Загрузка данных


<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7864667</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7864790</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7864848</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7864979</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7865154</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7873279</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12236</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7874802</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7875006</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7875226</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7876135</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\Kirill\_netrc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7893495</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 27680, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7902021</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7902612</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7909026</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\Kirill\.netrc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7912068</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7912263</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7912319</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 12872, User Time: 0.0000000, Kernel Time: 0.0156250</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7912926</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7914286</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7916992</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7917296</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7919588</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 2160</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7921774</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7922073</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7922505</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7923827</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\Kirill\_netrc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7931632</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\Kirill\.netrc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7934743</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7934969</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7935756</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>Thread Create</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 16416</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7938215</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>Thread Exit</Operation>
<Path></Path>
<Result>SUCCESS</Result>
<Detail>Thread ID: 30196, User Time: 0.0000000, Kernel Time: 0.0000000</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7939742</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7939911</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7940072</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7940261</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\Kirill\_netrc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7940391</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegCloseKey</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail></Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7941641</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7941784</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7945271</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>CreateFile</Operation>
<Path>C:\Users\Kirill\.netrc</Path>
<Result>NAME NOT FOUND</Result>
<Detail>Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7948835</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>BUFFER OVERFLOW</Result>
<Detail>Length: 12</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7948856</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryKey</Operation>
<Path>HKCU</Path>
<Result>SUCCESS</Result>
<Detail>Query: HandleTags, HandleTags: 0x0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7949052</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegQueryValue</Operation>
<Path>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable</Path>
<Result>SUCCESS</Result>
<Detail>Type: REG_DWORD, Length: 4, Data: 0</Detail>
</event>

<event>
<ProcessIndex>452</ProcessIndex>
<Time_of_Day>15:31:50,7949059</Time_of_Day>
<Process_Name>winlocker_builder_0.6.exe</Process_Name>
<PID>24072</PID>
<Operation>RegOpenKey</Operation>
<Path>HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings</Path>
<Result>SUCCESS</Result>
<Detail>Desired Access: Read</Detail>
</event>
</eventlist></procmon>