e192995a...64da | VTI
Try VMRay Analyzer
VTI SCORE: 100/100
Target: win10_64 | exe
Classification: Wiper, Ransomware

e192995a42b91bd86aa0c5fe5d4e4aaff1b921bdb10946b1ea67565b5d3164da (SHA256)

scvhost.exe

Windows Exe (x86-32)

Created at 2018-04-15 00:07:00

Severity Category Operation Classification
5/5
File System Encrypts content of user files Ransomware
  • Encrypts the content of multiple user files. This is an indicator for ransomware.
4/5
OS Modifies Windows automatic backups -
3/5
Process Creates an unusally large number of processes -
2/5
File System Associated with suspicious files -
  • File "c:\users\ciihmnxmn6ps\desktop\scvhost.exe" is a known suspicious file.
1/5
Persistence Installs system startup script or application -
  • Adds "C:\Users\CIiHmnxMn6Ps\Desktop\scvhost.exe supermetroidrules" to Windows startup via registry.
1/5
Process Creates process with hidden window -
  • The process "C:\Windows\system32\cmd.exe" starts with hidden window.
1/5
Anti Analysis Resolves APIs dynamically to possibly evade static detection -
1/5
File System Modifies application directory -
  • Modifies "c:\program files\common files\designer\msaddndr.olb.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\c2rheartbeatconfig.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\clientcapabilities.json.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\i640.hash.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\i641033.hash.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\officeupdateschedule.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\servicewatcherschedule.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\alphabet.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\content.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\flickanimation.avi.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\hwrcommonlm.dat.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\hwrenclm.dat.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\hwrlatinlm.dat.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\hwrusalm.dat.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\hwrusash.dat.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsar.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipscat.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipschs.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipscht.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipscsy.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsdan.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsdeu.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsel.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsen.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsesp.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsfin.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsfra.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipshe.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipshi.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipshrv.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsid.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsita.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsjpn.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipskor.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsnld.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsnor.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsplk.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsptb.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsptg.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsrom.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipsrus.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipssrb.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipssrl.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipssve.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ipstr.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ar-sa\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\bg-bg\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\cs-cz\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\da-dk\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\de-de\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\el-gr\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-gb\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\boxed-correct.avi.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\boxed-delete.avi.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\boxed-join.avi.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\boxed-split.avi.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\correct.avi.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\delete.avi.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\flicklearningwizard.exe.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\inkobj.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\inputpersonalization.exe.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\ipseventlogmsg.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\ipsmigrationplugin.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\join.avi.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\micaut.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\mip.exe.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\mshwlatin.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\rtscom.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\shapecollector.exe.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\split.avi.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\tabskb.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\tabtip.exe.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\tipres.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\tiptsf.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\es-es\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\es-mx\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\et-ee\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fi-fi\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fr-ca\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fr-fr\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\auxpad.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\insert.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\keypad.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\oskclearui.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\oskmenu.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\osknav.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\osknumpad.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\oskpred.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\symbols.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\auxpad\auxbase.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\insert\insertbase.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\keypad\ea.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\basealtgr_rtl.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_altgr.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_ca.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_heb.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_jpn.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_kor.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_rtl.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\ja-jp.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\ko-kr.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\zh-changjei.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\zh-dayi.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\zh-phonetic.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\oskclearui\oskclearuibase.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\oskmenu\oskmenubase.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\osknav\osknavbase.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\osknumpad\osknumpadbase.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\oskpred\oskpredbase.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\symbols\ea-sym.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\symbols\ja-jp-sym.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\symbols\symbase.xml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\he-il\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\hr-hr\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\hu-hu\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\it-it\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ja-jp\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ko-kr\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\languagemodel\chstic.dgml.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\lt-lt\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\lv-lv\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\nb-no\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\nl-nl\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\pl-pl\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\pt-br\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\pt-pt\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ro-ro\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\ru-ru\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\sk-sk\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\sl-si\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\sr-latn-cs\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\sr-latn-rs\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\sv-se\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\th-th\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\tr-tr\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\uk-ua\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\zh-cn\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\zh-hk\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\ink\zh-tw\tipresx.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\msinfo\en-us\msinfo32.exe.mui.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\office16\office setup controller\pkeyconfig-office.xrm-ms.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\bears.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\bears.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\blue_gradient.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\cave_drawings.gif.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\connectivity.gif.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\dotted_lines.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\garden.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\garden.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\genko_1.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\genko_2.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\graph.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\green bubbles.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\greenbubbles.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\grid_(cm).wmf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\grid_(inch).wmf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\hand prints.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\handprints.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\memo.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\monet.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\month_calendar.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\music.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\notebook.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\orange circles.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\orangecircles.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\peacock.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\peacock.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\pine_lumber.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\pretty_peacock.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\psychedelic.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\roses.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\roses.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\sand_paper.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\seyes.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\shades of blue.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\shadesofblue.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\shorthand.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\small_news.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\soft blue.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\softblue.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\stars.htm.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\stars.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\stucco.gif.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\tanspecks.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\tiki.gif.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\to_do_list.emf.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\white_chocolate.jpg.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\stationery\wrinkled_paper.gif.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\vsto\vstoee100.tlb.nmcrypt".
  • Modifies "c:\program files\common files\microsoft shared\vsto\vstoee90.tlb.nmcrypt".
  • Modifies "c:\program files\common files\services\verisign.bmp.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\adojavas.inc.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\adovbs.inc.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msado20.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msado21.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msado25.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msado26.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msado27.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msado28.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msado60.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msadomd28.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msador28.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\msadox28.tlb.nmcrypt".
  • Modifies "c:\program files\common files\system\ado\en-us\msader15.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\en-us\wab32res.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\msadc\adcjavas.inc.nmcrypt".
  • Modifies "c:\program files\common files\system\msadc\adcvbs.inc.nmcrypt".
  • Modifies "c:\program files\common files\system\msadc\en-us\msadcer.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\msadc\en-us\msadcor.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\msadc\en-us\msaddsr.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\msadc\en-us\msdaprsr.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\msadc\en-us\msdaremr.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\ole db\oledbjvs.inc.nmcrypt".
  • Modifies "c:\program files\common files\system\ole db\oledbvbs.inc.nmcrypt".
  • Modifies "c:\program files\common files\system\ole db\sqloledb.rll.nmcrypt".
  • Modifies "c:\program files\common files\system\ole db\sqlxmlx.rll.nmcrypt".
  • Modifies "c:\program files\common files\system\ole db\en-us\msdasqlr.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\ole db\en-us\oledb32r.dll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\ole db\en-us\sqloledb.rll.mui.nmcrypt".
  • Modifies "c:\program files\common files\system\ole db\en-us\sqlxmlx.rll.mui.nmcrypt".
  • Modifies "c:\program files\microsoft office\appxmanifest.xml.nmcrypt".
  • Modifies "c:\program files\microsoft office\filesystemmetadata.xml.nmcrypt".
  • Modifies "c:\program files\microsoft office\office16\ospp.htm.nmcrypt".
  • Modifies "c:\program files\microsoft office\office16\ospp.vbs.nmcrypt".
  • Modifies "c:\program files\microsoft office\office16\slerror.xml.nmcrypt".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0015-0000-1000-0000000ff1ce.xml.nmcrypt".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hm00172_.wmf.nmcrypt".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hm00426_.wmf.nmcrypt".
1/5
File System Modifies operating system directory -
  • Creates file "C:\Windows\System32\spp\store\2.0\data.dat" in the OS directory.
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image