Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =93c98cfc407afe3c3b3cd557643a160e

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    93c98cfc407afe3c3b3cd557643a160efbca31e452e693c1ac01b04105a184e5755fd0ec5a06d7ca8e39b39291e9eb2203283080dbe8d5a6eb1956288e6a2963e19a24c51536:PmkgRjKOPM82q2qstg4QeV/EVWUXLNjUYphlp:PmV3Pz2fgneV8tXp9jD80596

    File Results

    File Name
    www.hhezahh.co.cc.exe
    thootham.exe
    statsbeck.com.exe
    statistics.php.exe
    shufaica.exe
    scan.exe
    saejuogi.exe
    oomiephe.exe
    load.php%3Fspl%3Djava%5Fgsb%26h%3B%3D.exe
    laangiet.exe
    l.php.exe
    installer.0042.exe
    index.php.exe
    exe.exe
    bot.exe
    baiquaad.exe
    %3Espl%3DMDAC%26exe%5Facces%3Don.exe

    SNORT Results

    Snort ClassSnort AlertCount
    Misc AttackET RBN Known Russian Business Network IP TCP (284)1

    AV Results

    AV AlertAV Vendor

    Folders (Added) - ICC Results

    PathFolder Name
    c:/Documents and Settings/dmc73144/Local Settings/Tempd5cc4b46-34b2-412f-b87b-aabed2287952
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Temp715393df-506a-4832-86cd-900138ca1b89
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Temp4e571963-08d3-4f93-8c2d-2fd9538527df
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Temp9f400591-57db-473c-a155-b39f3cbc63e0
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Tempc7ea2850-ca0c-4821-a711-babad3ca589a
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Temp38340485-bed7-4681-a270-d326e6cd1d37
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Tempdacc35b4-73e4-4c0d-b819-d67fb7297581
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Tempae7c964e-3e4b-4d61-b40e-527828533e05
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Tempf0edcf17-7b3e-4eed-98f8-0428940ac24b
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Temp66260f35-cc1f-44f5-ba98-b0d442e123e2
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Tempd3240025-0d8f-4942-be4c-9f77407798df
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C

    Files (Added) - ICC Results

    PathFile Name
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/d5cc4b46-34b2-412f-b87b-aabed2287952wrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/d5cc4b46-34b2-412f-b87b-aabed2287952wrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/d5cc4b46-34b2-412f-b87b-aabed2287952wrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/PrefetchRUNDLL32.EXE-2512DEBF.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-306B40A1.pf
    c:netstat_post.txt
    c:taskv_post.txt
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/715393df-506a-4832-86cd-900138ca1b89wrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/715393df-506a-4832-86cd-900138ca1b89wrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/715393df-506a-4832-86cd-900138ca1b89wrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-13722C3F.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-1AB3B55B.pf
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/4e571963-08d3-4f93-8c2d-2fd9538527dfwrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/4e571963-08d3-4f93-8c2d-2fd9538527dfwrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/4e571963-08d3-4f93-8c2d-2fd9538527dfwrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchCYGRUNSRV.EXE-01BF82AE.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-1CE2C65D.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-218ACEC9.pf
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/9f400591-57db-473c-a155-b39f3cbc63e0wrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/9f400591-57db-473c-a155-b39f3cbc63e0wrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/9f400591-57db-473c-a155-b39f3cbc63e0wrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/c7ea2850-ca0c-4821-a711-babad3ca589awrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/c7ea2850-ca0c-4821-a711-babad3ca589awrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/c7ea2850-ca0c-4821-a711-babad3ca589awrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/38340485-bed7-4681-a270-d326e6cd1d37wrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/38340485-bed7-4681-a270-d326e6cd1d37wrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/38340485-bed7-4681-a270-d326e6cd1d37wrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-25DE1D47.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-482AC6D9.pf
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/dacc35b4-73e4-4c0d-b819-d67fb7297581wrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/dacc35b4-73e4-4c0d-b819-d67fb7297581wrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/dacc35b4-73e4-4c0d-b819-d67fb7297581wrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-27C30B35.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-35836DA9.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/ae7c964e-3e4b-4d61-b40e-527828533e05wrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/ae7c964e-3e4b-4d61-b40e-527828533e05wrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/ae7c964e-3e4b-4d61-b40e-527828533e05wrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchCYGRUNSRV.EXE-01BF82AE.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/f0edcf17-7b3e-4eed-98f8-0428940ac24bwrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/f0edcf17-7b3e-4eed-98f8-0428940ac24bwrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/f0edcf17-7b3e-4eed-98f8-0428940ac24bwrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/66260f35-cc1f-44f5-ba98-b0d442e123e2wrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/66260f35-cc1f-44f5-ba98-b0d442e123e2wrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/66260f35-cc1f-44f5-ba98-b0d442e123e2wrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/PrefetchRUNDLL32.EXE-19E0DDC4.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-32993667.pf
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt
    c:/Documents and Settings/dmc73144/Application Data8fbc0ebc-15d7-4dae-818a-50f3473ae912_47.avi
    c:/Documents and Settings/dmc73144/Local Settings/Temp/d3240025-0d8f-4942-be4c-9f77407798dfwrk1.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temp/d3240025-0d8f-4942-be4c-9f77407798dfwrk2.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/d3240025-0d8f-4942-be4c-9f77407798dfwrk2.tmp_47
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt
    c:/WINDOWS/PrefetchRUNDLL32.EXE-1EAC97FA.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-4AE4645F.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/Program Files/OpenSSH/var/runsshd.pid
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING1.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING1.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/Program Files/OpenSSH/var/runsshd.pid
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed3C CD 90 34 AF 12 4E 04 C9 D8 78 DF 34 A1 F2 41 0F CF C2 DD 9A 06 B7 61 84 81 D9 DC FF 71 F3 0E 60 68 19 A4 37 E4 B2 91 9F 31 B1 DD B9 3E 98 2D AA D7 51 8D E0 E
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed7D F3 5A DF 45 69 2D 90 41 FC 31 EF 2A AD 45 11 4A 18 CA 3C 04 72 2C 13 15 45 84 98 3A C4 20 78 6A 6E CD 56 3C 5B BB 2E 0A DA F6 03 83 AF 38 05 93 AE 75 29 78 C
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedFC D8 B0 06 28 3A 60 7C FB 36 CA AD 44 8D F4 62 1D B9 D6 DA 0F 8D E9 2B F9 8B C7 1E 62 07 FB 95 0B 2E 5E C1 47 77 58 AF FF CD 50 C4 28 FA AE B4 0C 66 D3 9C 00 C
    modifiedHKLM/SYSTEM/ControlSet001/Control/ServiceCurrent0x00000009 0x0000000A
    modifiedHKLM/SYSTEM/CurrentControlSet/Control/ServiceCurrent0x00000009 0x0000000A
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedBF D8 DF BD 31 24 8D 3A 18 14 6A 0F 2E 73 16 9C 0A D9 48 99 43 F6 B5 8F B1 6E A5 8A 20 94 23 13 AA B5 66 FE A5 B9 28 E6 8C 87 BD 0D AB BF C0 52 CD 98 AD A1 9E A
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed7E 4A 7B 4F BE 70 EA 6F 12 98 3F E1 6A B8 38 F1 AC 6A 5D D4 7B 6B 2A 20 DF 92 07 94 FF ED 6A E7 EB BA AC 2D C6 BE D7 F0 66 AF 9B 4C 14 81 2C 6D D4 59 8B E3 A4 5
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed5D 4D 7A 66 2F 05 F5 B4 4D 5E 29 B1 AD 62 1D CE 79 78 D3 D1 D2 24 47 5B AD 4C 6C A8 D2 33 7D 80 B7 30 5B A0 6B 57 7A 2A EA 67 15 7E 8D C9 63 CC 6F C8 D7 88 5E 7
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedC7 11 9D D8 21 7E 33 56 AE F4 5D 61 FB F7 D3 77 5A EE B5 FC FC 04 AF B9 65 05 38 AE 29 F4 D0 6A D9 D0 7B 63 01 30 31 A6 CD 3F 76 DF AD 5D A8 C3 13 E4 25 F5 A5 3
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedC2 3C A8 CB 9F 70 88 6B 9D 31 CF 9B 4D 8E 3C 2C B0 41 19 89 40 91 4B 29 49 A1 CF 32 25 47 B9 90 56 AD 5D 94 64 AF CE E2 B0 E3 DE 90 13 48 64 CA 74 D0 D8 14 B1 1
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedA5 9B 26 48 4A 0E AA 6E 9D 86 56 28 24 62 0F CF F2 01 F6 C8 1A AC 3F BE C3 31 EB 27 EA BE 67 59 C0 3B 7B DB F2 8D 82 80 02 AB 46 3F B2 E7 59 C2 26 48 F8 09 45 E
    modifiedHKLM/SYSTEM/CurrentControlSet/Control/ServiceCurrent0x00000009 0x0000000A
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedB0 41 82 82 5D A6 91 3D E3 4C 33 32 80 5B E2 E6 A7 FD F4 B9 41 94 45 75 24 CD 2F AF 79 42 E5 9F F0 DC 04 28 6D B6 09 96 6E AC A0 C8 75 7E 33 7D AB C6 E0 72 E2 7
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed55 FF B9 4C EF 7D 03 F0 7C CE B1 C7 1B 66 58 62 93 1D 17 EE FE 2D BC 76 A1 44 94 69 CF 69 17 A2 4B 0A B9 4A 26 B9 5E BD 1D CA 1C 02 96 22 8E A1 65 56 96 1C 03 8
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed19 A0 15 C1 E6 C7 2A D9 DE 4D 21 02 50 41 9E 3F F3 13 98 F8 33 39 D7 9C A1 F1 18 42 63 A3 F1 F2 3C C0 FD E4 18 E8 D7 B1 1E 50 61 25 A5 BC 52 18 08 19 48 9E EB 1
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed89 9C 6F 08 CA CF C8 04 08 1E 46 EC F8 C6 AF 5A 7B 14 27 E6 05 0F EB 9B 76 C0 B3 8F FB 3B E8 92 22 13 27 7C D6 A2 26 72 98 61 ED D7 7B 69 28 71 FA B2 9B 45 F5 7
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001

    DNS Results

    DNSDNS Response
    windowsupdate.microsoft.comStandard query response CNAME windowsupdate.microsoft.nsatc.net A 65.54.221.118
    windowsupdate.microsoft.comStandard query response CNAME windowsupdate.microsoft.nsatc.net A 207.46.18.94

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    65.54.221.118windowsupdate.microsoft.com/0x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=d5cc4b46-34b2-412f-b87b-aabed2287952&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=d5cc4b46-34b2-412f-b87b-aabed2287952&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=d5cc4b46-34b2-412f-b87b-aabed2287952&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=d5cc4b46-34b2-412f-b87b-aabed2287952&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=d5cc4b46-34b2-412f-b87b-aabed2287952&l=2400x06
    207.46.18.94windowsupdate.microsoft.com/0x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=715393df-506a-4832-86cd-900138ca1b89&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=715393df-506a-4832-86cd-900138ca1b89&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=715393df-506a-4832-86cd-900138ca1b89&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=715393df-506a-4832-86cd-900138ca1b89&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=715393df-506a-4832-86cd-900138ca1b89&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=4e571963-08d3-4f93-8c2d-2fd9538527df&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=4e571963-08d3-4f93-8c2d-2fd9538527df&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=4e571963-08d3-4f93-8c2d-2fd9538527df&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=4e571963-08d3-4f93-8c2d-2fd9538527df&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=4e571963-08d3-4f93-8c2d-2fd9538527df&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=9f400591-57db-473c-a155-b39f3cbc63e0&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=9f400591-57db-473c-a155-b39f3cbc63e0&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=9f400591-57db-473c-a155-b39f3cbc63e0&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=9f400591-57db-473c-a155-b39f3cbc63e0&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=9f400591-57db-473c-a155-b39f3cbc63e0&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=c7ea2850-ca0c-4821-a711-babad3ca589a&t=20x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=c7ea2850-ca0c-4821-a711-babad3ca589a&l=4160x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=c7ea2850-ca0c-4821-a711-babad3ca589a&t=50x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=c7ea2850-ca0c-4821-a711-babad3ca589a&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=c7ea2850-ca0c-4821-a711-babad3ca589a&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=38340485-bed7-4681-a270-d326e6cd1d37&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=38340485-bed7-4681-a270-d326e6cd1d37&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=38340485-bed7-4681-a270-d326e6cd1d37&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=38340485-bed7-4681-a270-d326e6cd1d37&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=38340485-bed7-4681-a270-d326e6cd1d37&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=dacc35b4-73e4-4c0d-b819-d67fb7297581&t=50x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=dacc35b4-73e4-4c0d-b819-d67fb7297581&t=20x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=dacc35b4-73e4-4c0d-b819-d67fb7297581&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=dacc35b4-73e4-4c0d-b819-d67fb7297581&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=dacc35b4-73e4-4c0d-b819-d67fb7297581&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=7f0b41ab-f426-4ffb-a025-01e4fa8cd435&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=7f0b41ab-f426-4ffb-a025-01e4fa8cd435&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=7f0b41ab-f426-4ffb-a025-01e4fa8cd435&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=7f0b41ab-f426-4ffb-a025-01e4fa8cd435&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=7f0b41ab-f426-4ffb-a025-01e4fa8cd435&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=ae7c964e-3e4b-4d61-b40e-527828533e05&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=ae7c964e-3e4b-4d61-b40e-527828533e05&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=ae7c964e-3e4b-4d61-b40e-527828533e05&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=ae7c964e-3e4b-4d61-b40e-527828533e05&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=ae7c964e-3e4b-4d61-b40e-527828533e05&l=2400x06
    239.255.255.250239.255.255.250:1900*--blank--0x11
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=f0edcf17-7b3e-4eed-98f8-0428940ac24b&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=f0edcf17-7b3e-4eed-98f8-0428940ac24b&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=f0edcf17-7b3e-4eed-98f8-0428940ac24b&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=f0edcf17-7b3e-4eed-98f8-0428940ac24b&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=f0edcf17-7b3e-4eed-98f8-0428940ac24b&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=66260f35-cc1f-44f5-ba98-b0d442e123e2&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=66260f35-cc1f-44f5-ba98-b0d442e123e2&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=66260f35-cc1f-44f5-ba98-b0d442e123e2&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=66260f35-cc1f-44f5-ba98-b0d442e123e2&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=66260f35-cc1f-44f5-ba98-b0d442e123e2&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=d3240025-0d8f-4942-be4c-9f77407798df&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=d3240025-0d8f-4942-be4c-9f77407798df&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=d3240025-0d8f-4942-be4c-9f77407798df&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=d3240025-0d8f-4942-be4c-9f77407798df&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=d3240025-0d8f-4942-be4c-9f77407798df&l=2400x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=3c04db17-9708-43ad-84ac-fab51f3e062a&t=20x06
    91.188.60.591.188.60.5/hit.php?v=47&app_type_id=1&wm_id=acc0042&u=3c04db17-9708-43ad-84ac-fab51f3e062a&t=50x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=3c04db17-9708-43ad-84ac-fab51f3e062a&l=4160x06
    91.188.60.591.188.60.5/t.php?app_type_id=1&wm_id=acc0042&u=3c04db17-9708-43ad-84ac-fab51f3e062a&v=470x06
    91.188.60.591.188.60.5/ll.php?v=47&app_type_id=1&wm_id=acc0042&u=3c04db17-9708-43ad-84ac-fab51f3e062a&l=2400x06

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    6362838173605
    17203500

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    806362838173605
    190017203500

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    04:07:242010-08-23610.10.10.765.54.221.118-> e 42809889
    04:07:252010-08-23610.10.10.765.54.221.118-> e 412809889
    04:07:262010-08-23610.10.10.791.188.60.5-> e 56809956
    04:07:262010-08-23610.10.10.791.188.60.5-> e 4480101509
    04:07:272010-08-23610.10.10.791.188.60.5-> e 20809950
    04:07:292010-08-23610.10.10.791.188.60.5-> e 1088091273
    04:12:422010-08-231710.10.10.7239.255.255.250-> e 819002350
    14:10:332010-08-23610.10.10.7207.46.18.94-> e 159809889
    14:10:342010-08-23610.10.10.7207.46.18.94-> e 451809889
    14:10:352010-08-23610.10.10.791.188.60.5-> e 42809956
    14:10:372010-08-23610.10.10.791.188.60.5-> e 56809950
    14:10:382010-08-23610.10.10.791.188.60.5-> e 448091273
    14:15:522010-08-231710.10.10.7239.255.255.250-> e 819001175
    08:34:392010-08-27610.10.10.765.54.221.118-> e 169809889
    08:34:402010-08-27610.10.10.765.54.221.118-> e 122809889
    08:34:412010-08-27610.10.10.791.188.60.5-> e 30809956
    08:34:422010-08-27610.10.10.791.188.60.5-> e 3180101509
    08:34:432010-08-27610.10.10.791.188.60.5-> e 32809950
    08:34:442010-08-27610.10.10.791.188.60.5-> e 628091273
    08:40:452010-08-271710.10.10.7239.255.255.250-> e 819002350
    06:19:462010-08-28610.10.10.765.54.221.118-> e 42809889
    06:19:472010-08-28610.10.10.765.54.221.118-> e 412809889
    06:19:482010-08-28610.10.10.791.188.60.5-> e 56809956
    06:19:492010-08-28610.10.10.791.188.60.5-> e 20809950
    06:19:502010-08-28610.10.10.791.188.60.5-> e 1088091273
    06:25:262010-08-281710.10.10.7239.255.255.250-> e 819002350
    00:40:042010-09-03610.10.10.765.54.221.118-> e 31809889
    00:40:052010-09-03610.10.10.791.188.60.5-> e 32809956
    00:40:072010-09-03610.10.10.791.188.60.5-> e 64809956
    00:40:072010-09-03610.10.10.791.188.60.5-> e 6380101509
    00:40:082010-09-03610.10.10.791.188.60.5-> e 65809950
    00:40:092010-09-03610.10.10.791.188.60.5-> e 668091273
    00:48:042010-09-031710.10.10.7239.255.255.250-> e 819002350
    00:48:102010-09-031710.10.10.7239.255.255.250-> e 819001175
    06:48:562010-09-06610.10.10.765.54.221.118-> e 43809889
    06:48:572010-09-06610.10.10.765.54.221.118-> e 56809889
    06:48:582010-09-06610.10.10.791.188.60.5-> e 20809956
    06:48:592010-09-06610.10.10.791.188.60.5-> e 316809950
    06:49:002010-09-06610.10.10.791.188.60.5-> e 3118091273
    06:54:402010-09-061710.10.10.7239.255.255.250-> e 819002350
    19:43:542010-09-06610.10.10.765.54.221.118-> e 41809889
    19:43:552010-09-06610.10.10.791.188.60.5-> e 499809956
    19:43:562010-09-06610.10.10.791.188.60.5-> e 20809950
    19:43:582010-09-06610.10.10.791.188.60.5-> e 3118091273
    19:50:032010-09-061710.10.10.7239.255.255.250-> e 819002350
    12:37:222010-09-07610.10.10.7207.46.18.94-> e 43809889
    12:37:242010-09-07610.10.10.791.188.60.5-> e 56809956
    12:37:252010-09-07610.10.10.791.188.60.5-> e 20809956
    12:37:262010-09-07610.10.10.791.188.60.5-> e 316809950
    12:37:272010-09-07610.10.10.791.188.60.5-> e 3118091273
    23:49:092010-09-07610.10.10.7207.46.18.94-> e 495809889
    23:49:102010-09-07610.10.10.7207.46.18.94-> e 449809889
    23:49:112010-09-07610.10.10.791.188.60.5-> e 245809956
    23:49:132010-09-07610.10.10.791.188.60.5-> e 496809950
    23:49:142010-09-07610.10.10.791.188.60.5-> e 4978091273
    12:43:062010-09-071710.10.10.7239.255.255.250-> e 819001175
    23:55:182010-09-071710.10.10.7239.255.255.250-> e 819002350
    22:16:552010-09-08610.10.10.7207.46.18.94-> e 159809889
    22:16:562010-09-08610.10.10.7207.46.18.94-> e 451809889
    22:16:572010-09-08610.10.10.791.188.60.5-> e 412809956
    22:16:582010-09-08610.10.10.791.188.60.5-> e 56809950
    22:16:592010-09-08610.10.10.791.188.60.5-> e 448091273
    22:24:572010-09-081710.10.10.7239.255.255.250-> e 819002350
    22:25:032010-09-081710.10.10.7239.255.255.250-> e 819001175
    11:50:172010-09-09610.10.10.7207.46.18.94-> e 316809889
    11:50:182010-09-09610.10.10.791.188.60.5-> e 311809956
    11:50:192010-09-09610.10.10.791.188.60.5-> e 6809956
    11:50:202010-09-09610.10.10.791.188.60.5-> e 90809950
    11:50:212010-09-09610.10.10.791.188.60.5-> e 918091273
    11:56:052010-09-091710.10.10.7239.255.255.250-> e 819002350
    05:19:322010-09-10610.10.10.765.54.221.118-> e 159809889
    05:19:332010-09-10610.10.10.791.188.60.5-> e 451809956
    05:19:342010-09-10610.10.10.791.188.60.5-> e 412809956
    05:19:342010-09-10610.10.10.791.188.60.5-> e 4380101509
    05:19:362010-09-10610.10.10.791.188.60.5-> e 56809950
    05:19:372010-09-10610.10.10.791.188.60.5-> e 448091273
    05:25:172010-09-101710.10.10.7239.255.255.250-> e 819002350
    03:54:182010-09-11610.10.10.7207.46.18.94-> e 282809889
    03:54:192010-09-11610.10.10.791.188.60.5-> e 283809956
    03:54:212010-09-11610.10.10.791.188.60.5-> e 223809956
    03:54:212010-09-11610.10.10.791.188.60.5-> e 22480101509
    03:54:222010-09-11610.10.10.791.188.60.5-> e 284809950
    03:54:232010-09-11610.10.10.791.188.60.5-> e 2258091273
    04:00:242010-09-111710.10.10.7239.255.255.250-> e 819002350

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location