VMRay Analyzer Report
Localhost
Logfile Output
X
Occurrences
World IP Map
IP World Map
Involved Hosts
Domain IP Used Country City
update.microsoft.com157.56.96.56, 191.232.80.55domain/ip_address--
time.windows.com137.170.185.211domain/ip_addressUSDonnelsville
IP not resolvable157.56.96.56ip_addressUSRedmond
Behavior Information
ID#1
OS PID0xb50
OS Parent PID0x830
Image Name089c5446291c9145ad8ac6c1cdfe4928.exe
Page Root0x79d9e000
Monitor Reasonanalysis_target
Unmonitor Reasonself_terminated
CMD Line"C:\Users\user\Desktop\089c5446291c9145ad8ac6c1cdfe4928.exe"
Current DirectoryC:\Users\user\Desktop\
Host Behavior
Operation File Additional Information Success Amount Logfile
CREATE_MAPPINGSystem Paging Filemaximum_size = 0x61646, protection = PAGE_READWRITETrue1
Bin
Fn
CREATE_MAPPINGSystem Paging Filemaximum_size = 0x8000, protection = PAGE_EXECUTE_READWRITE, SEC_COMMITTrue1
Bin
Fn
FINDC:\Program Files\Agnitum\*-False1
Bin
Fn
OPEN_MAPPING\BaseNamedObjects\ShimSharedMemory-False1
Bin
Fn
OPEN_MAPPING\BaseNamedObjects\windows_shell_global_counters-True1
Bin
Fn
Operation Key Additional Information Success Amount Logfile
OPEN_KEYHKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography-True1
Bin
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Cryptographyvalue_name = MachineGuid, data = 5b914348-258a-4617-b462-d107efea3e7bTrue1
Bin
Fn
Operation Process Additional Information Success Amount Logfile
ENUMERATE--True2
Bin
Fn
OPENc:\windows\explorer.exeos_pid = 0x830, desired_access = PROCESS_VM_READ, PROCESS_QUERY_INFORMATIONTrue1
Bin
Fn
Operation Address Additional Information Success Amount Logfile
READ0x7fffffd4018os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x777a2650os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1925e0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x192472os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1926d0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x77785418os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x192a50os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x192a28os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x192bc0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x192b98os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1938b0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x193888os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1939f0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1939c8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x193e80os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x193e58os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x193cf0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x193c88os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a49d0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a49a8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a4b10os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a4ae8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a4c40os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a4c28os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a4d80os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a4d58os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a4ec0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a4e98os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a5000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a4fd8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a5940os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a5918os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a5a80os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a5a58os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a5e90os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a5e58os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a6fb0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a5fd8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a70a0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6028os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7190os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6118os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7280os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6168os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7370os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a61b8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7460os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6208os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7550os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6258os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7640os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a62a8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7730os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a62f8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7820os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6348os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7910os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a5c08os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7af0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a7ad0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7be0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a63e8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7cd0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6438os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7dc0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6488os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a7eb0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6618os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a8180os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6668os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a8270os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1ce640os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a8360os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1bf168os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a8540os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6708os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a89f0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6e88os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a8ae0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1a6ed8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a8bd0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d3768os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a8cc0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d3858os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1a8db0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d38f8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1eec70os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d3998os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1eed60os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d3a38os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1eee50os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d3b28os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1eef40os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1dceb8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1ef030os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d3ee8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1ef120os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d3f88os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1ef210os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d3f38os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1ef4e0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d4348os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1ef5d0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x2091e8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1ef6c0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d4398os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1ef7b0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d4578os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1ef8a0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x216cf8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1ef990os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x221bf8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1efc60os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x221f18os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1efd50os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x221f68os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1eff30os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x2784c8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1f05c0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x278928os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1f06b0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x23f308os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1f0a70os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29f2398os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1f0980os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29f23e8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x1f0890os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29f2438os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x286d40os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29f2488os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x286e30os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29d9b58os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x287010os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29e97e8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x287100os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29e9888os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x2871f0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29e9a18os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x2872e0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29e9ab8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x2873d0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29e9b08os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x2874c0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29ea0a8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x2875b0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29d8d88os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x2876a0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x29ccf56os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x287790os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x2a33468os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x287880os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x2a33558os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x287b50os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x2a3b528os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x288870os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x2a34138os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x288a50os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3d7dfb8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3da5460os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x28b9b8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3da69f0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ddbfd8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3da6ae0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ddc028os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3da6bd0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ddc118os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3da6cc0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ddc168os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3da6db0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ddc2a8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3da6ea0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ddc1b8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3da6f90os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ddc488os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deae90os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ddc708os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deaf80os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ddc7a8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb070os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3dd8b78os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb160os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3dd0a38os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb250os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d44d8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb340os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3d81cf8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb430os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3d81d78os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb520os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3df1a98os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb610os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3d81df8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb700os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3d81e78os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb7f0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x2a5e1a8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb8e0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3df1b28os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3deb9d0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1b748os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3debac0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1b798os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3debbb0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1b838os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3debca0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1b9c8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3debd90os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1bb08os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3debe80os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1bbf8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3debf70os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e23ac8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec060os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1bc48os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec150os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1bc98os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec240os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1bd38os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec330os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1bec8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec420os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1bf68os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec510os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1bfb8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec6f0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1c0f8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec7e0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1c148os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec9c0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1c238os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3decab0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1c288os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3decba0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1c2d8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3decc90os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1c738os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec8d0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1c9b8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3dec600os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1cf08os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e52f40os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1c198os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53030os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1d1d8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53120os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1ce18os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53210os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1d2c8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53300os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e1d408os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e533f0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x1d40c8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e534e0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e63df8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e535d0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e50158os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e537b0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e64488os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53990os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e64118os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e536c0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3d825f8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e538a0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e641b8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53a80os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e64208os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53b70os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e7d458os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53c60os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e645c8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53d50os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e64a78os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53e40os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e64b18os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e53f30os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e64c58os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e54020os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e64ed8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e54200os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e64f28os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e542f0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e64fc8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e543e0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e650b8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e546b0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3ed9218os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x3e544d0os_pid = 0x830, process_name = c:\windows\explorer.exeTrue32
Bin
Fn
READ0x3e763f8os_pid = 0x830, process_name = c:\windows\explorer.exeTrue16
Bin
Fn
READ0x6eos_pid = 0x830, process_name = c:\windows\explorer.exeFalse16
Bin
Fn
READ0x77450000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue2
Bin
Fn
READ0x774d3380os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x77550000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue7
Bin
Fn
READ0x775efffcos_pid = 0x830, process_name = c:\windows\explorer.exeTrue5
Bin
Fn
READ0x0os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x10000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x20000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x22000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x30000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x34000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x40000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x42000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x50000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x51000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x60000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0xc7000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0xd0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0xd6000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0xe0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0xe1000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0xf0000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x15c000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x15e000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x170000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x171000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x180000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x18d000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x190000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x290000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x291000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x2d0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x2d1000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x2e0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x2e2000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x2f0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x2f1000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x300000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x302000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x310000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x311000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x320000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x322000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x330000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x332000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x340000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x341000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x350000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x360000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x386000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x460000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x463000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x5e0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x5e3000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x5e8000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x5f0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x771000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x780000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7a0000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1b80000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1b90000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1ba0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1bb0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1bb2000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1bc0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1c02000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1c10000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1c11000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1c20000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1c23000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1c30000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1c31000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1c40000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1c65000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1cc0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1d9f000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1da0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1dfc000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1e00000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1e2e000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1e30000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1e9a000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1e9c000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1eb0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1eb1000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1ec0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1ec9000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1ed0000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1f3f000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x1f42000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x1f50000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x221f000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x2220000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x2328000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x2330000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x238a000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x2390000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x23d2000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x23e0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x23e1000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x24e0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x24e8000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x24f0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x2517000os_pid = 0x830, process_name = c:\windows\explorer.exeFalse1
Bin
Fn
READ0x2520000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0xffa00000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue9
Bin
Fn
READ0xffa01000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue9
Bin
Fn
READ0x77670000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue4
Bin
Fn
READ0x77671000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue3
Bin
Fn
READ0x77551000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue2
Bin
Fn
READ0x7fefd540000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue2
Bin
Fn
READ0x7fefd541000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue2
Bin
Fn
READ0x7fefd870000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue2
Bin
Fn
READ0x7fefd871000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue2
Bin
Fn
READ0x7feff8c0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue2
Bin
Fn
READ0x7feff8c1000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue2
Bin
Fn
READ0x77776270os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe290000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe291000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7feff790000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7feff791000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefda70000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefda71000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x77451000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefdd90000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefdd91000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7feff6c0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7feff6c1000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe040000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe041000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe930000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe931000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe720000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe721000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe2b0000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
READ0x7fefe2b1000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
Operation Module Additional Information Success Amount Logfile
MAPoIE9wInos_pid = 0xb50, process_name = c:\users\user\desktop\089c5446291c9145ad8ac6c1cdfe4928.exe, desired_access = FILE_MAP_WRITE, address = 0xb60000, map_size = 0x61646True1
Bin
Fn
MAP-process_name = current_Process, protection = PAGE_READWRITE, address = 0x23f3ccTrue1
Bin
Fn
MAP5b914348-os_pid = 0xb50, process_name = c:\users\user\desktop\089c5446291c9145ad8ac6c1cdfe4928.exe, desired_access = FILE_MAP_ALL_ACCESS, address = 0x130000, map_size = 0x0True1
Bin
Fn
UNMAP0x130000os_pid = 0xb50, process_name = c:\users\user\desktop\089c5446291c9145ad8ac6c1cdfe4928.exeTrue1
Bin
Fn
UNMAP0x120000process_name = current_ProcessTrue1
Bin
Fn
UNMAP0xb60000os_pid = 0xb50, process_name = c:\users\user\desktop\089c5446291c9145ad8ac6c1cdfe4928.exeTrue1
Bin
Fn
Operation Class Name Additional Information Success Amount Logfile
CREATEDialog1-True1
Bin
Fn
FINDShell_TrayWnd-True1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
GET_RANDOM0x23f6c0result_out = 0x5593eTrue1
Bin
Fn
GET_RANDOM0x23f6c0result_out = 0x1361b816True1
Bin
Fn
GET_RANDOM0x23f6c0result_out = 0x67714df2True1
Bin
Fn
GET_RANDOM0x23f6c0result_out = 0x3d86591bTrue1
Bin
Fn
GET_RANDOM0x23f6c0result_out = 0x320a3b6True1
Bin
Fn
GET_RANDOM0x23f6c0result_out = 0x7ddb7988True1
Bin
Fn
GET_RANDOM0x23f6c0result_out = 0x798e5345True1
Bin
Fn
GET_TIMETicksresult_out = 0xf008True1
Bin
Fn
GET_TIMETicksresult_out = 0xf018True397
Bin
Fn
GET_TIMETicksresult_out = 0xf21bTrue1
Bin
Fn
Operation Name Additional Information Success Amount Logfile
OPENGlobal\5b914348-258a-4617-b462-d107efea3e7bgfdgfdgdfg830-False1
Bin
Fn
Operation Environment Variable Additional Information Success Amount Logfile
GETSystemDriveresult_out = C:True1
Bin
Fn
ID#2
OS PID0x830
OS Parent PID0xffffffffffffffff
Image Nameexplorer.exe
Page Root0x110ef000
Monitor Reasoninjection
Unmonitor Reasonself_terminated
CMD LineC:\Windows\Explorer.EXE
Current DirectoryC:\Windows\system32\
Host Behavior
Operation File Additional Information Success Amount Logfile
CREATEC:\Users\user\AppData\Local\Temp\2625.tmp-True1
Bin
Fn
DELETE--False1
Bin
Fn
DELETEC:\Users\user\Desktop\089c5446291c9145ad8ac6c1cdfe4928.exe-True1
Bin
Fn
DELETEC:\Users\user\AppData\Local\Temp\2625.tmp-True1
Bin
Fn
COPYC:\Users\user\AppData\Local\Temp\2625.tmpsource_file = C:\Windows\system32\unattend.dllTrue1
Bin
Fn
CREATE_MAPPINGSystem Paging Filemaximum_size = 0x8000, protection = PAGE_EXECUTE_READWRITE, SEC_COMMITTrue1
Bin
Fn
CREATE_MAPPINGC:\Users\user\AppData\Local\Temp\2625.tmpmaximum_size = 0x0, protection = PAGE_READWRITETrue1
Bin
Fn
CREATE_TMPFILEC:\Users\user\AppData\Local\Temp\2625.tmp-True1
Bin
Fn
GET_TMPDIRC:\Users\user\AppData\Local\Temp\-True1
Bin
Fn
OPEN_MAPPINGoIE9wIn-True1
Bin
Fn
Operation Key Additional Information Success Amount Logfile
OPEN_KEYHKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography-True1
Bin
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Cryptographyvalue_name = MachineGuid, data = 5b914348-258a-4617-b462-d107efea3e7bTrue1
Bin
Fn
Operation Process Additional Information Success Amount Logfile
CREATEC:\Windows\system32\sysprep\sysprep.exeos_pid = 0x7d4, show_window = SW_SHOWTrue1
Bin
Fn
Operation Module Additional Information Success Amount Logfile
MAPoIE9wInos_pid = 0x830, process_name = c:\windows\explorer.exe, desired_access = FILE_MAP_ALL_ACCESS, address = 0x5f10000, map_size = 0x61646True1
Bin
Fn
MAP5b914348-25os_pid = 0x830, process_name = c:\windows\explorer.exe, desired_access = FILE_MAP_ALL_ACCESS, address = 0x5d20000, map_size = 0x0True1
Bin
Fn
MAPSystem Paging Fileos_pid = 0x830, process_name = c:\windows\explorer.exe, desired_access = FILE_MAP_ALL_ACCESS, address = 0x5d20000, map_size = 0x0True1
Bin
Fn
UNMAP0x5d20000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue2
Bin
Fn
UNMAP0x5f10000os_pid = 0x830, process_name = c:\windows\explorer.exeTrue1
Bin
Fn
Operation User/Group/Server Additional Information Success Amount Logfile
LOOKUP_PRIVILEGElocalhostprivilege_name = SeShutdownPrivilegeTrue1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
GET_INFOSystem directoryresult_out = C:\Windows\system32True1
Bin
Fn
GET_RANDOM0x6c1fd88result_out = 0x130dd9abTrue1
Bin
Fn
GET_TIMETicksresult_out = 0x12625True1
Bin
Fn
GET_TIMETicksresult_out = 0x12e40True1
Bin
Fn
SLEEP0x3e8-True1
Bin
Fn
SLEEP0x12c-True1
Bin
Fn
SLEEP0x6544b-True1
Bin
Fn
POWERCTRLEWX_REBOOT, EWX_FORCE-True1
Bin
Fn
ID#4
OS PID0x7d4
OS Parent PID0x830
Image Namesysprep.exe
Page Root0x76c87000
Monitor Reasonchild_process
Unmonitor Reasonself_terminated
CMD Line"C:\Windows\system32\sysprep\sysprep.exe"
Current DirectoryC:\Windows\system32\
Host Behavior
Operation File Additional Information Success Amount Logfile
CREATE\\.\GLOBALROOT\ArcName\multi(0)disk(0)rdisk(0)partition(1)-True2
Bin
Fn
CREATE\\.\PhysicalDrive0-True6
Bin
Fn
WRITE\\.\PhysicalDrive0-True2
Bin
Fn
OPEN_MAPPINGoIE9wIn-True1
Bin
Fn
Operation Module Additional Information Success Amount Logfile
MAPoIE9wInos_pid = 0x7d4, process_name = c:\windows\system32\sysprep\sysprep.exe, desired_access = FILE_MAP_ALL_ACCESS, address = 0x1d0000, map_size = 0x61646True1
Bin
Fn
UNMAP0x1d0000os_pid = 0x7d4, process_name = c:\windows\system32\sysprep\sysprep.exeTrue1
Bin
Fn
Operation Driver Additional Information Success Amount Logfile
CONTROL\\.\GLOBALROOT\ArcName\multi(0)disk(0)rdisk(0)partition(1)control_code = 0x70048True2
Bin
Fn
CONTROL\\.\GLOBALROOT\ArcName\multi(0)disk(0)rdisk(0)partition(1)control_code = 0x2d1080True2
Bin
Fn
CONTROL\\.\PhysicalDrive0control_code = 0x70000True6
Bin
Fn
CONTROL\\.\PhysicalDrive0control_code = 0x700a0True4
Bin
Fn
ID#5
OS PID0x4
OS Parent PID0xffffffffffffffff
Image NameSYSTEM
Page Root0x00187000
Monitor Reasonkernel_analysis
Unmonitor Reason(still running)
CMD Line-
Current Directory-
Host Behavior
Operation File Additional Information Success Amount Logfile
CREATE\Device\HarddiskVolume1-True1
Bin
Fn
CREATE\Device\Harddisk0\DR0-True2
Bin
Fn
CREATE\Device\HarddiskVolume2-True1
Bin
Fn
CREATE\??\C:\System Volume Information\{0052009a-da41-5ffa-89bd-9f9f6b830ac5}-False1
Bin
Fn
CREATE\??\C:\System Volume Information\{0052009a-da41-5ffa-89bd-9f9f6b830ac5}-True2
Bin
Fn
WRITE\??\C:\System Volume Information\{0052009a-da41-5ffa-89bd-9f9f6b830ac5}-True1983
Bin
Fn
WRITE\??\C:\System Volume Information\{0052009a-da41-5ffa-89bd-9f9f6b830ac5}-False534
Bin
Fn
SET_INFO\??\C:\System Volume Information\{0052009a-da41-5ffa-89bd-9f9f6b830ac5}-True370
Bin
Fn
SET_INFO\??\C:\System Volume Information\{0052009a-da41-5ffa-89bd-9f9f6b830ac5}-False66
Bin
Fn
Operation Key Additional Information Success Amount Logfile
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion-False1
Bin
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion-True1
Bin
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CFCD29B3-A836-426F-8329-8362EC941293}-False2
Bin
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B22E8C55-CC74-4FBE-B907-F46D25953BEC}-False2
Bin
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5D403E7A-7554-4DD5-A8CF-7099B00A9E2D}-False2
Bin
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CACEFAA3-95D9-4B5B-B275-FF35DF23713E}-False2
Bin
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D720734D-0C14-4C25-829D-F6B4814978B3}-False2
Bin
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}-True2
Bin
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1C5BF427-3CBA-4599-A970-6F5C2EB7E2E2}-False2
Bin
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{37B932CB-736B-42BF-AABE-1D5EAE57F920}-False2
Bin
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{50CD5E3E-0F08-4519-A9EF-B9802ED12701}-False1
Bin
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersionvalue_name = SystemRootFalse1
Bin
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersionvalue_name = SystemRootTrue1
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = IPAddressFalse2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = DhcpIPAddressFalse2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = DhcpIPAddressTrue2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = DefaultGatewayFalse2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = DhcpDefaultGatewayFalse2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = DhcpDefaultGatewayTrue2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = SubnetMaskFalse2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = DhcpSubnetMaskFalse2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = DhcpSubnetMaskTrue2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = NameServerTrue2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = DhcpNameServerFalse2
Bin
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90CF4272-4C90-4C32-AB8B-72465DB1CA78}value_name = DhcpNameServerTrue2
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
GET_INFOSYSTEM_BASIC_INFORMATION-True1
Bin
Fn
ID#17
OS PID0x24c
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x1bfad000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\system32\svchost.exe -k DcomLaunch
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
ID#18
OS PID0x290
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x1bde4000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\system32\svchost.exe -k RPCSS
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
ID#19
OS PID0x2c0
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x1b5af000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
ID#21
OS PID0x344
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x19f79000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
ID#22
OS PID0x370
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x15742000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\system32\svchost.exe -k LocalService
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
ID#23
OS PID0x398
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x1570c000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\system32\svchost.exe -k netsvcs
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
ID#24
OS PID0x3e0
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x15054000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\system32\svchost.exe -k GPSvcGroup
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
ID#28
OS PID0x428
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x1613d000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\system32\svchost.exe -k NetworkService
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Key Additional Information Success Amount Logfile
OPEN_KEYHKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-True1
Bin
Fn
OPEN_KEYHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-True1
Bin
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogonvalue_name = Shell, data = 0x0False1
Bin
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogonvalue_name = Shell, data = explorer.exeTrue1
Bin
Fn
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True6
Bin
Fn
TERMINATE--False6
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
Network Behavior
Remote Address Remote Port Username Password Success Amount
157.56.96.5680--True1
Method URL Success Amount
GEThttp://157.56.96.56/True1
Operation Host Additional Information Success Amount Logfile
RESOLVE_NAMEwww.update.microsoft.comhost = 157.56.96.56, 191.232.80.55True1
Bin
Fn
RESOLVE_NAMEtime.windows.comhost = 137.170.185.211True1
Bin
Fn
Remote Address Remote Port L7Protocol Success Amount
157.56.96.5680-True1
Remote Address Remote Port Packet Size Amount
137.170.185.211123481
ID#31
OS PID0x4c4
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x15e73000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
ID#32
OS PID0x570
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x148f0000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn
ID#34
OS PID0x73c
OS Parent PID0x1c0
Image Namesvchost.exe
Page Root0x0f58c000
Monitor Reasonchild_process
Unmonitor Reason(still running)
CMD LineC:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
Current DirectoryC:\Windows\system32\
Host Behavior
Operation Thread ID Additional Information Success Amount Logfile
CREATE--True1
Bin
Fn
TERMINATE--False1
Bin
Fn
Operation Info Additional Information Success Amount Logfile
GET_INFOOSoperating_system = Windows 7 / Windows Server 2008 R2, os_build = 0x1db1, platform_id = VER_PLATFORM_WIN32_NTTrue1
Bin
Fn