Technical Information
- <SYSTEM32>\tasks\windows update
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- Windows Defender
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoControlPanel' = '00000001'
- [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'DisallowRun' = '00000001'
- %HOMEPATH%\desktop\adadsi.html
- %HOMEPATH%\desktop\alert.html
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\cveuropeo.doc
- %HOMEPATH%\desktop\browse.html
- %HOMEPATH%\desktop\delete.avi
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %HOMEPATH%\desktop\trivial-merge.html
- %TEMP%\tmp36df.tmp
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\kfmscanexclusiontoast.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\loadingpage.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.contrast-black_scale-140.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.scale-100.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.scale-80.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.scale-125.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.contrast-black_scale-180.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.contrast-black_scale-100.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.scale-100.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.scale-150.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.contrast-black_scale-80.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.contrast-black_scale-140.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.scale-125.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.contrast-white_scale-100.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.scale-200.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.contrast-black_scale-180.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.scale-400.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.contrast-white_scale-140.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-white_scale-400.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.scale-150.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.contrast-white_scale-140.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-white_scale-125.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\elevatedappwhite.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.contrast-white_scale-140.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.contrast-black_scale-100.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\error.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-white_scale-100.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.contrast-black_scale-140.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.contrast-white_scale-180.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\errorpage.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.contrast-white_scale-80.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.contrast-white_scale-100.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.contrast-black_scale-180.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\kfmherotoast.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.scale-100.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-white_scale-150.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.contrast-black_scale-80.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.scale-140.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\kfmlockedfiletoast.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-white_scale-200.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.scale-180.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.contrast-white_scale-140.sos
- %APPDATA%\opera software\opera stable\dictionaries\dictionaries.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.scale-200.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.contrast-white_scale-125.sos
- %APPDATA%\microsoft\internet explorer\quick launch\google chrome.sos
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\sitesecurityservicestate.sos
- %APPDATA%\microsoft\internet explorer\quick launch\shows desktop.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.scale-140.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\winprojlogo.contrast-black_scale-100.sos
- %LOCALAPPDATA%\google\chrome\application\47.0.2526.106\secondarytile.sos
- %APPDATA%\microsoft\internet explorer\quick launch\window switcher.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\winprojlogo.contrast-black_scale-140.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.contrast-black_scale-80.sos
- %APPDATA%\microsoft\windows\sendto\fax recipient.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.contrast-white_scale-150.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\logoimages\onedrivesmalltile.contrast-white_scale-100.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\winprojlogo.contrast-black_scale-180.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.scale-80.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\winprojlogo.contrast-black_scale-80.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.contrast-white_scale-200.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\logoimages\onedrivesmalltile.contrast-white_scale-125.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.scale-100.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-black_scale-400.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.scale-80.sos
- %LOCALAPPDATA%\packages\microsoft.skypeapp_kzf8qxf38zg5c\localstate\rtcpal_registry.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.contrast-white_scale-180.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.scale-400.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.contrast-black_scale-125.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.contrast-white_scale-80.sos
- %LOCALAPPDATA%\microsoft\windows\shell\defaultlayouts.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.contrast-white_scale-100.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.scale-100.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.contrast-black_scale-150.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.contrast-black_scale-100.sos
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\securitypreloadstate.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.scale-140.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.contrast-black_scale-200.sos
- %APPDATA%\thunderbird\profiles\yrg4bo2l.default-release\prefs.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologosmall.scale-180.sos
- %LOCALAPPDATA%\packages\microsoft.skypeapp_kzf8qxf38zg5c\localstate\shared.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.contrast-white_scale-180.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.contrast-black_scale-400.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.contrast-white_scale-80.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivesmalltile.contrast-white_scale-100.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\visiologo.scale-180.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.contrast-white_scale-100.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.contrast-black_scale-100.sos
- %TEMP%\dd_vcredistmsi6d07.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.contrast-white_scale-180.sos
- %TEMP%\microsoft visual c++ 2010 x86 redistributable setup_20220928_192036284-msi_vc_red.msi.sos
- %TEMP%\dd_vcredistui6d07.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.contrast-white_scale-80.sos
- %TEMP%\microsoft visual c++ 2010 x86 redistributable setup_20220928_192036284.sos
- %TEMP%\jawshtml.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.scale-100.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.scale-140.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.contrast-black_scale-100.sos
- %TEMP%\wallpaper.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.scale-180.sos
- %LOCALAPPDATA%\microsoft\internet explorer\brndlog.sos
- %TEMP%\microsoft visual c++ 2010 x64 redistributable setup_20220928_191926081-msi_vc_red.msi.sos
- %LOCALAPPDATA%\microsoft\onedrive\onedrive.visualelementsmanifest.sos
- %TEMP%\microsoft visual c++ 2010 x64 redistributable setup_20220928_191926081.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.scale-80.sos
- %LOCALAPPDATA%\google\chrome\application\chrome.visualelementsmanifest.sos
- %HOMEPATH%\desktop\trivial-merge.sos
- %TEMP%\microsoft .net framework 4.6.2 setup_20220928_193050208.sos
- %TEMP%\dd_ndp462-kb3151800-x86-x64-allos-enu_decompression_log.sos
- %HOMEPATH%\desktop\browse.sos
- %WINDIR%\syswow64\<File name>.exe
- %HOMEPATH%\desktop\adadsi.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\onenotelogosmall.scale-80.sos
- %HOMEPATH%\desktop\alert.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.contrast-black_scale-100.sos
- %HOMEPATH%\desktop\archer.sos
- %HOMEPATH%\desktop\cveuropeo.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.contrast-black_scale-140.sos
- %HOMEPATH%\desktop\delete.sos
- %HOMEPATH%\links\downloads.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.contrast-black_scale-180.sos
- %HOMEPATH%\desktop\google chrome.sos
- %HOMEPATH%\desktop\weeklysheet1215.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.contrast-black_scale-80.sos
- %HOMEPATH%\desktop\microsoft edge.sos
- %HOMEPATH%\links\desktop.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.contrast-white_scale-100.sos
- %HOMEPATH%\desktop\telegram.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogo.contrast-white_scale-140.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.contrast-white_scale-140.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.scale-80.sos
- %LOCALAPPDATA%\microsoft\internet explorer\iecompatdata\iecompatdata.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\testsharepage.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\appwhite.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.scale-180.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.scale-80.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.scale-140.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\thirdpartynotices.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\warning.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\autoplayoptin.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-black_scale-100.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.contrast-black_scale-140.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\collectsynclogs.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.contrast-black_scale-140.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.scale-180.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-black_scale-125.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.contrast-black_scale-180.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-black_scale-150.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogosmall.contrast-black_scale-80.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\elevatedappblue.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.scale-100.sos
- %LOCALAPPDATA%\microsoft\onedrive\logoimages\onedrivemedtile.contrast-black_scale-200.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.scale-140.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.contrast-white_scale-180.sos
- %TEMP%\microsoft visual c++ 2010 x64 redistributable setup_20220928_192019924.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.contrast-black_scale-180.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\alerticon.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\quotanearing.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.contrast-black_scale-80.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\onedrivelogo.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\alerticon.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.contrast-white_scale-100.sos
- %TEMP%\microsoft visual c++ 2010 x64 redistributable setup_20220928_192019924-msi_vc_red.msi.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.contrast-white_scale-80.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\quotacritical.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\appblue.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.contrast-white_scale-80.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\apperrorblue.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\outlooklogosmall.contrast-white_scale-180.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\quotaerror.sos
- %ProgramFiles(x86)%\microsoft office\office16\logoimages\powerpntlogo.scale-100.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\quotanearing.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005_1\apperrorwhite.sos
- %LOCALAPPDATA%\microsoft\onedrive\19.002.0107.0005\logoimages\onedrivesmalltile.contrast-white_scale-150.sos
- %APPDATA%\microsoft\windows\themes\transcodedwallpaper
- %APPDATA%\microsoft\windows\themes\cachedfiles\cachedimage_1152_864_pos2.jpg
- %LOCALAPPDATA%\microsoft\windows\explorer\thumbcache_idx.db
- 'ra#.####ubusercontent.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Get-MpPreference -verbose
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "Windows Update" /tr "%WINDIR%\SysWOW64\Eleven.exe" /sc MINUTE /mo 1 /ru SYSTEM /f /rl HIGHEST
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "Windows Update" /tr "%WINDIR%\SysWOW64\Eleven.exe" /sc MINUTE /mo 1 /ru SYSTEM /f /rl HIGHEST' (with hidden window)