Description | Time |
---|---|
winrar.exe (PID:4312) modified energy-report.html in c:\programdata\microsoft\windows\power efficiency diagnostics | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 01.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 02.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 03.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 04.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 05.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 06.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 07.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 08.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 09.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified ringtone 10.wma in c:\programdata\microsoft\windows\ringtones | 7/13/2016, 8:50:02 AM |
winrar.exe (PID:4312) modified wer4f58.tmp.werdatacollectionfailure.txt in c:\programdata\microsoft\windows\wer\reportqueue\appcrash_remediationservi_42e59132c53d35a61a571b722665b5506cbf3c_cab_0ace4f57 | 7/13/2016, 8:50:03 AM |
winrar.exe (PID:4312) modified unhandled.txt in c:\users\pashap\appdata\local\checkpoint\endpoint security\threat emulation | 7/13/2016, 8:50:03 AM |
winrar.exe (PID:4312) modified main.html in c:\users\pashap\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0 | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified main.html in c:\users\pashap\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0 | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified main.html in c:\users\pashap\appdata\local\google\chrome\user data\default\extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0 | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified craw_window.html in c:\users\pashap\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_0\html | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified index.txt in c:\users\pashap\appdata\local\google\chrome\user data\default\service worker\cachestorage\2af31d7a47c00c79f2c81ae400c6156ec6c19415 | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified brndlog.txt in c:\users\pashap\appdata\local\microsoft\internet explorer | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified mainwindow[1].htm in c:\users\pashap\appdata\local\microsoft\windows\temporary internet files\content.ie5\1hgz4e8n | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified mainwindow[1].htm in c:\users\pashap\appdata\local\microsoft\windows\temporary internet files\content.ie5\jtz0su9z | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified mainwindow[2].htm in c:\users\pashap\appdata\local\microsoft\windows\temporary internet files\content.ie5\jtz0su9z | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified mainwindow[1].htm in c:\users\pashap\appdata\local\microsoft\windows\temporary internet files\content.ie5\kipmv6sx | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified notifier[1].htm in c:\users\pashap\appdata\local\microsoft\windows\temporary internet files\content.ie5\vs7n3lhq | 7/13/2016, 8:50:06 AM |
winrar.exe (PID:4312) modified plugins.md5[1].txt in c:\users\pashap\appdata\local\microsoft\windows\temporary internet files\content.ie5\vs7n3lhq | 7/13/2016, 8:50:06 AM |
Description | Time |
---|---|
ctb-faker.exe (PID:3336) creates a ransom message in c:\programdata\your personal files are encrypted.txt | 7/13/2016, 8:40:51 AM |
cmd.exe (PID:4148) creates a ransom message in c:\your personal files are encrypted.txt | 7/13/2016, 8:40:58 AM |
Description | Time |
---|---|
wscript.exe (PID:2472) [integrity: high] has a higher privilege than ctb-faker.exe (PID:3424) [integrity: medium] | 7/13/2016, 8:40:52 AM |
wscript.exe (PID:1748) [integrity: high] has a higher privilege than ctb-faker.exe (PID:3424) [integrity: medium] | 7/13/2016, 8:40:52 AM |
wscript.exe (PID:3580) [integrity: high] has a higher privilege than ctb-faker.exe (PID:3424) [integrity: medium] | 7/13/2016, 8:40:52 AM |
wscript.exe (PID:1440) [integrity: high] has a higher privilege than ctb-faker.exe (PID:3424) [integrity: medium] | 7/13/2016, 8:40:52 AM |
startup.exe (PID:4132) [integrity: high] has a higher privilege than ctb-faker.exe (PID:3424) [integrity: medium] | 7/13/2016, 8:40:57 AM |
cmd.exe (PID:4156) [integrity: high] has a higher privilege than ctb-faker.exe (PID:3424) [integrity: medium] | 7/13/2016, 8:40:57 AM |
cmd.exe (PID:4148) [integrity: high] has a higher privilege than ctb-faker.exe (PID:3424) [integrity: medium] | 7/13/2016, 8:40:57 AM |
winrar.exe (PID:4312) [integrity: high] has a higher privilege than ctb-faker.exe (PID:3424) [integrity: medium] | 7/13/2016, 8:40:58 AM |
ctb-faker.exe (PID:3336) [integrity: high] has a higher privilege than ctb-faker.exe (PID:3424) [integrity: medium] | 9/7/2019, 8:27:21 PM |
Description | Time |
---|---|
startup.exe (PID:4132) modified HKU\s-1-5-21-1350185060-4047523286-3791768344-1000\software\microsoft\windows\currentversion\run\help.exe = C:\ProgramData\help.exe | 7/13/2016, 8:40:57 AM |
Description | Time |
---|---|
winrar.exe (PID:4312) executed with arguments: a -afzip -x*.exe -x*.msi -x*.dll -x*.jpg -x*.jpeg -x*.bmp -x*.gif -x*.png -x*.psd -x*.mp3 -x*.wav -x*.mp4 -x*.avi -x*.zip -x*.rar -x*.iso -x*.7z -x*.cab -x*.dat -x*.data -m0 -df -ibck -inul -ioff -ri15:0 -p4w1q3x5y8z "C:\Users.zip" "C:\Users" | 7/13/2016, 8:40:58 AM |
Description | Time |
---|---|
c:\programdata\archiver.bat was created by ctb-faker.exe (PID:3336) and deleted by winrar.exe (PID:4312) | 7/13/2016, 8:50:02 AM |
c:\programdata\archiver.vbs was created by ctb-faker.exe (PID:3336) and deleted by winrar.exe (PID:4312) | 7/13/2016, 8:50:02 AM |
c:\programdata\copy.bat was created by ctb-faker.exe (PID:3336) and deleted by winrar.exe (PID:4312) | 7/13/2016, 8:50:02 AM |
c:\programdata\copy.vbs was created by ctb-faker.exe (PID:3336) and deleted by winrar.exe (PID:4312) | 7/13/2016, 8:50:02 AM |
c:\programdata\microsoft\windows\start menu\programs\adobe reader xi.lnk was created by msiexec.exe (PID:3076) and deleted by winrar.exe (PID:4312) | 7/13/2016, 8:50:03 AM |
c:\programdata\startup.vbs was created by ctb-faker.exe (PID:3336) and deleted by winrar.exe (PID:4312) | 7/13/2016, 8:50:03 AM |
c:\programdata\untitled.vbs was created by ctb-faker.exe (PID:3336) and deleted by winrar.exe (PID:4312) | 7/13/2016, 8:50:03 AM |
Description | Time |
---|---|
winrar.exe (PID:4312) executed with arguments: a -afzip -x*.exe -x*.msi -x*.dll -x*.jpg -x*.jpeg -x*.bmp -x*.gif -x*.png -x*.psd -x*.mp3 -x*.wav -x*.mp4 -x*.avi -x*.zip -x*.rar -x*.iso -x*.7z -x*.cab -x*.dat -x*.data -m0 -df -ibck -inul -ioff -ri15:0 -p4w1q3x5y8z "C:\Users.zip" "C:\Users" | 7/13/2016, 8:40:58 AM |
winrar.exe (PID:4312) created users.zip in c: | 7/13/2016, 8:41:32 AM |
Description | Time |
---|---|
cmd.exe (PID:4156) executed with arguments: /c ""C:\ProgramData\archiver.bat" " | 7/13/2016, 8:40:57 AM |
cmd.exe (PID:4148) executed with arguments: /c ""C:\ProgramData\copy.bat" " | 7/13/2016, 8:40:57 AM |
Description | Time |
---|---|
startup.exe (PID:4132) modified HKU\s-1-5-21-1350185060-4047523286-3791768344-1000\software\microsoft\windows\currentversion\run\help.exe = C:\ProgramData\help.exe | 7/13/2016, 8:40:57 AM |
Description | Time |
---|---|
wscript.exe (PID:2472) executed with arguments: "C:\ProgramData\archiver.vbs" | 7/13/2016, 8:40:52 AM |
wscript.exe (PID:1748) executed with arguments: "C:\ProgramData\untitled.vbs" | 7/13/2016, 8:40:52 AM |
wscript.exe (PID:3580) executed with arguments: "C:\ProgramData\startup.vbs" | 7/13/2016, 8:40:52 AM |
wscript.exe (PID:1440) executed with arguments: "C:\ProgramData\copy.vbs" | 7/13/2016, 8:40:52 AM |
cmd.exe (PID:4156) executed with arguments: /c ""C:\ProgramData\archiver.bat" " | 7/13/2016, 8:40:57 AM |
cmd.exe (PID:4148) executed with arguments: /c ""C:\ProgramData\copy.bat" " | 7/13/2016, 8:40:57 AM |
Description | Time |
---|---|
wscript.exe (PID:2472) executed with arguments: "C:\ProgramData\archiver.vbs" | 7/13/2016, 8:40:52 AM |
wscript.exe (PID:1748) executed with arguments: "C:\ProgramData\untitled.vbs" | 7/13/2016, 8:40:52 AM |
wscript.exe (PID:3580) executed with arguments: "C:\ProgramData\startup.vbs" | 7/13/2016, 8:40:52 AM |
wscript.exe (PID:1440) executed with arguments: "C:\ProgramData\copy.vbs" | 7/13/2016, 8:40:52 AM |
startup.exe (PID:4132) executed. | 7/13/2016, 8:40:57 AM |
cmd.exe (PID:4156) executed with arguments: /c ""C:\ProgramData\archiver.bat" " | 7/13/2016, 8:40:57 AM |
cmd.exe (PID:4148) executed with arguments: /c ""C:\ProgramData\copy.bat" " | 7/13/2016, 8:40:57 AM |
winrar.exe (PID:4312) executed with arguments: a -afzip -x*.exe -x*.msi -x*.dll -x*.jpg -x*.jpeg -x*.bmp -x*.gif -x*.png -x*.psd -x*.mp3 -x*.wav -x*.mp4 -x*.avi -x*.zip -x*.rar -x*.iso -x*.7z -x*.cab -x*.dat -x*.data -m0 -df -ibck -inul -ioff -ri15:0 -p4w1q3x5y8z "C:\Users.zip" "C:\Users" | 7/13/2016, 8:40:58 AM |
Description | Time |
---|---|
ctb-faker.exe (PID:3336) created startup.vbs in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created untitled.vbs in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created archiver.bat in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created archiver.vbs in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created copy.bat in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created copy.vbs in c:\programdata | 7/13/2016, 8:40:51 AM |
Description | Time |
---|---|
ctb-faker.exe (PID:3336) created rarext64.dll in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created rarext.dll in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created unacev2.dll in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created 7zxa.dll in c:\programdata | 7/13/2016, 8:40:51 AM |
Description | Time |
---|---|
ctb-faker.exe (PID:3336) created rar.exe in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created restore.exe in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created startup.exe in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created unrar.exe in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created winrar.exe in c:\programdata | 7/13/2016, 8:40:51 AM |
ctb-faker.exe (PID:3336) created help.exe in c:\programdata | 7/13/2016, 8:40:51 AM |
Description | Time |
---|---|
ctb-faker.exe (PID:3424) executed. | 7/13/2016, 8:40:45 AM |
startup.exe (PID:4132) executed. | 7/13/2016, 8:40:57 AM |
winrar.exe (PID:4312) executed with arguments: a -afzip -x*.exe -x*.msi -x*.dll -x*.jpg -x*.jpeg -x*.bmp -x*.gif -x*.png -x*.psd -x*.mp3 -x*.wav -x*.mp4 -x*.avi -x*.zip -x*.rar -x*.iso -x*.7z -x*.cab -x*.dat -x*.data -m0 -df -ibck -inul -ioff -ri15:0 -p4w1q3x5y8z "C:\Users.zip" "C:\Users" | 7/13/2016, 8:40:58 AM |
help.exe (PID:1860) executed. | 7/13/2016, 8:55:18 AM |
ctb-faker.exe (PID:3336) executed. | 9/7/2019, 8:27:21 PM |
Description | Time |
---|---|
startup.exe (PID:4132) modified HKU\s-1-5-21-1350185060-4047523286-3791768344-1000\software\microsoft\windows\currentversion\run\help.exe = C:\ProgramData\help.exe | 7/13/2016, 8:40:57 AM |
winrar.exe (PID:4312) modified HKU\s-1-5-21-1350185060-4047523286-3791768344-1000\software\winrar\general\verinfo | 7/13/2016, 8:40:58 AM |
ctb-faker.exe (PID:3336) modified HKU\s-1-5-21-1350185060-4047523286-3791768344-1000_classes\local settings\muicache\6f\52c64b7e\@c:\windows\system32\wshext.dll,-4511 = Open &with Command Prompt | 9/7/2019, 8:27:21 PM |
ctb-faker.exe (PID:3336) modified HKU\s-1-5-21-1350185060-4047523286-3791768344-1000\software\microsoft\windows\currentversion\explorer\fileexts\.vbs\openwithprogids\vbsfile | 9/7/2019, 8:27:21 PM |
Description | Time |
---|---|
ctb-faker.exe (PID:3336) was running at integrity level: high. A User Account Control popup was shown. Based on the elevation the user is assumed to have accepted. | 9/7/2019, 8:27:21 PM |
Description | Time |
---|---|
ctb-faker.exe (PID:3424) executed. | 7/13/2016, 8:40:45 AM |