Professional Documents
Culture Documents
Threat Analysis Report: Hash Values File Details Environment
Threat Analysis Report: Hash Values File Details Environment
SHA-256 Hash
7D72F078EE28B94396B051CEC47E57B665A205C09D8772E8FD631CC9ABB7DE64
Identifier
Screenshots 17
File Type F
Microsoft Windows 7 Professional Service Pack 1 (build 7601, version 6.1.7601), 64-bit
Hide environment
Behavior Classification
Behavior Severity
⬤ 1-
Offile file contains VBA code
Informational
⬤ 1-
office file Spawns printer spooler
Informational
⬤ 1-
Offile file contains VBA code
Informational
⬤ 1-
Changed the protection attribute of the process
Informational
Security Solution / Mechanism bypass, termination and removal, Anti Debugging, VM Detection ⬤ 1 - Informational
⬤ 1-
Offile file contains VBA code
Informational
⬤ 1-
Disabled attach/detach notifications from dynamic link library
Informational
⬤ 1-
Contained long sleep
Informational
Spreading ⬤ 1 - Informational
⬤ 1-
Offile file contains VBA code
Informational
⬤ 1-
Offile file contains VBA code
Informational
Networking ⬤ 1 - Informational
⬤ 1-
Offile file contains VBA code
Informational
⬤ 1-
Offile file contains VBA code
Informational
⬤ 1-
Contained long sleep
Informational
Processes Analyzed
Timeline Activity
SPIDER.doc
s plwow64.exe
00:00:000 Others Initialized a critical section object and set the spin count for the critical section
00:00:000 Others Initialized a critical section object and set the spin count for the critical section
File Operations,
00:00:000 Retrieved the full path for the module
miscellaneous
File Operations,
00:00:000 Obtained the path of the Windows system directory
miscellaneous
Process Operations, Retrieved information on a specific string in the current activation context
00:00:000
miscellaneous
Process Operations, Obtained the contents of the specified variable from the environment block of the
00:00:000
miscellaneous calling process
Process Operations, Changed the protection attribute of process address: 0x2fc21634, new attribute:
00:00:000
miscellaneous Execute_ReadWrite
Process Operations, Changed the protection attribute of process address: 0x2fc21634, new attribute:
00:00:016
miscellaneous Execute_Read
C:\Windows\Microsoft.NET\Framework\\v2.0.50727\clr.dll
20000
00:00:156 Files Opened
10000000
C:\Windows\Microsoft.NET\Framework\\v1.1.4322\mscorwks.dll
20000
00:00:156 Files Opened
10000000
C:\Windows\Microsoft.NET\Framework\\v1.1.4322\clr.dll
20000
00:00:156 Files Opened
10000000
C:\Windows\Microsoft.NET\Framework\\v1.0.3705\mscorwks.dll
20000
00:00:156 Files Opened
10000000
C:\Windows\Microsoft.NET\Framework\\v1.0.3705\clr.dll
20000
00:00:156 Files Opened
10000000
File Operations,
00:00:156 Obtained a set of FAT file system attributes for a file or directory
miscellaneous
HKLM\Software\Microsoft\.NETFramework
00:00:156 Registry Read
InstallRoot
File Operations,
00:00:156 Searched a directory for the name: C:\Windows\Microsoft.NET\Framework\\*
miscellaneous
HKLM\SOFTWARE\Microsoft\Fusion
00:00:172 Registry Read
NoClientChecks
C:\Windows\Microsoft.NET\Framework\\v4.0.30319\clr.dll
20000
00:00:172 Files Opened
10000000
C:\Windows\Microsoft.NET\Framework\\v2.0.50727\mscorwks.dll
20000
00:00:172 Files Opened
20000
00:00:172 Files Opened
10000000
HKLM\Software\Microsoft\.NETFramework
00:00:172 Registry Read
UseLegacyV2RuntimeActivationPolicyDefaultValue
HKLM\Software\Microsoft\.NETFramework
00:00:172 Registry Read
OnlyUseLatestCLR
c:\windows\splwow64.exe
00:00:297 Process Created c:\windows\splwow64.exe 12288
File Operations,
00:00:328 Retrieved the full path for the module
miscellaneous
HKLM\System\CurrentControlSet\Control\Print
00:00:328 Registry Read
SplWOW64TimeOut
ff7f6cd8
00:00:328 Thread Created
Obtained the current system date and time in in Coordinated Universal Time (UTC)
00:00:328 Others
format
ff7fa838
00:00:328 Thread Created
Process Operations,
00:00:328 Enabled an application to supersede the top-level exception handler
miscellaneous
ff7faa2c
00:00:328 Thread Created
Process Operations,
00:00:328 Opened the access token associated with a process
miscellaneous
Process Operations,
00:00:328 Opened the access token associated with a thread
miscellaneous
Process Operations,
00:00:328 Retrieved the Remote Desktop Services session
miscellaneous
Process Operations, Set a waiting mode until a specified object is in the signaled state or the time-out
00:00:328
miscellaneous interval elapses
00:00:328 Others Initialized a critical section object and set the spin count for the critical section
{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}
00:00:391 Process Created
{FA445657-9379-11D6-B41A-00065B83EE53}
00:00:391 Process Created
C:\Users\Administrator\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Write
00:00:453 Files Created
Hidden
Process Operations,
00:00:453 Initialized COM library for the current thread and set it in the concurrency mode
miscellaneous
{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
00:00:469 Process Created
{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
00:00:688 Process Created
{0E5AAE11-A475-4C5B-AB00-C66DE400274E}
00:00:688 Process Created
{88D969EC-8B8B-4C3D-859E-AF6CD158BE0F}
00:00:719 Process Created
{88D969EF-F192-11D4-A65F-0040963251E5}
00:00:844 Process Created
C:\nogwfjxpzm\~$5c81fc-0946-4a78-bb24-0c37f7a297f6.doc
Write
00:01:031 Files Created
Hidden
{33C53A50-F456-4884-B049-85FD643ECFED}
00:01:312 Process Created
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\7b5c81fc-0946-
00:01:500 Files Deleted
4a78-bb24-0c37f7a297f6.LNK
File Operations,
00:02:016 Obtained the current directory for the current process
miscellaneous
Process Operations,
00:02:016 Obtained the identifier of the thread or process that created the specified window
miscellaneous
File Operations, Determined whether a disk drive C:\ is a removable, fixed, CD-ROM, RAM disk, or
00:02:030
miscellaneous network drive
HKCU\Software\Microsoft\VBA\6.0\Common
00:02:046 Registry Read
BackGroundCompile
HKCU\Software\Microsoft\VBA\6.0\Common
00:02:046 Registry Read
CompileOnDemand
HKCU\Software\Microsoft\VBA\6.0\Common
00:02:046 Registry Read
BreakOnServerErrors
HKCU\Software\Microsoft\VBA\6.0\Common
00:02:046 Registry Read
BreakOnAllErrors
HKCU\Software\Microsoft\VBA\6.0\Common
00:02:046 Registry Read
RequireDeclaration
HKCU\Software\Microsoft\VBA\6.0\Common
00:02:046 Registry Read
NotifyUserBeforeStateLoss
File Operations,
00:02:062 Searched a directory for the name: Normal
miscellaneous
File Operations,
00:03:391 Retrieved the path of the directory designated for temporary files
miscellaneous
Directories C:\Users\ADMINI~1\AppData\Local\Temp\VBE
00:03:405
Created/Opened
65001f64
00:04:063 Thread Created
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
EndProcLine
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
IndicatorBar
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
00:04:110 Registry Read
TabWidth
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
OBSearchHeight
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
SyntaxChecking
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
DragDropInEditor
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
AutoIndent
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
AutoQuickTips2
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
AutoStatement2
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:110 Registry Read
AutoValueTips2
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:125 Registry Read
CodeBackColors
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:125 Registry Read
OBGroupMembers
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:125 Registry Read
MdiMaximized
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:125 Registry Read
IndicatorColors
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:125 Registry Read
FontHeight
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:125 Registry Read
FontFace
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:125 Registry Read
FontCharSet
00:04:125 Others Retrieved an integer from a key in a section of the Win.ini file
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:125 Registry Read
CodeForeColors
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
UpgradeVBX
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
AlignToGrid
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
ShowToolTips
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
ShowGrid
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
ReadOnlyMode
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
BackgroundProjectLoad
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
CollapseWindows
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
FolderView
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
GridHeight
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:140 Registry Read
GridWidth
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:156 Registry Read
Tool
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:188 Registry Read
UI
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:188 Registry Read
PropertiesWindow
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:203 Registry Read
CtlsShowSelected
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:203 Registry Read
Dock
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:203 Registry Read
DsnShowSelected
HKCU\Software\Microsoft\VBA\6.0\Common
00:04:218 Registry Read
MainWindow
Obtained the current system date and time in in Coordinated Universal Time (UTC)
00:04:235 Others
format
HKLM\Software\Microsoft\Windows\Help
00:04:281 Registry Read
VbLR6.chm
HKLM\Software\Microsoft\Windows\HTML Help
00:04:281 Registry Read
VbLR6.chm
{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}
00:08:781 Process Created
Process Operations, Disabled the DLL_THREAD_ATTACH and DLL_THREAD_DETACH notifications for the
02:12:985
miscellaneous dynamic-link library
HKCU\Software\Microsoft\Shared Tools\Proofing
02:13:000 Registry Created
Tools\Grammar\MSGrammar\3.0\1033
HKCU\Software\Microsoft\Shared Tools\Proofing
02:13:000 Registry Read Tools\Grammar\MSGrammar\3.0\1033
Options Version
HKCU\Software\Microsoft\Shared Tools\Proofing
02:13:000 Registry Created
Tools\Grammar\MSGrammar\3.0\1033\Option Set 1
HKCU\Software\Microsoft\Shared Tools\Proofing
02:13:000 Registry Created
Tools\Grammar\MSGrammar\3.0\1033\Option Set 0
HKCU\Software\Microsoft\Shared Tools\Proofing
Tools\Grammar\MSGrammar\3.0\1033\Option Set 0\Data
02:13:000 Registry Modified
1010101
REG_BINARY
HKCU\Software\Microsoft\Shared Tools\Proofing
HKCU\Software\Microsoft\Shared Tools\Proofing
Tools\Grammar\MSGrammar\3.0\1033\Option Set 0\Name
02:13:000 Registry Modified
Grammar & Style
REG_SZ
HKCU\Software\Microsoft\Shared Tools\Proofing
Tools\Grammar\MSGrammar\3.0\1033\Option Set 1\Data
02:13:000 Registry Modified
1010101
REG_BINARY
HKCU\Software\Microsoft\Shared Tools\Proofing
Tools\Grammar\MSGrammar\3.0\1033\Option Set 1\Name
02:13:000 Registry Modified
Grammar Only
REG_SZ
HKCU\Software\Microsoft\Shared Tools\Proofing
Tools\Grammar\MSGrammar\3.0\1033\Options Version
02:13:000 Registry Modified
1
REG_DWORD
02:13:016 Memory Mapped Files Created a file that can be used for memory mapping
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet
02:14:375 Files Deleted
Files\Content.Word\~WRS{25162D27-F411-449E-9F1D-FF884C228A84}.tmp
HKCU\Software\Microsoft\VBA\6.0\Common\PropertiesWindow
02:14:500 Registry Modified 8 8 180 400 1
REG_SZ
HKCU\Software\Microsoft\VBA\6.0\Common\MainWindow
02:14:531 Registry Modified 0 0 800 560 1
REG_SZ
HKCU\Software\Microsoft\VBA\6.0\Common\MdiMaximized
02:14:531 Registry Modified 0
REG_SZ
HKCU\Software\Microsoft\VBA\6.0\Common\Dock
02:14:531 Registry Modified 14C0002
REG_BINARY
HKCU\Software\Microsoft\VBA\6.0\Common\CtlsShowSelected
02:14:546 Registry Modified 0
REG_SZ
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\VB12.pip
Write
02:14:546 Files Created
8100000
HKCU\Software\Microsoft\VBA\6.0\Common\UI
02:14:546 Registry Modified 68
REG_BINARY
HKCU\Software\Microsoft\VBA\6.0\Common\Tool
02:14:546 Registry Modified 0
REG_BINARY
HKCU\Software\Microsoft\VBA\6.0\Common\DsnShowSelected
02:14:546 Registry Modified 0
REG_SZ
Process Operations, Set a waiting mode until a specified object is in the signaled state or the time-out
02:14:563
miscellaneous interval elapses
miscellaneous interval elapses
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet
02:14:625 Files Deleted
Files\Content.Word\~WRS{428F46C1-A8AC-497B-A911-5A1CCFE1CF8B}.tmp
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Word12.pip
Write
02:14:625 Files Created
8100000
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet
02:14:828 Files Deleted
Files\Content.Word\~WRF{27735B2C-E422-491D-8985-3FE59DB6D384}.tmp
Engine Analysis
YARA
Custom Rules
Sandbox ⬤ 2 - Low
Embedded/Dropped content
* Attachments were extracted from the sample file and stored in the dropfiles.zip
Screenshots
Note: a pop-up window was detected during dynamic analysis so user interaction may be required in order to fully analyze this sample
Images: 17
2c78c.jpg
18c4d.jpg
25b35.jpg
2a2ce.jpg
2b77e.jpg
26fe6.jpg
f731.jpg
11623.jpg
29e0b.jpg
103b4.jpg
274a9.jpg
2cc3f.jpg
2b2cb.jpg
25fe9.jpg
e60a.jpg
2867c.jpg
28b2f.jpg
SPIDER.doc
Run-Time Dlls: 8
api-ms-win-appmodel-runtime-l1-1-0.dll
vbe6intl.dll
comctl32.dll
oleaut32.dll
shlwapi.dll
vbe6.dll
version.dll
wwlib.dll
File Operations: 36
Files Created
Files Opened
C:\Users\ADMINI~1\AppData\Local\Temp\55187.od
C:\Users\ADMINI~1\AppData\Local\Temp\CVRD793.tmp.cvr
C:\Users\Administrator\AppData\Local\Microsoft\Schemas\MS Word_restart.xml
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\7b5c81fc-0946-4a78-bb24-0c37f7a297f6.LNK
C:\Users\Administrator\AppData\Roaming\Microsoft\Office\Recent\nogwfjxpzm.LNK
C:\Users\Administrator\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
C:\nogwfjxpzm\~$5c81fc-0946-4a78-bb24-0c37f7a297f6.doc
Files Read
C:\Windows\Microsoft.NET\Framework\
C:\Windows\Microsoft.NET\Framework\v2.0.50727
Normal
Directories Created/Opened
C:\Users\ADMINI~1\AppData\Local\Temp\VBE
Other
Determined whether a disk drive C:\ is a removable, fixed, CD-ROM, RAM disk, or network drive
Registry Created
HKCU\Software\Microsoft\VBA\6.0\Common
Registry Opened
HKCR\Licenses
HKCR\TypeLib
HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}
HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0
HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0
HKCR\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
HKCR\TypeLib\{00020813-0000-0000-C000-000000000046}
HKCR\TypeLib\{00020905-0000-0000-C000-000000000046}
HKCR\TypeLib\{00020905-0000-0000-C000-000000000046}\8.4
HKCR\TypeLib\{00020905-0000-0000-C000-000000000046}\8.4\0
HKCR\TypeLib\{00020905-0000-0000-C000-000000000046}\8.4\0\win32
HKCR\TypeLib\{00020905-0000-0000-C000-000000000046}\8.4\409
HKCR\TypeLib\{00020905-0000-0000-C000-000000000046}\8.4\9
HKCR\TypeLib\{0D452EE1-E08F-101A-852E-02608C4D0BB4}
HKCR\TypeLib\{0D452EE1-E08F-101A-852E-02608C4D0BB4}\2.0
HKCR\TypeLib\{0D452EE1-E08F-101A-852E-02608C4D0BB4}\2.0\0
HKCR\TypeLib\{0D452EE1-E08F-101A-852E-02608C4D0BB4}\2.0\0\win32
HKCR\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}
HKCR\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.4
HKCR\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.4\0
HKCR\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.4\0\win32
HKCR\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}
HKCR\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\3.0
HKCR\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\3.0\0
HKCR\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\3.0\0\win32
HKCU\Software\Microsoft\.NETFramework
HKCU\Software\Microsoft\VBA\6.0\Common
HKCU\Software\Microsoft\VBA\6.0\Common\Designers
HKCU\Software\Microsoft\VBA\6.0\Common\ToolboxControls
HKCU\Software\Microsoft\VBA\VBE\6.0\Addins
HKLM\SOFTWARE\Microsoft\Fusion
HKLM\SOFTWARE\Microsoft\VBA\Monitors
HKLM\Software\Microsoft\.NETFramework
HKLM\Software\Microsoft\.NETFramework\Policy\Upgrades
HKLM\Software\Microsoft\Windows
HKLM\Software\Microsoft\Windows\HTML Help
HKLM\Software\Microsoft\Windows\Help
Registry Modified
Key NewValue Type
HKCU\Software\Microsoft\VBA\6.0\Common\CtlsShowSelected 0 REG_SZ
HKCU\Software\Microsoft\VBA\6.0\Common\DsnShowSelected 0 REG_SZ
HKCU\Software\Microsoft\VBA\6.0\Common\FolderView 1 REG_SZ
HKCU\Software\Microsoft\VBA\6.0\Common\MdiMaximized 0 REG_SZ
HKCU\Software\Microsoft\VBA\6.0\Common\Tool 0 REG_BINARY
HKCU\Software\Microsoft\VBA\6.0\Common\UI 68 REG_BINARY
Registry Read
HKCU\Software\Microsoft\Shared Tools\Proofing
Options Version
Tools\Grammar\MSGrammar\3.0\1033
HKCU\Software\Microsoft\VBA\6.0\Common AlignToGrid
HKCU\Software\Microsoft\VBA\6.0\Common AutoIndent
HKCU\Software\Microsoft\VBA\6.0\Common AutoQuickTips2
HKCU\Software\Microsoft\VBA\6.0\Common AutoStatement2
HKCU\Software\Microsoft\VBA\6.0\Common AutoValueTips2
HKCU\Software\Microsoft\VBA\6.0\Common BackGroundCompile
HKCU\Software\Microsoft\VBA\6.0\Common BackgroundProjectLoad
HKCU\Software\Microsoft\VBA\6.0\Common BreakOnAllErrors
HKCU\Software\Microsoft\VBA\6.0\Common BreakOnServerErrors
HKCU\Software\Microsoft\VBA\6.0\Common CodeBackColors
HKCU\Software\Microsoft\VBA\6.0\Common CodeForeColors
HKCU\Software\Microsoft\VBA\6.0\Common CollapseWindows
HKCU\Software\Microsoft\VBA\6.0\Common CompileOnDemand
HKCU\Software\Microsoft\VBA\6.0\Common CtlsShowSelected
HKCU\Software\Microsoft\VBA\6.0\Common Dock
HKCU\Software\Microsoft\VBA\6.0\Common DragDropInEditor
HKCU\Software\Microsoft\VBA\6.0\Common DsnShowSelected
HKCU\Software\Microsoft\VBA\6.0\Common EndProcLine
HKCU\Software\Microsoft\VBA\6.0\Common FolderView
HKCU\Software\Microsoft\VBA\6.0\Common FontCharSet
HKCU\Software\Microsoft\VBA\6.0\Common FontFace
HKCU\Software\Microsoft\VBA\6.0\Common FontHeight
HKCU\Software\Microsoft\VBA\6.0\Common FullModuleView
HKCU\Software\Microsoft\VBA\6.0\Common GridHeight
HKCU\Software\Microsoft\VBA\6.0\Common GridWidth
HKCU\Software\Microsoft\VBA\6.0\Common IndicatorBar
HKCU\Software\Microsoft\VBA\6.0\Common IndicatorColors
HKCU\Software\Microsoft\VBA\6.0\Common MainWindow
HKCU\Software\Microsoft\VBA\6.0\Common MdiMaximized
HKCU\Software\Microsoft\VBA\6.0\Common NotifyUserBeforeStateLoss
HKCU\Software\Microsoft\VBA\6.0\Common OBGroupMembers
HKCU\Software\Microsoft\VBA\6.0\Common OBSearchHeight
HKCU\Software\Microsoft\VBA\6.0\Common PropertiesWindow
HKCU\Software\Microsoft\VBA\6.0\Common ReadOnlyMode
HKCU\Software\Microsoft\VBA\6.0\Common RequireDeclaration
HKCU\Software\Microsoft\VBA\6.0\Common SaveBeforeRun
HKCU\Software\Microsoft\VBA\6.0\Common ShowGrid
HKCU\Software\Microsoft\VBA\6.0\Common ShowToolTips
HKCU\Software\Microsoft\VBA\6.0\Common SyntaxChecking
HKCU\Software\Microsoft\VBA\6.0\Common TabWidth
HKCU\Software\Microsoft\VBA\6.0\Common Tool
HKCU\Software\Microsoft\VBA\6.0\Common UI
HKCU\Software\Microsoft\VBA\6.0\Common UpgradeVBX
HKLM\SOFTWARE\Microsoft\Fusion NoClientChecks
HKLM\Software\Microsoft\.NETFramework InstallRoot
HKLM\Software\Microsoft\.NETFramework OnlyUseLatestCLR
HKLM\Software\Microsoft\.NETFramework UseLegacyV2RuntimeActivationPolicyDefaultValue
HKLM\Software\Microsoft\Windows\Help VbLR6.chm
Other
Process Operations: 21
Process Created
C:\NOGWFJXPZM\EXCEL.EXE
{0E5AAE11-A475-4C5B-AB00-C66DE400274E}
{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
{33C53A50-F456-4884-B049-85FD643ECFED}
{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}
{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}
{88D969EC-8B8B-4C3D-859E-AF6CD158BE0F}
{88D969EF-F192-11D4-A65F-0040963251E5}
{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
{FA445657-9379-11D6-B41A-00065B83EE53}
Thread Created
65001f64
Other
Changed the protection attribute of process address: 0x2fc21634, new attribute: Execute_Read
Changed the protection attribute of process address: 0x2fc21634, new attribute: Execute_ReadWrite
Disabled the DLL_THREAD_ATTACH and DLL_THREAD_DETACH notifications for the dynamic-link library
Initialized COM library for the current thread and set it in the concurrency mode
Obtained the contents of the specified variable from the environment block of the calling process
Obtained the identifier of the thread or process that created the specified window
Set a waiting mode until a specified object is in the signaled state or the time-out interval elapses
Other Operations: 7
Others
Initialized a critical section object and set the spin count for the critical section
Obtained the current system date and time in in Coordinated Universal Time (UTC) format