Test.Interesting
Table of Contents
Analysis Report
General information
| Family Name: | Test.Interesting |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
8710dbccb8291585dbc9163761d5be49
SHA1:
78d89fff52b3bddc78fe03615e57e047f8cd3e43
SHA256:
B609C31958238C19A13D138B91A2683EB1E4D5F3C4EA9563F697BE832E451B25
File Size:
1.21 MB, 1206272 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File is .NET application
- File is 32-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version | 1.0.0.0 |
| File Description | PoC_AbortHydration_ArbitraryRegKey_EoP |
| File Version | 1.0.0.0 |
| Internal Name | Mini_Runner.exe |
| Legal Copyright | Copyright © 2020 |
| Original Filename | Mini_Runner.exe |
| Product Name | PoC_AbortHydration_ArbitraryRegKey_EoP |
| Product Version | 1.0.0.0 |
File Traits
- .NET
- Agile.net
- Fody
- HighEntropy
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 25 |
|---|---|
| Potentially Malicious Blocks: | 5 |
| Whitelisted Blocks: | 12 |
| Unknown Blocks: | 8 |
Visual Map
x
x
?
x
0
x
?
?
?
x
?
?
?
?
0
0
0
0
0
0
0
0
0
0
0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block
? - Unknown Block
x - Potentially Malicious Block
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\programdata\mp_1b9fbebf.cfg | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps::symboliclinkvalue | \Registry\User\.DEFAULT\Volatile Environment | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
Show More
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKU\.DEFAULT\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::enabled | RegNtPreCreateKey | |
| HKCU\software\policies\microsoft\cloudfiles\blockedapps\83bcf1b1dc99187a2a17c263bd2f45d54b81c11485c29cf3e3f1e6aeba9a9d7::imagepath | \Device\HarddiskVolume2\Users\user\Downloads\78d89fff52b3bddc78fe03615e57e047f8cd3e43_0001206272 | RegNtPreCreateKey |
385 additional registry modifications are not displayed above.
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| User Data Access |
|