MalwareMustDie icon

Shadow Logger Registry Trace in Memory Dump (forensics)

MalwareMustDie | PRO | 01/02/14 11:38:15 AM UTC | 0 ⭐ | 11927 πŸ‘οΈ | Never ⏰ | []
text |

11.65 KB

|

None

|

0 πŸ‘

/

0 πŸ‘Ž

(37852): 0000007FC144   \REGISTRY\MACHINE
(37868): 0000007FC40A   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003
(37870): 0000007FC4B2   \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework
(37913): 0000007FC978   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
(37914): 0000007FCA1C   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
(37938): 0000007FD30E   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default
(37947): 0000007FD460   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Explorer
(37950): 0000007FD5EA   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
(37951): 0000007FD6A4   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003_CLASSES
(37952): 0000007FD73E   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
(37953): 0000007FD84E   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
(37954): 0000007FD906   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
(37955): 0000007FDA14   \REGISTRY\MACHINE\SOFTWARE\Classes
(37956): 0000007FDA6A   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003_CLASSES
(37958): 0000007FDB14   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(37960): 0000007FDB88   \REGISTRY\USER
(37962): 0000007FDBC6   \REGISTRY\MACHINE\SOFTWARE\Classes
(37964): 0000007FDC2C   \REGISTRY\USER
(37966): 0000007FDC6A   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(37968): 0000007FDCDE   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(37970): 0000007FDD52   \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID
(37972): 0000007FDDC4   \REGISTRY\MACHINE\SOFTWARE\Classes
(37974): 0000007FDE2A   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(37976): 0000007FDE9E   \REGISTRY\USER
(37978): 0000007FDEDC   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(37980): 0000007FDF50   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(37982): 0000007FDFC4   \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID
(37986): 0000007FE094   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003_CLASSES
(37987): 0000007FE12E   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings
(37996): 0000007FE31C   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003_CLASSES
(38013): 0000007FE636   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
(38015): 0000007FE748   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\ShellNoRoam
(38017): 0000007FE830   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache
(38026): 0000007FEBDC   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38032): 0000007FED6E   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38038): 0000007FEF9E   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38044): 0000007FF268   \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts
(38065): 0000007FF8F6   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38072): 0000007FFAF2   \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale
(38075): 0000007FFBDC   \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups
(38080): 0000007FFD56   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38081): 0000007FFE3C   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38082): 0000007FFF22   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38083): 000000800008   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38084): 0000008000EE   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38085): 0000008001D4   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38086): 0000008002BA   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38092): 0000008003F2   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38093): 0000008004D8   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38094): 0000008005BE   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38095): 0000008006A4   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38096): 00000080078A   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38097): 000000800870   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38098): 000000800956   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38099): 000000800A3C   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38100): 000000800B22   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(38101): 000000800C08   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(75953): 0000007FC144   \REGISTRY\MACHINE
(75969): 0000007FC40A   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003
(75971): 0000007FC4B2   \REGISTRY\MACHINE\SOFTWARE\Microsoft\.NETFramework
(76014): 0000007FC978   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
(76015): 0000007FCA1C   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
(76039): 0000007FD30E   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default
(76048): 0000007FD460   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Explorer
(76051): 0000007FD5EA   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
(76052): 0000007FD6A4   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003_CLASSES
(76053): 0000007FD73E   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
(76054): 0000007FD84E   \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
(76055): 0000007FD906   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
(76056): 0000007FDA14   \REGISTRY\MACHINE\SOFTWARE\Classes
(76057): 0000007FDA6A   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003_CLASSES
(76059): 0000007FDB14   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(76061): 0000007FDB88   \REGISTRY\USER
(76063): 0000007FDBC6   \REGISTRY\MACHINE\SOFTWARE\Classes
(76065): 0000007FDC2C   \REGISTRY\USER
(76067): 0000007FDC6A   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(76069): 0000007FDCDE   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(76071): 0000007FDD52   \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID
(76073): 0000007FDDC4   \REGISTRY\MACHINE\SOFTWARE\Classes
(76075): 0000007FDE2A   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(76077): 0000007FDE9E   \REGISTRY\USER
(76079): 0000007FDEDC   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(76081): 0000007FDF50   \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
(76083): 0000007FDFC4   \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID
(76087): 0000007FE094   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003_CLASSES
(76088): 0000007FE12E   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings
(76097): 0000007FE31C   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003_CLASSES
(76114): 0000007FE636   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
(76116): 0000007FE748   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\ShellNoRoam
(76118): 0000007FE830   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache
(76127): 0000007FEBDC   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76133): 0000007FED6E   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76139): 0000007FEF9E   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76145): 0000007FF268   \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts
(76166): 0000007FF8F6   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76173): 0000007FFAF2   \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale
(76176): 0000007FFBDC   \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups
(76181): 0000007FFD56   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76182): 0000007FFE3C   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76183): 0000007FFF22   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76184): 000000800008   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76185): 0000008000EE   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76186): 0000008001D4   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76187): 0000008002BA   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76193): 0000008003F2   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76194): 0000008004D8   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76195): 0000008005BE   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76196): 0000008006A4   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76197): 00000080078A   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76198): 000000800870   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76199): 000000800956   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76200): 000000800A3C   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76201): 000000800B22   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run
(76202): 000000800C08   \REGISTRY\USER\S-1-5-21-1214440339-926492609-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Run

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    πŸ‘

    /

    πŸ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    πŸ‘

    /

    πŸ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    πŸ‘

    /

    πŸ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    πŸ‘

    /

    πŸ‘Ž

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    πŸ‘

    /

    πŸ‘Ž