Source: 250427-sppmmasyfv.bin.exe, 00000000.00000003.1191420772.00000000028A0000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: [autorun] |
Source: 250427-sppmmasyfv.bin.exe, 00000000.00000002.2397231730.0000000000480000.00000004.00000020.00040000.00000000.sdmp | Binary or memory string: AUTORUN.INFC:\W |
Source: 250427-sppmmasyfv.bin.exe, 00000000.00000002.2398425183.0000000002220000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INF |
Source: 250427-sppmmasyfv.bin.exe, 00000000.00000002.2398425183.0000000002220000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INFN |
Source: 250427-sppmmasyfv.bin.exe, 00000000.00000000.1139948507.0000000000401000.00000008.00000001.01000000.00000003.sdmp | Binary or memory string: :\AUTORUN.INF |
Source: 250427-sppmmasyfv.bin.exe, 00000000.00000003.1191449570.00000000028A0000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: [autorun] |
Source: 250427-sppmmasyfv.bin.exe, 00000000.00000003.1191367754.00000000028A0000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: [autorun] |
Source: 250427-sppmmasyfv.bin.exe, 00000000.00000003.1191393925.00000000028A0000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: [autorun] |
Source: HelpMe.exe, 00000001.00000002.2398511650.00000000021B0000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INF |
Source: HelpMe.exe, 00000009.00000002.2398246376.00000000021E0000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INF |
Source: HelpMe.exe, 00000009.00000002.2397649835.00000000005FF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INFy |
Source: HelpMe.exe, 00000009.00000002.2397649835.00000000005FF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\AUTORUN.INFO |
Source: HelpMe.exe, 00000009.00000002.2397649835.00000000005FF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\AUTORUN.INF |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: :\AUTORUN.INF |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: [autorun] |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: AUTORUN.INF |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: AUTORUN.INF(t |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: AUTORUN.INFx |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: A@p[autorun] |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: 250427-sppmmasyfv.bin.exe | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: desktop.ini.exe1.0.dr | Binary or memory string: [autorun] |
Source: desktop.ini.exe1.0.dr | Binary or memory string: AUTORUN.INF |
Source: desktop.ini.exe1.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: desktop.ini.exe1.0.dr | Binary or memory string: AUTORUN.INFx |
Source: desktop.ini.exe1.0.dr | Binary or memory string: A@p[autorun] |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe1.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: [autorun] |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.exe.0.dr | Binary or memory string: 4'AUTORUN.INFD |
Source: .curlrc.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: .curlrc.exe.0.dr | Binary or memory string: [autorun] |
Source: .curlrc.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: .curlrc.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: .curlrc.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: .curlrc.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: .curlrc.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AUTORUN.INF.0.dr | Binary or memory string: [autorun] |
Source: desktop.ini.exe0.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: desktop.ini.exe0.0.dr | Binary or memory string: [autorun] |
Source: desktop.ini.exe0.0.dr | Binary or memory string: AUTORUN.INF |
Source: desktop.ini.exe0.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: desktop.ini.exe0.0.dr | Binary or memory string: AUTORUN.INFx |
Source: desktop.ini.exe0.0.dr | Binary or memory string: A@p[autorun] |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe0.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: desktop.ini.exe.0.dr | Binary or memory string: [autorun] |
Source: desktop.ini.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: desktop.ini.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: desktop.ini.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: desktop.ini.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: desktop.ini.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: AutoRun.exe.0.dr | Binary or memory string: [autorun] |
Source: AutoRun.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: AutoRun.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: AutoRun.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: AutoRun.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: AutoRun.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: :\AUTORUN.INF |
Source: HelpMe.exe.0.dr | Binary or memory string: [autorun] |
Source: HelpMe.exe.0.dr | Binary or memory string: AUTORUN.INF |
Source: HelpMe.exe.0.dr | Binary or memory string: AUTORUN.INF(t |
Source: HelpMe.exe.0.dr | Binary or memory string: AUTORUN.INFx |
Source: HelpMe.exe.0.dr | Binary or memory string: A@p[autorun] |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000110","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.861","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","CreateFileW","SUCCESS","0x00000120","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20200219080202.871","1748","63ca6d5db8cb42a97e67e81c98b7ffe4b342425f6a9baec9b252f8ef9b853d45","1772","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130647.999","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201024130648.010","1792","5f6f34cc1391e70f22092181b498750859fb29f2803fc280f49fa6917921a9cb","1748","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x00000118","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x000000b8","lpFileName->C:\AUTORUN.INF","dwDesiredAccess->GENERIC_READ" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.928","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","CreateFileW","SUCCESS","0x0000011c","lpFileName->C:\AUTORUN.INF.exe","dwDesiredAccess->GENERIC_READ | GENERIC_WRITE" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","DeleteFileW","FAILURE","","lpFileName->C:\AUTORUN.INF" |
Source: HelpMe.exe.0.dr | Binary or memory string: "20201103202142.938","1024","0fdbe35b386621441a0a7465d5d08fcec1d73acf54ab4ba5eb88d77f380a824e","1016","filesystem","MoveFileWithProgressW","FAILURE","","lpExistingFileName->C:\AUTORUN.INF.exe","lpNewFileName->C:\AUTORUN.INF" |