Behe mot\AppData\L ocal\Temp\vSQ shX.exe

C:\Windows\SysWOW64\rsaenh.dll

3/5/20 18 - 1

O p

C:\Users\Behe

mot\AppData\L C:\Windows\SysWOW64\rsaenh.dll

Referências

Documentos relacionados

ws2_32.dll ws2_32.dll olepro32.dll comctl32.dll comctl32.dll comctl32.dll comctl32.dll comctl32.dll wship6.dll version.dll WINMM.dll UxTheme.dll wininet.dll uxtheme.dll 0.0.0.0

Files Allowed: kernel32.dll, USER32.dll, mscoree.dll, GDI32.dll hasFiles:

report.log COMCTL32.dll MSVCR110.dll WS2_32.dll WININET.dll ,&amp;combase.dll WINTRUST.dll data\surfaud.dat WINMM.dll WINMM.dll UxTheme.dll iphlpapi.dll dbghelp.dll

Libraries Allowed: mapi32.dll, mtxex.dll, ws2_32.dll, user32.dll, uxtheme.dll, dwmap i.dll, wininet.dll, ole32.dll, imm32.dll, advapi32.dll, comctl32.dll, shfolder.dll,

Files Allowed: rarext64.dll, rarext.dll, riched20.dll, KERNEL32.DLL, cabinet.dll, U nAceV2.Dll, Wkernel32.dll, mscoree.dll, \SOFTWARE\Microsoft\Windows\Curr

Files Allowed: user32.dll, kernel32.dll, uxtheme.dll, gdi32.dll, crypt32.dll, coleto r.dll, vcltest3.dll, pstorec.dll, MAPI32.DLL, version.dll, comctl32.dll, shell32.d ll,

Files Allowed: KERNEL32.DLL, Crypt32.dll, riched32.dll, riched20.dll, mscoree.dl l, ADVAPI32.dll, SHLWAPI.dll, OLEAUT32.dll, SHELL32.dll, GDI32.dll, COMCTL 32.dll,

Files Allowed: kernel32.dll, ntdll.dll, psapi.dll, mscoree.dll, dnsapi.dll,