restr.exe is usually located in the 'c:\downloads\' folder.
Some of the anti-virus scanners at VirusTotal detected restr.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
restr.exe is not signed.
53 of the 73 anti-virus programs at VirusTotal detected the restr.exe file. That's a 73% detection rate.
| Scanner | Detection Name |
|---|---|
| Ad-Aware | Gen:Variant.Strictor.173808 |
| AegisLab | Trojan.Win32.Scar.4!c |
| AhnLab-V3 | Malware/Win32.Generic.C2478501 |
| Alibaba | Trojan:Win32/Scar.c69e6b10 |
| ALYac | Gen:Variant.Strictor.173808 |
| APEX | Malicious |
| Arcabit | Trojan.Strictor.D2A6F0 |
| Avast | Win32:Trojan-gen |
| AVG | Win32:Trojan-gen |
| Avira | HEUR/AGEN.1000506 |
| BitDefender | Gen:Variant.Strictor.173808 |
| CAT-QuickHeal | Trojan.Presenoker |
| Comodo | Malware@#1gujooy1ayemr |
| CrowdStrike | win/malicious_confidence_70% (W) |
| Cybereason | malicious.10a9d1 |
| Cylance | Unsafe |
| Cyren | W32/Strictor.OVKQ-2539 |
| DrWeb | Program.SrvAny |
| Emsisoft | Gen:Variant.Strictor.173808 (B) |
| Endgame | malicious (moderate confidence) |
| ESET-NOD32 | BAT/Agent.OPA |
| F-Prot | W32/Strictor.BG |
| F-Secure | Heuristic.HEUR/AGEN.1000506 |
| FireEye | Generic.mg.d845a3510a9d1273 |
| Fortinet | W32/Scar.RTRD!tr |
| GData | Win32.Trojan.Agent.30ZPKK |
| Ikarus | PUA.Presenoker |
| Invincea | heuristic |
| K7AntiVirus | Unwanted-Program ( 005445961 ) |
| K7GW | Unwanted-Program ( 005445961 ) |
| Kaspersky | Trojan.Win32.Scar.rtrd |
| Malwarebytes | RiskWare.BatFile |
| MAX | malware (ai score=100) |
| MaxSecure | Trojan.Malware.11973.susgen |
| McAfee | RDN/Generic.grp |
| McAfee-GW-Edition | RDN/Generic.grp |
| Microsoft | Trojan:Win32/Occamy.C |
| MicroWorld-eScan | Gen:Variant.Strictor.173808 |
| Paloalto | generic.ml |
| Qihoo-360 | Win32/Trojan.5b5 |
| Rising | Malware.Undefined!8.C (CLOUD) |
| Sophos | Generic PUA ML (PUA) |
| Symantec | SMG.Heur!gen |
| Tencent | Win32.Trojan.Scar.Wqwj |
| TheHacker | Posible_Worm32 |
| TrendMicro | TROJ_GEN.R020C0OCA19 |
| TrendMicro-HouseCall | TROJ_GEN.R020C0OCA19 |
| VBA32 | Trojan.Scar |
| VIPRE | Win32.Malware!Drop |
| ViRobot | Trojan.Win32.S.Agent.81082 |
| Webroot | W32.Malware.Gen |
| Yandex | Riskware.SrvAny! |
| ZoneAlarm | Trojan.Win32.Scar.rtrd |
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{
"guid": [
"{4590f812-1d3a-11d0-891f-00aa004b2e24}",
"{00000003-0000-0000-c000-000000000046}",
"{eac04bc0-3791-11d2-bb95-0060977b464c}",
"{00bb2763-6a77-11d0-a535-00c04fd7d062}",
"{00000000-0000-0000-c000-000000000046}",
"{4590f811-1d3a-11d0-891f-00aa004b2e24}",
"{44aca674-e8fc-11d0-a07c-00c04fb68820}",
"{674b6698-ee92-11d0-ad71-00c04fd8fdff}",
"{8bc3f05e-d86b-11d0-a075-00c04fb68820}",
"{807c1e6c-1d00-453f-b920-b61bb7cdd997}",
"{7c857801-7381-11cf-884d-00aa004b2e24}",
"{d5f569d0-593b-101a-b569-08002b2dbf7a}",
"{5e078e03-8265-4bbe-9487-d242edbef910}",
"{f309ad18-d86a-11d0-a075-00c04fb68820}",
"{03c036f1-a186-11d0-824a-00aa005b4383}",
"{00bb2765-6a77-11d0-a535-00c04fd7d062}",
"{dc12a687-737f-11cf-884d-00aa004b2e24}"
],
"file_recreated": [
"\\??\\nul",
"\\??\\Nsi"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ObjectName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ErrorControl",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\DisplayName",
"HKEY_CURRENT_USER\\Software\\WinRAR SFX\\C%%Windows%shdd",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ImagePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Parameters\\Application"
],
"dll_loaded": [
"COMDLG32.dll",
"kernel32.dll",
"UxTheme.dll",
"C:\\Windows\\system32\\ole32.dll",
"dwmapi.dll",
"C:\\Windows\\syswow64\\MSCTF.dll",
"API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
"KERNEL32.DLL",
"comctl32",
"ole32.dll",
"COMCTL32.dll",
"USER32.dll",
"IMM32.dll",
"riched32.dll",
"C:\\Windows\\system32\\Winsta.dll",
"riched20.dll",
"OLEAUT32.dll",
"SHELL32.dll",
"comctl32.dll",
"C:\\Windows\\system32\\shell32.dll",
"GDI32.dll",
"C:\\Windows\\system32\\mswsock.dll",
"ADVAPI32.dll",
"rpcrt4.dll",
"C:\\Windows\\System32\\wshtcpip.dll",
"SETUPAPI.dll",
"COMCTL32.DLL"
],
"file_opened": [
"C:\\Windows\\shdd\\hddsmart.bat",
"C:\\",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
"C:\\Windows\\shdd\\hddsvc.exe",
"C:\\Windows\\win.ini",
"C:\\Windows\\shdd",
"C:\\Windows\\SysWOW64\\en-US\\sc.exe.mui",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin",
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\shdd\\ins.bat"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_CURRENT_USER\\Software",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Winsock",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Policies",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
"HKEY_CURRENT_USER\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete",
"HKEY_CURRENT_USER\\Control Panel\\Desktop",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip6\\Parameters\\Winsock",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart\\Parameters",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
"HKEY_LOCAL_MACHINE\\Software",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Setup Migration\\Providers",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
"HKEY_CLASSES_ROOT\\CLSID\\{00BB2763-6A77-11D0-A535-00C04FD7D062}\\InProcServer32",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor",
"HKEY_CURRENT_USER\\Software\\Policies",
"HKEY_CLASSES_ROOT\\CLSID\\{03C036F1-A186-11D0-824A-00AA005B4383}\\InProcServer32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Parameters",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete\\Client\\",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\WinRAR SFX",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\System",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\WBEM\\CIMOM",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete"
],
"resolves_host": [
"127.0.0.1"
],
"file_written": [
"C:\\Windows\\shdd\\hddsvc.exe",
"C:\\Windows\\shdd\\hddsmart.bat",
"C:\\Windows\\shdd\\ins.bat",
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Windows\\shdd\\instsrv.exe"
],
"file_deleted": [
"C:\\Windows\\shdd\\ins.bat",
"C:\\Windows\\shdd\\__tmp_rar_sfx_access_check_14496812"
],
"file_exists": [
"C:\\Windows\\shdd\\instsrv.exe",
"C:\\Windows\\shdd\\hddsvc.exe",
"C:\\Windows\\shdd\\\"C:\\Windows\\shdd\\ins.bat\"",
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Windows\\shdd\\ser.reg",
"C:\\Windows\\shdd",
"C:\\Windows\\instsrv.exe",
"C:\\Windows\\hddsmart.exe",
"C:\\Windows\\shdd\\hddsmart.bat",
"C:\\Windows\\shdd\\ins.bat"
],
"file_moved": [
[
"C:\\Windows\\shdd\\instsrv.exe",
"C:\\Windows\\instsrv.exe"
],
[
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Windows\\hddsmart.exe"
]
],
"file_failed": [
"C:\\Windows\\shdd\\ins.bat"
],
"wmi_query": [
"SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = \"hddsmart.exe\")"
],
"file_created": [
"C:\\Windows\\shdd\\instsrv.exe",
"C:\\Windows\\shdd\\__tmp_rar_sfx_access_check_14496812",
"C:\\Windows\\shdd\\hddsvc.exe",
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Windows\\shdd\\hddsmart.bat",
"C:\\Windows\\shdd\\ins.bat"
],
"command_line": [
"attrib +h +s C:\\Windows\\shdd\\hddsmart.bat",
"Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"DisplayName\" \/t REG_SZ \/d \"Smart HDD\" \/f",
"sc start HddSmart",
"sc config HddSmart DisplayName= \"Smart HDD\"",
"ping 127.0.0.1 -n 1",
"ping 127.0.0.1 -n 2",
"reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ImagePath\" \/t REG_EXPAND_SZ \/d \"C:\\Windows\\shdd\\hddsvc.exe\" \/f",
"Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\\Parameters\" \/v \"Application\" \/t REG_SZ \/d \"C:\\Windows\\shdd\\hddsmart.bat\" \/f",
"Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ObjectName\" \/t REG_SZ \/d \"LocalSystem\" \/f",
"Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Description\" \/t REG_SZ \/d \"Service for determining the performance of hard disks and defragmenting the file system. SMARTHDD allows you to change the characteristics of hard and solid-state drives, changing the speed of the positioning of magnetic heads (AAM) and fine-tuning the level of energy-saving drives (APM). The system of dynamic read-write load allows to increase by 50-60.\" \/f",
"reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Type\" \/t REG_DWORD \/d \"16\" \/f",
"reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Start\" \/t REG_DWORD \/d \"2\" \/f",
"C:\\Windows\\instsrv.exe HddSmart C:\\Windows\\shdd\\hddsvc.exe",
"reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ErrorControl\" \/t REG_DWORD \/d \"1\" \/f",
"\"C:\\Windows\\shdd\\ins.bat\" ",
"C:\\Windows\\shdd\\ins.bat",
"taskkill \/f \/im hddsmart.exe"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin",
"C:\\Windows\\win.ini",
"C:\\Windows\\shdd\\ins.bat"
],
"regkey_read": [
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\AutoComplete\\Always Use Tab",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DisableUNCCheck",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Description",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DelayedExpansion",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Parameters\\Application",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\CompletionChar",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollDelay",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\DisplayName",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{03C036F1-A186-11D0-824A-00AA005B4383}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AccListViewV6",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\CIMOM\\EnableObjectValidation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\PathCompletionChar",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language\\InstallLanguageFallback",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DefaultColor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInset",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\DefaultLevel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\PathCompletionChar",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\EnableExtensions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\EMPTY",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\EnableExtensions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\AutoComplete\\AutoSuggest",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\CIMOM\\Logging",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\MuiCached\\MachinePreferredUILanguages",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\UILanguages\\en-US\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ImagePath",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DefaultColor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\AutoRun",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ErrorControl",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32\\(Default)",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\PreferredUILanguages",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\UILanguages\\en-US\\AlternateCodePage",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DelayedExpansion",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewAlphaSelect",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInterval",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Start",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragMinDist",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Srp\\GP\\RuleCount",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\LogFileName",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\CompletionChar",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\AutoComplete\\Client\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\UseDoubleClickTimer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\Levels",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\EnableBalloonTips",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DisableUNCCheck",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{00BB2763-6A77-11D0-A535-00C04FD7D062}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\DefaultTTL",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\PolicyScope",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\SmoothScroll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\SaferFlags",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewShadow",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\AutoRun"
],
"directory_enumerated": [
"C:\\Python27\\attrib",
"C:\\Windows\\System32\\attrib.COM",
"C:\\Python27\\Scripts\\attrib",
"C:\\Windows\\shdd",
"C:\\Python27\\taskkill.*",
"C:\\Windows\\shdd\\attrib.*",
"C:\\Python27\\Reg",
"C:\\Windows\\System32\\attrib.*",
"C:\\Python27\\reg.*",
"C:\\Windows\\shdd\\ser.reg",
"C:\\Python27\\Scripts\\reg.*",
"C:\\Windows\\shdd\\taskkill.*",
"C:\\Windows\\shdd\\ping",
"C:\\Python27\\Scripts\\attrib.*",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin",
"C:\\Windows\\shdd\\attrib",
"C:\\Python27\\Scripts\\taskkill.*",
"C:\\Python27\\sc",
"C:\\Windows\\System32\\reg.*",
"C:\\Windows\\shdd\\taskkill",
"C:\\Windows\\System32\\PING.COM",
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Python27\\Reg.*",
"C:\\Python27\\Scripts\\Reg",
"C:\\Python27\\Scripts\\sc.*",
"C:\\Windows\\shdd\\ping.*",
"C:\\Python27\\sc.*",
"C:\\Windows\\shdd\\hddsmart.bat",
"C:\\Python27\\attrib.*",
"C:\\Windows\\System32\\PING.EXE",
"C:\\Windows\\System32\\Reg.*",
"C:\\Windows\\System32\\reg.COM",
"C:\\Windows\\System32\\taskkill.*",
"C:\\Windows\\System32\\sc.COM",
"C:\\Python27\\Scripts\\taskkill",
"C:\\Windows\\shdd\\Reg.*",
"C:\\Python27\\Scripts\\reg",
"C:\\Windows\\shdd\\Reg",
"C:\\Windows\\System32\\taskkill.exe",
"C:\\Windows\\shdd\\sc.*",
"C:\\Python27\\Scripts\\ping.*",
"C:\\Windows\\System32\\sc.*",
"C:\\Python27\\ping.*",
"C:\\Python27\\Scripts\\sc",
"C:\\Windows\\System32\\sc.exe",
"C:\\Windows\\shdd\\instsrv.exe",
"C:\\Python27\\ping",
"C:\\Windows\\System32\\attrib.exe",
"C:\\Python27\\Scripts\\ping",
"C:\\Windows\\shdd\\reg.*",
"C:\\Python27\\reg",
"C:\\Windows\\System32\\taskkill.COM",
"C:\\Windows\\shdd\\sc",
"C:\\Windows\\shdd\\reg",
"C:\\Python27\\Scripts\\Reg.*",
"C:\\Windows",
"C:\\Windows\\instsrv.exe",
"C:\\Python27\\taskkill",
"C:\\Windows\\System32\\ping.*",
"C:\\Windows\\shdd\\ins.bat",
"C:\\Windows\\System32\\reg.exe"
],
"directory_created": [
"C:\\Windows",
"C:\\Windows\\shdd",
"C:\\Users\\cuck\\AppData\\Local\\Temp"
]
}[
{
"yara": [],
"sha1": "2190fb9c9e2e4afd2db146028853462e39f48596",
"name": "9fe0f7f2c11f583d_instsrv.exe",
"filepath": "c:\\windows\\instsrv.exe",
"type": "PE32 executable (console) Intel 80386, for MS Windows",
"sha256": "9fe0f7f2c11f583dba91dc8e002f77f0c27ca4ce5c6e913b8d8b113084fd7e60",
"urls": [],
"crc32": "F0092F54",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/1072\/files\/9fe0f7f2c11f583d_instsrv.exe",
"ssdeep": null,
"size": 37888,
"sha512": "3a74c4d96bba0119a8ce3e3c2a86bc0a00bbd34eb996e5533b95b8e962e516f13cc52d6dd038ce1e7fc43b974abff2354fe60b1a834c146ad14553d391d51240",
"pids": [
2420,
1516
],
"md5": "7bc1928cd1d6ea2bce5fdb1fdeac0b3d"
},
{
"yara": [],
"sha1": "6f655296f2492b2707dd2cf14a95fa2a8829dd8d",
"name": "c9f42e3ad89398d7_hddsmart.bat",
"filepath": "C:\\Windows\\shdd\\hddsmart.bat",
"type": "ASCII text, with CRLF line terminators",
"sha256": "c9f42e3ad89398d7b3c54f68811981a8c8f9cdc3dd40d4ac97c8f6a3ee09c1b5",
"urls": [],
"crc32": "EEEB7932",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/1072\/files\/c9f42e3ad89398d7_hddsmart.bat",
"ssdeep": null,
"size": 524,
"sha512": "df547a01ac092403239ecc3190e1b8bf5f681133ac24c60de419c044142eed047541035310acfa44bf3a422c918952c6685a0ae45adcc7ced1fd7dc4c2ddfc7b",
"pids": [
2420
],
"md5": "af84cc312b2f4f309f4d818a400980d2"
},
{
"yara": [],
"sha1": "cb6ec5f52faff405a3174ce2804f59df2cb7be7f",
"name": "781118256e1e96e7_hddsmart.exe",
"filepath": "c:\\windows\\hddsmart.exe",
"type": "PE32 executable (GUI) Intel 80386, for MS Windows",
"sha256": "781118256e1e96e76c6ebea4478003ecaaf497dab1529c702fa8595d2e3646db",
"urls": [],
"crc32": "CFF31D3B",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/1072\/files\/781118256e1e96e7_hddsmart.exe",
"ssdeep": null,
"size": 6144,
"sha512": "9a0b58370cff2398fadd916042a58f743fef8a0a07d9396297cd5f9aead5573eae125c915874ea9164ab37b02e3cfc43aa1ab5654ff7acb6611e88a0a6bb3e13",
"pids": [
2420,
1516
],
"md5": "def69f8bcbc83adb45f8aeb4453f2e35"
},
{
"yara": [],
"sha1": "33659140c3842d6753e4389aa49612333a0d166d",
"name": "576911063b10114a_hddsvc.exe",
"filepath": "C:\\Windows\\shdd\\hddsvc.exe",
"type": "PE32 executable (console) Intel 80386, for MS Windows",
"sha256": "576911063b10114a4844a039c771bc4eef631a457ae3775d7645604ef2950f4f",
"urls": [],
"crc32": "826DD575",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/1072\/files\/576911063b10114a_hddsvc.exe",
"ssdeep": null,
"size": 15872,
"sha512": "5d9a931ccc18877ce1886d7813c7c10d31980874eda11aeea94a9298602b610c5b288e9622bb3f565545a5be61d22eec756cc1fd2c5fcf47e242a21d6d5f42bb",
"pids": [
2420
],
"md5": "f3ca8234f60eba24604b5a9390d2fed5"
},
{
"yara": [],
"sha1": "da39a3ee5e6b4b0d3255bfef95601890afd80709",
"name": "e3b0c44298fc1c14___tmp_rar_sfx_access_check_14496812",
"type": "empty",
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
"urls": [],
"crc32": "00000000",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/1072\/files\/e3b0c44298fc1c14___tmp_rar_sfx_access_check_14496812",
"ssdeep": null,
"size": 0,
"sha512": "cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e",
"md5": "d41d8cd98f00b204e9800998ecf8427e"
},
{
"yara": [],
"sha1": "a64181b8ea1a2a67816251a01ad2801a0eaa363e",
"name": "410d3ac12317925b_ins.bat",
"filepath": "C:\\Windows\\shdd\\ins.bat",
"type": "ASCII text, with very long lines, with CRLF line terminators",
"sha256": "410d3ac12317925b385244b3a532f8716fba3487963d0f27ac7fa8dd7ffe0797",
"urls": [],
"crc32": "2EE41715",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/1072\/files\/410d3ac12317925b_ins.bat",
"ssdeep": null,
"size": 1782,
"sha512": "674eaa50d13b357d1ebe5b76d04cd778dfd8e2b91ce9212347ae1ec3f2f7340472625ceda0bc5739793e206f9ad946e8a3959fb3cd8d33865a680c38df30698c",
"pids": [
2420,
1516
],
"md5": "f841ab33b9003c314a2f26959e760c24"
}
][
{
"process_path": "C:\\Windows\\SysWOW64\\PING.EXE",
"process_name": "PING.EXE",
"pid": 2816,
"summary": {
"file_recreated": [
"\\??\\Nsi"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip6\\Parameters\\Winsock",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Winsock",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Parameters",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Setup Migration\\Providers"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\DefaultTTL",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID"
],
"dll_loaded": [
"rpcrt4.dll",
"C:\\Windows\\System32\\wshtcpip.dll",
"C:\\Windows\\system32\\mswsock.dll"
],
"resolves_host": [
"127.0.0.1"
]
},
"first_seen": 1563267195.3275,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\attrib.exe",
"process_name": "attrib.exe",
"pid": 2684,
"summary": {
"file_opened": [
"C:\\Windows\\shdd\\hddsmart.bat"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles"
],
"directory_enumerated": [
"C:\\Windows\\shdd\\hddsmart.bat",
"C:\\Windows\\shdd"
]
},
"first_seen": 1563267198.2494,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\reg.exe",
"process_name": "reg.exe",
"pid": 2700,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Type",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
],
"dll_loaded": [
"kernel32.dll"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Type"
]
},
"first_seen": 1563267196.0306,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\reg.exe",
"process_name": "reg.exe",
"pid": 2948,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
],
"dll_loaded": [
"kernel32.dll"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ImagePath"
]
},
"first_seen": 1563267196.3744,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\PING.EXE",
"process_name": "PING.EXE",
"pid": 2812,
"summary": {
"file_recreated": [
"\\??\\Nsi"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip6\\Parameters\\Winsock",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Winsock",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Parameters",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Setup Migration\\Providers"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\DefaultTTL",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID"
],
"dll_loaded": [
"rpcrt4.dll",
"C:\\Windows\\System32\\wshtcpip.dll",
"C:\\Windows\\system32\\mswsock.dll"
],
"resolves_host": [
"127.0.0.1"
]
},
"first_seen": 1563267193.9369,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\instsrv.exe",
"process_name": "instsrv.exe",
"pid": 2876,
"summary": {
"file_opened": [
"C:\\Windows\\shdd\\hddsvc.exe"
]
},
"first_seen": 1563267193.6712,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\reg.exe",
"process_name": "reg.exe",
"pid": 2376,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ErrorControl",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
],
"dll_loaded": [
"kernel32.dll"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ErrorControl"
]
},
"first_seen": 1563267196.2181,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\reg.exe",
"process_name": "reg.exe",
"pid": 2332,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Start",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
],
"dll_loaded": [
"kernel32.dll"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Start"
]
},
"first_seen": 1563267195.8431,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\reg.exe",
"process_name": "reg.exe",
"pid": 3020,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ObjectName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
],
"dll_loaded": [
"kernel32.dll"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ObjectName"
]
},
"first_seen": 1563267195.6869,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\System32\\lsass.exe",
"process_name": "lsass.exe",
"pid": 476,
"summary": {},
"first_seen": 1563267191.3438,
"ppid": 376
},
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin",
"process_name": "6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin",
"pid": 2420,
"summary": {
"file_created": [
"C:\\Windows\\shdd\\instsrv.exe",
"C:\\Windows\\shdd\\__tmp_rar_sfx_access_check_14496812",
"C:\\Windows\\shdd\\hddsvc.exe",
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Windows\\shdd\\hddsmart.bat",
"C:\\Windows\\shdd\\ins.bat"
],
"directory_created": [
"C:\\Windows\\shdd",
"C:\\Windows",
"C:\\Users\\cuck\\AppData\\Local\\Temp"
],
"dll_loaded": [
"COMDLG32.dll",
"kernel32.dll",
"UxTheme.dll",
"C:\\Windows\\system32\\ole32.dll",
"dwmapi.dll",
"C:\\Windows\\syswow64\\MSCTF.dll",
"KERNEL32.DLL",
"API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
"comctl32",
"ole32.dll",
"COMCTL32.dll",
"USER32.dll",
"IMM32.dll",
"riched32.dll",
"riched20.dll",
"OLEAUT32.dll",
"SHELL32.dll",
"comctl32.dll",
"C:\\Windows\\system32\\shell32.dll",
"GDI32.dll",
"ADVAPI32.dll",
"SETUPAPI.dll",
"COMCTL32.DLL"
],
"file_opened": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin",
"C:\\Windows\\win.ini",
"C:\\Windows\\shdd",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Policies",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Control Panel\\Desktop",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
"HKEY_LOCAL_MACHINE\\Software",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
"HKEY_CLASSES_ROOT\\CLSID\\{00BB2763-6A77-11D0-A535-00C04FD7D062}\\InProcServer32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Policies",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CLASSES_ROOT\\CLSID\\{03C036F1-A186-11D0-824A-00AA005B4383}\\InProcServer32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete\\Client\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\WinRAR SFX",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoComplete"
],
"command_line": [
"\"C:\\Windows\\shdd\\ins.bat\" ",
"C:\\Windows\\shdd\\ins.bat"
],
"file_written": [
"C:\\Windows\\shdd\\hddsvc.exe",
"C:\\Windows\\shdd\\hddsmart.bat",
"C:\\Windows\\shdd\\ins.bat",
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Windows\\shdd\\instsrv.exe"
],
"file_deleted": [
"C:\\Windows\\shdd\\__tmp_rar_sfx_access_check_14496812"
],
"file_exists": [
"C:\\Windows\\shdd\\hddsvc.exe",
"C:\\Windows\\shdd\\hddsmart.bat",
"C:\\Windows\\shdd\\ins.bat",
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Windows\\shdd\\instsrv.exe"
],
"guid": [
"{eac04bc0-3791-11d2-bb95-0060977b464c}",
"{5e078e03-8265-4bbe-9487-d242edbef910}",
"{00bb2763-6a77-11d0-a535-00c04fd7d062}",
"{00000000-0000-0000-c000-000000000046}",
"{807c1e6c-1d00-453f-b920-b61bb7cdd997}",
"{03c036f1-a186-11d0-824a-00aa005b4383}",
"{00bb2765-6a77-11d0-a535-00c04fd7d062}"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin",
"C:\\Windows\\win.ini"
],
"regkey_read": [
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\AutoComplete\\Always Use Tab",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewAlphaSelect",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{00BB2763-6A77-11D0-A535-00C04FD7D062}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInset",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInterval",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollDelay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{03C036F1-A186-11D0-824A-00AA005B4383}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragMinDist",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\AutoComplete\\AutoSuggest",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\SmoothScroll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewShadow",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AccListViewV6",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\AutoComplete\\Client\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\UseDoubleClickTimer",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\EnableBalloonTips",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey"
],
"directory_enumerated": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e.bin"
],
"regkey_written": [
"HKEY_CURRENT_USER\\Software\\WinRAR SFX\\C%%Windows%shdd"
]
},
"first_seen": 1563267191.625,
"ppid": 1268
},
{
"process_path": "C:\\Windows\\SysWOW64\\sc.exe",
"process_name": "sc.exe",
"pid": 2344,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\sc.exe.mui"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language\\InstallLanguageFallback",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\PreferredUILanguages",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\UILanguages\\en-US\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\UILanguages\\en-US\\AlternateCodePage",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\MuiCached\\MachinePreferredUILanguages",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\EMPTY"
]
},
"first_seen": 1563267198.4212,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\cmd.exe",
"process_name": "cmd.exe",
"pid": 1516,
"summary": {
"file_recreated": [
"\\??\\nul"
],
"directory_created": [
"C:\\Windows\\shdd"
],
"dll_loaded": [
"ADVAPI32.dll",
"kernel32.dll"
],
"file_opened": [
"C:\\Windows\\shdd\\ins.bat",
"C:\\",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\System",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Command Processor"
],
"file_moved": [
[
"C:\\Windows\\shdd\\instsrv.exe",
"C:\\Windows\\instsrv.exe"
],
[
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Windows\\hddsmart.exe"
]
],
"file_deleted": [
"C:\\Windows\\shdd\\ins.bat"
],
"file_exists": [
"C:\\Windows\\shdd\\instsrv.exe",
"C:\\Windows\\shdd\\\"C:\\Windows\\shdd\\ins.bat\"",
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Windows\\shdd\\ser.reg",
"C:\\Windows\\shdd",
"C:\\Windows\\instsrv.exe",
"C:\\Windows\\hddsmart.exe",
"C:\\Windows\\shdd\\ins.bat"
],
"file_failed": [
"C:\\Windows\\shdd\\ins.bat"
],
"command_line": [
"attrib +h +s C:\\Windows\\shdd\\hddsmart.bat",
"Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"DisplayName\" \/t REG_SZ \/d \"Smart HDD\" \/f",
"sc start HddSmart",
"sc config HddSmart DisplayName= \"Smart HDD\"",
"ping 127.0.0.1 -n 1",
"ping 127.0.0.1 -n 2",
"reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ImagePath\" \/t REG_EXPAND_SZ \/d \"C:\\Windows\\shdd\\hddsvc.exe\" \/f",
"Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\\Parameters\" \/v \"Application\" \/t REG_SZ \/d \"C:\\Windows\\shdd\\hddsmart.bat\" \/f",
"Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ObjectName\" \/t REG_SZ \/d \"LocalSystem\" \/f",
"Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Description\" \/t REG_SZ \/d \"Service for determining the performance of hard disks and defragmenting the file system. SMARTHDD allows you to change the characteristics of hard and solid-state drives, changing the speed of the positioning of magnetic heads (AAM) and fine-tuning the level of energy-saving drives (APM). The system of dynamic read-write load allows to increase by 50-60.\" \/f",
"reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Type\" \/t REG_DWORD \/d \"16\" \/f",
"reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Start\" \/t REG_DWORD \/d \"2\" \/f",
"C:\\Windows\\instsrv.exe HddSmart C:\\Windows\\shdd\\hddsvc.exe",
"reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ErrorControl\" \/t REG_DWORD \/d \"1\" \/f",
"taskkill \/f \/im hddsmart.exe"
],
"file_read": [
"C:\\Windows\\shdd\\ins.bat"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\AutoRun",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DisableUNCCheck",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\LogFileName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DelayedExpansion",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\CompletionChar",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DefaultColor",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DelayedExpansion",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\EnableExtensions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\DefaultLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\PathCompletionChar",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\CompletionChar",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\EnableExtensions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\SaferFlags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\PolicyScope",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Srp\\GP\\RuleCount",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\PathCompletionChar",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\safer\\codeidentifiers\\Levels",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor\\DisableUNCCheck",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\DefaultColor",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\AutoRun"
],
"directory_enumerated": [
"C:\\Python27\\attrib",
"C:\\Windows\\System32\\attrib.COM",
"C:\\Python27\\Scripts\\attrib",
"C:\\Windows\\shdd\\taskkill.*",
"C:\\Python27\\taskkill.*",
"C:\\Windows\\shdd\\attrib.*",
"C:\\Python27\\Reg",
"C:\\Windows\\System32\\attrib.*",
"C:\\Python27\\reg.*",
"C:\\Windows\\shdd\\ser.reg",
"C:\\Python27\\Scripts\\reg.*",
"C:\\Windows\\shdd",
"C:\\Windows\\shdd\\ping",
"C:\\Python27\\Scripts\\attrib.*",
"C:\\Windows\\shdd\\attrib",
"C:\\Python27\\Scripts\\taskkill.*",
"C:\\Python27\\sc",
"C:\\Windows\\System32\\reg.*",
"C:\\Windows\\shdd\\taskkill",
"C:\\Windows\\System32\\PING.COM",
"C:\\Windows\\shdd\\hddsmart.exe",
"C:\\Python27\\Reg.*",
"C:\\Python27\\Scripts\\Reg",
"C:\\Python27\\Scripts\\sc.*",
"C:\\Windows\\shdd\\ping.*",
"C:\\Python27\\sc.*",
"C:\\Python27\\attrib.*",
"C:\\Windows\\System32\\PING.EXE",
"C:\\Windows\\System32\\Reg.*",
"C:\\Windows\\System32\\reg.COM",
"C:\\Windows\\System32\\taskkill.*",
"C:\\Windows\\System32\\sc.COM",
"C:\\Python27\\Scripts\\taskkill",
"C:\\Windows\\shdd\\Reg.*",
"C:\\Python27\\Scripts\\reg",
"C:\\Windows\\shdd\\Reg",
"C:\\Windows\\System32\\taskkill.exe",
"C:\\Windows\\shdd\\sc.*",
"C:\\Python27\\Scripts\\ping.*",
"C:\\Windows\\System32\\sc.*",
"C:\\Python27\\ping.*",
"C:\\Python27\\Scripts\\sc",
"C:\\Windows\\System32\\sc.exe",
"C:\\Windows\\shdd\\instsrv.exe",
"C:\\Python27\\ping",
"C:\\Windows\\System32\\attrib.exe",
"C:\\Python27\\Scripts\\ping",
"C:\\Windows\\shdd\\reg.*",
"C:\\Python27\\reg",
"C:\\Windows\\System32\\taskkill.COM",
"C:\\Windows\\shdd\\sc",
"C:\\Windows\\shdd\\reg",
"C:\\Python27\\Scripts\\Reg.*",
"C:\\Windows",
"C:\\Windows\\instsrv.exe",
"C:\\Python27\\taskkill",
"C:\\Windows\\System32\\ping.*",
"C:\\Windows\\shdd\\ins.bat",
"C:\\Windows\\System32\\reg.exe"
]
},
"first_seen": 1563267191.9688,
"ppid": 2420
},
{
"process_path": "C:\\Windows\\SysWOW64\\reg.exe",
"process_name": "reg.exe",
"pid": 2260,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\DisplayName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
],
"dll_loaded": [
"kernel32.dll"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\DisplayName"
]
},
"first_seen": 1563267195.4994,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\PING.EXE",
"process_name": "PING.EXE",
"pid": 2820,
"summary": {
"file_recreated": [
"\\??\\Nsi"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip6\\Parameters\\Winsock",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Winsock",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Parameters",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Setup Migration\\Providers"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\DefaultTTL",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID"
],
"dll_loaded": [
"rpcrt4.dll",
"C:\\Windows\\System32\\wshtcpip.dll",
"C:\\Windows\\system32\\mswsock.dll"
],
"resolves_host": [
"127.0.0.1"
]
},
"first_seen": 1563267196.7025,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\sc.exe",
"process_name": "sc.exe",
"pid": 2360,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\sc.exe.mui"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language\\InstallLanguageFallback",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\PreferredUILanguages",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\UILanguages\\en-US\\Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\UILanguages\\en-US\\AlternateCodePage",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\MuiCached\\MachinePreferredUILanguages",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\EMPTY"
]
},
"first_seen": 1563267197.9525,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\PING.EXE",
"process_name": "PING.EXE",
"pid": 2964,
"summary": {
"file_recreated": [
"\\??\\Nsi"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip6\\Parameters\\Winsock",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Winsock",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Parameters",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Setup Migration\\Providers"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\DefaultTTL",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID"
],
"dll_loaded": [
"rpcrt4.dll",
"C:\\Windows\\System32\\wshtcpip.dll",
"C:\\Windows\\system32\\mswsock.dll"
],
"resolves_host": [
"127.0.0.1"
]
},
"first_seen": 1563267192.4688,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\taskkill.exe",
"process_name": "taskkill.exe",
"pid": 2492,
"summary": {
"dll_loaded": [
"C:\\Windows\\system32\\Winsta.dll"
],
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32",
"HKEY_CURRENT_USER\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}",
"HKEY_CURRENT_USER\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\WBEM\\CIMOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32"
],
"wmi_query": [
"SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = \"hddsmart.exe\")"
],
"guid": [
"{4590f812-1d3a-11d0-891f-00aa004b2e24}",
"{00000003-0000-0000-c000-000000000046}",
"{4590f811-1d3a-11d0-891f-00aa004b2e24}",
"{44aca674-e8fc-11d0-a07c-00c04fb68820}",
"{674b6698-ee92-11d0-ad71-00c04fd8fdff}",
"{8bc3f05e-d86b-11d0-a075-00c04fb68820}",
"{7c857801-7381-11cf-884d-00aa004b2e24}",
"{d5f569d0-593b-101a-b569-08002b2dbf7a}",
"{f309ad18-d86a-11d0-a075-00c04fb68820}",
"{dc12a687-737f-11cf-884d-00aa004b2e24}"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\CIMOM\\EnableObjectValidation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\CIMOM\\Logging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32\\(Default)"
]
},
"first_seen": 1563267192.1562,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\reg.exe",
"process_name": "reg.exe",
"pid": 2204,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart\\Parameters"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Parameters\\Application",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
],
"dll_loaded": [
"kernel32.dll"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Parameters\\Application"
]
},
"first_seen": 1563267196.5306,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\SysWOW64\\reg.exe",
"process_name": "reg.exe",
"pid": 2280,
"summary": {
"file_opened": [
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\HddSmart"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Description",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
],
"dll_loaded": [
"kernel32.dll"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Description"
]
},
"first_seen": 1563267195.1556,
"ppid": 1516
}
][
{
"markcount": 1,
"families": [],
"description": "Queries for the computername",
"severity": 1,
"marks": [
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetComputerNameW",
"return_value": 1,
"arguments": {
"computer_name": "CUCKPC"
},
"time": 1563267192.3122,
"tid": 2272,
"flags": {}
},
"pid": 2492,
"type": "call",
"cid": 68
}
],
"references": [],
"name": "antivm_queries_computername"
},
{
"markcount": 135,
"families": [],
"description": "Command line console output was observed",
"severity": 1,
"marks": [
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 169
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "md",
"console_handle": "0x00000007"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 171
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " C:\\Windows\\shdd ",
"console_handle": "0x00000007"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 173
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "A subdirectory or file C:\\Windows\\shdd already exists.\r\n",
"console_handle": "0x0000000b"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 181
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 199
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "cd",
"console_handle": "0x00000007"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 201
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " \/D C:\\Windows\\shdd ",
"console_handle": "0x00000007"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 203
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 230
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "taskkill",
"console_handle": "0x00000007"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 232
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " \/f \/im hddsmart.exe ",
"console_handle": "0x00000007"
},
"time": 1563267192.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 234
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267192.3588,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 295
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "move",
"console_handle": "0x00000007"
},
"time": 1563267192.3588,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 297
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " \/Y hddsmart.exe C:\\Windows\\hddsmart.exe ",
"console_handle": "0x00000007"
},
"time": 1563267192.3588,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 299
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " 1 file(s) moved.\r\n",
"console_handle": "0x00000007"
},
"time": 1563267192.3747,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 326
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267192.3747,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 343
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "move",
"console_handle": "0x00000007"
},
"time": 1563267192.3747,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 345
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " \/Y instsrv.exe C:\\Windows\\instsrv.exe ",
"console_handle": "0x00000007"
},
"time": 1563267192.3747,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 347
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " 1 file(s) moved.\r\n",
"console_handle": "0x00000007"
},
"time": 1563267192.3747,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 374
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267192.3747,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 390
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "ping",
"console_handle": "0x00000007"
},
"time": 1563267192.3747,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 392
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " 127.0.0.1 -n 2 ",
"console_handle": "0x00000007"
},
"time": 1563267192.3747,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 394
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267193.5938,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 463
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\instsrv.exe",
"console_handle": "0x00000007"
},
"time": 1563267193.5938,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 465
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " HddSmart C:\\Windows\\shdd\\hddsvc.exe ",
"console_handle": "0x00000007"
},
"time": 1563267193.5938,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 467
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267193.8438,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 499
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "ping",
"console_handle": "0x00000007"
},
"time": 1563267193.8438,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 501
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " 127.0.0.1 -n 2 ",
"console_handle": "0x00000007"
},
"time": 1563267193.8438,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 503
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267195.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 558
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "Reg",
"console_handle": "0x00000007"
},
"time": 1563267195.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 560
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Description\" \/t REG_SZ \/d \"Service for determining the performance of hard disks and defragmenting the file system. SMARTHDD allows you to change the characteristics of hard and solid-state drives, changing the speed of the positioning of magnetic heads (AAM) and fine-tuning the level of energy-saving drives (APM). The system of dynamic read-write load allows to increase by 50-60.\" \/f ",
"console_handle": "0x00000007"
},
"time": 1563267195.0468,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 562
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267195.2188,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 620
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "ping",
"console_handle": "0x00000007"
},
"time": 1563267195.2188,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 622
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " 127.0.0.1 -n 1 ",
"console_handle": "0x00000007"
},
"time": 1563267195.2338,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 624
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267195.4058,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 693
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "Reg",
"console_handle": "0x00000007"
},
"time": 1563267195.4058,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 695
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"DisplayName\" \/t REG_SZ \/d \"Smart HDD\" \/f ",
"console_handle": "0x00000007"
},
"time": 1563267195.4058,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 697
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267195.5938,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 763
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "Reg",
"console_handle": "0x00000007"
},
"time": 1563267195.5938,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 765
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ObjectName\" \/t REG_SZ \/d \"LocalSystem\" \/f ",
"console_handle": "0x00000007"
},
"time": 1563267195.5938,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 767
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267195.7497,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 831
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "reg",
"console_handle": "0x00000007"
},
"time": 1563267195.7497,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 833
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Start\" \/t REG_DWORD \/d \"2\" \/f ",
"console_handle": "0x00000007"
},
"time": 1563267195.7497,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 835
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267195.9218,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 904
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "reg",
"console_handle": "0x00000007"
},
"time": 1563267195.9218,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 906
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Type\" \/t REG_DWORD \/d \"16\" \/f ",
"console_handle": "0x00000007"
},
"time": 1563267195.9218,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 908
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267196.1247,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 976
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "reg",
"console_handle": "0x00000007"
},
"time": 1563267196.1247,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 978
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": " add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ErrorControl\" \/t REG_DWORD \/d \"1\" \/f ",
"console_handle": "0x00000007"
},
"time": 1563267196.1247,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 980
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "C:\\Windows\\shdd>",
"console_handle": "0x00000007"
},
"time": 1563267196.2808,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 1047
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "reg",
"console_handle": "0x00000007"
},
"time": 1563267196.2808,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 1049
}
],
"references": [],
"name": "console_output"
},
{
"markcount": 1,
"families": [],
"description": "Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available",
"severity": 1,
"marks": [
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "GlobalMemoryStatusEx",
"return_value": 1,
"arguments": {},
"time": 1563267192.5777,
"tid": 264,
"flags": {}
},
"pid": 2964,
"type": "call",
"cid": 22
}
],
"references": [],
"name": "antivm_memory_available"
},
{
"markcount": 1,
"families": [],
"description": "Creates a service",
"severity": 2,
"marks": [
{
"call": {
"category": "services",
"status": 1,
"stacktrace": [],
"api": "CreateServiceA",
"return_value": 4657856,
"arguments": {
"service_start_name": "",
"start_type": 2,
"service_handle": "0x004712c0",
"display_name": "HddSmart",
"error_control": 1,
"service_name": "HddSmart",
"filepath": "C:\\Windows\\shdd\\hddsvc.exe",
"filepath_r": "C:\\Windows\\shdd\\hddsvc.exe",
"service_manager_handle": "0x00471360",
"desired_access": 983551,
"service_type": 16,
"password": ""
},
"time": 1563267193.8432,
"tid": 1348,
"flags": {}
},
"pid": 2876,
"type": "call",
"cid": 10
}
],
"references": [],
"name": "creates_service"
},
{
"markcount": 1,
"families": [],
"description": "Drops a binary and executes it",
"severity": 2,
"marks": [
{
"category": "file",
"ioc": "C:\\Windows\\shdd\\ins.bat",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "dropper"
},
{
"markcount": 1,
"families": [],
"description": "Executes one or more WMI queries",
"severity": 2,
"marks": [
{
"category": "wmi",
"ioc": "SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = \"hddsmart.exe\")",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "has_wmi"
},
{
"markcount": 2,
"families": [],
"description": "The binary likely contains encrypted or compressed data indicative of a packer",
"severity": 2,
"marks": [
{
"entropy": 7.8850628386276,
"section": {
"size_of_data": "0x0000b600",
"virtual_address": "0x0001c000",
"entropy": 7.8850628386276,
"name": "UPX1",
"virtual_size": "0x0000c000"
},
"type": "generic",
"description": "A section with a high entropy has been found"
},
{
"entropy": 0.82727272727273,
"type": "generic",
"description": "Overall entropy of this PE file is high"
}
],
"references": [
"http:\/\/www.forensickb.com\/2013\/03\/file-entropy-explained.html",
"http:\/\/virii.es\/U\/Using%20Entropy%20Analysis%20to%20Find%20Encrypted%20and%20Packed%20Malware.pdf"
],
"name": "packer_entropy"
},
{
"markcount": 1,
"families": [],
"description": "Checks for the Locally Unique Identifier on the system for a suspicious privilege",
"severity": 2,
"marks": [
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1563267192.3122,
"tid": 2272,
"flags": {}
},
"pid": 2492,
"type": "call",
"cid": 49
}
],
"references": [],
"name": "privilege_luid_check"
},
{
"markcount": 2,
"families": [],
"description": "The executable is compressed using UPX",
"severity": 2,
"marks": [
{
"section": "UPX0",
"type": "generic",
"description": "Section name indicates UPX"
},
{
"section": "UPX1",
"type": "generic",
"description": "Section name indicates UPX"
}
],
"references": [],
"name": "packer_upx"
},
{
"markcount": 14,
"families": [],
"description": "Uses Windows utilities for basic Windows functionality",
"severity": 2,
"marks": [
{
"category": "cmdline",
"ioc": "attrib +h +s C:\\Windows\\shdd\\hddsmart.bat",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"DisplayName\" \/t REG_SZ \/d \"Smart HDD\" \/f",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "sc start HddSmart",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "sc config HddSmart DisplayName= \"Smart HDD\"",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "ping 127.0.0.1 -n 1",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "ping 127.0.0.1 -n 2",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ImagePath\" \/t REG_EXPAND_SZ \/d \"C:\\Windows\\shdd\\hddsvc.exe\" \/f",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\\Parameters\" \/v \"Application\" \/t REG_SZ \/d \"C:\\Windows\\shdd\\hddsmart.bat\" \/f",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ObjectName\" \/t REG_SZ \/d \"LocalSystem\" \/f",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Description\" \/t REG_SZ \/d \"Service for determining the performance of hard disks and defragmenting the file system. SMARTHDD allows you to change the characteristics of hard and solid-state drives, changing the speed of the positioning of magnetic heads (AAM) and fine-tuning the level of energy-saving drives (APM). The system of dynamic read-write load allows to increase by 50-60.\" \/f",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Type\" \/t REG_DWORD \/d \"16\" \/f",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"Start\" \/t REG_DWORD \/d \"2\" \/f",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\HddSmart\" \/v \"ErrorControl\" \/t REG_DWORD \/d \"1\" \/f",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "taskkill \/f \/im hddsmart.exe",
"type": "ioc",
"description": null
}
],
"references": [
"http:\/\/blog.jpcert.or.jp\/2016\/01\/windows-commands-abused-by-attackers.html"
],
"name": "uses_windows_utilities"
},
{
"markcount": 2,
"families": [],
"description": "Installs itself for autorun at Windows startup",
"severity": 3,
"marks": [
{
"service_name": "HddSmart",
"type": "generic",
"service_path": "C:\\Windows\\shdd\\hddsvc.exe"
},
{
"type": "generic",
"reg_key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\ImagePath",
"reg_value": "C:\\Windows\\shdd\\hddsvc.exe"
}
],
"references": [],
"name": "persistence_autorun"
},
{
"markcount": 1,
"families": [],
"description": "Deletes executed files from disk",
"severity": 3,
"marks": [
{
"category": "file",
"ioc": "C:\\Windows\\shdd\\ins.bat",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "deletes_executed_files"
},
{
"markcount": 1,
"families": [],
"description": "Stops Windows services",
"severity": 4,
"marks": [
{
"category": "service",
"ioc": "HddSmart (regkey HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HddSmart\\Start)",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "stops_service"
}
]The Yara rules did not detect anything in the file.
{
"tls": [],
"udp": [
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 546,
"time": 3.0792582035065,
"dport": 137,
"sport": 137
},
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 5226,
"time": 9.095379114151,
"dport": 138,
"sport": 138
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7070,
"time": 3.0390729904175,
"dport": 5355,
"sport": 51001
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7398,
"time": 1.0096640586853,
"dport": 5355,
"sport": 53595
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7726,
"time": 3.0729990005493,
"dport": 5355,
"sport": 53848
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8054,
"time": 1.518482208252,
"dport": 5355,
"sport": 54255
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8382,
"time": -0.095294952392578,
"dport": 5355,
"sport": 55314
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 8710,
"time": 1.5312650203705,
"dport": 1900,
"sport": 1900
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 28120,
"time": 1.0452520847321,
"dport": 3702,
"sport": 49152
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 36504,
"time": 3.124922990799,
"dport": 1900,
"sport": 53598
}
],
"dns_servers": [],
"http": [],
"icmp": [],
"smtp": [],
"tcp": [],
"smtp_ex": [],
"mitm": [],
"hosts": [],
"pcap_sha256": "5a238f210f924de8d600e31ebfe007a7254212d6cee46780f7e9cebbe30f148a",
"dns": [],
"http_ex": [],
"domains": [],
"dead_hosts": [],
"sorted_pcap_sha256": "5f04c4759b4ae931a0504026cbd95dd79dabc8bc7bf62378073f9e80c7ac0d31",
"irc": [],
"https_ex": []
}





The instructions below shows how to remove restr.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the restr.exe file for removal, restart your computer and scan it again to verify that restr.exe has been successfully removed. Here are the removal instructions in more detail:
| Property | Value |
|---|---|
| MD5 | d845a3510a9d1273b314ad992480cf65 |
| SHA256 | 6138f7c80219d495a657080cfc7d0683043292e7545f58752849407f9c23ef6e |
These are some of the error messages that can appear related to restr.exe:
restr.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
restr.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.
restr.exe has stopped working.
End Program - restr.exe. This program is not responding.
restr.exe is not a valid Win32 application.
restr.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.
To help other users, please let us know what you will do with restr.exe:
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.