Source: 250427-q9exta1yb1.bin.exe, 00000000.00000000.1140117456.0000000000401000.00000008.00000001.01000000.00000003.sdmp | Binary or memory string: :\AUTORUN.INF |
Source: 250427-q9exta1yb1.bin.exe, 00000000.00000002.2386122907.00000000001F0000.00000004.00000020.00040000.00000000.sdmp | Binary or memory string: AUTORUN.INFC:\W |
Source: 250427-q9exta1yb1.bin.exe, 00000000.00000003.1191397007.0000000004930000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: [autorun] |
Source: 250427-q9exta1yb1.bin.exe, 00000000.00000002.2387073222.00000000022B0000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INF |
Source: 250427-q9exta1yb1.bin.exe, 00000000.00000002.2387073222.00000000022B0000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INFN |
Source: 250427-q9exta1yb1.bin.exe, 00000000.00000003.1191450520.0000000004930000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: [autorun] |
Source: 250427-q9exta1yb1.bin.exe, 00000000.00000003.1191476802.0000000004930000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: [autorun] |
Source: 250427-q9exta1yb1.bin.exe, 00000000.00000003.1191422995.0000000004930000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: [autorun] |
Source: HelpMe.exe, 00000001.00000002.2387348712.00000000021D0000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INF |
Source: HelpMe.exe, 00000009.00000002.2386387554.000000000064B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INF |
Source: HelpMe.exe, 00000009.00000002.2386955865.00000000020D0000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INF |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: :\AUTORUN.INF |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: [autorun] |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: AUTORUN.INF |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: AUTORUN.INF(t |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: AUTORUN.INFx |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: A@p[autorun] |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: 250427-q9exta1yb1.bin.exe | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: desktop.ini.exe1.0.dr | Binary or memory string: [autorun] |
Source: desktop.ini.exe1.0.dr | Binary or memory string: AUTORUN.INF |
Source: desktop.ini.exe1.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: desktop.ini.exe1.0.dr | Binary or memory string: AUTORUN.INFx |
Source: desktop.ini.exe1.0.dr | Binary or memory string: A@p[autorun] |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: [autorun] |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: @@[autorun] |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: 3'AUTORUN.INFD |
Source: .curlrc.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: .curlrc.exe.0.dr | Binary or memory string: [autorun] |
Source: .curlrc.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: .curlrc.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: .curlrc.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: .curlrc.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.0.dr | Binary or memory string: [autorun] |
Source: desktop.ini.exe0.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: desktop.ini.exe0.0.dr | Binary or memory string: [autorun] |
Source: desktop.ini.exe0.0.dr | Binary or memory string: AUTORUN.INF |
Source: desktop.ini.exe0.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: desktop.ini.exe0.0.dr | Binary or memory string: AUTORUN.INFx |
Source: desktop.ini.exe0.0.dr | Binary or memory string: A@p[autorun] |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: desktop.ini.exe.0.dr | Binary or memory string: [autorun] |
Source: desktop.ini.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: desktop.ini.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: desktop.ini.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: desktop.ini.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: AutoRun.exe.0.dr | Binary or memory string: [autorun] |
Source: AutoRun.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: AutoRun.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: AutoRun.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: AutoRun.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: HelpMe.exe.0.dr | Binary or memory string: [autorun] |
Source: HelpMe.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: HelpMe.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: HelpMe.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: HelpMe.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |