%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\Data\Definitions\SMRDefs\20161121.023\LivePatch.exe
%PROGRAMFILES(X86)%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\Bin\setiCollect.exe
%PROGRAMFILES(X86)%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\SAEP\IDS\bin\IDSLWInit.exe
%PROGRAMFILES(X86)%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Bin64\installTeefer.exe
%PROGRAMFILES(X86)%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Bin\elaminst.exe
%PROGRAMFILES(X86)%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Bin\EFAInst.exe
%PROGRAMFILES(X86)%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Bin64\Sevntx64.exe
%SYSTEMROOT%\System32\FwsVpn.dll
new file created
%SYSTEMROOT%\System32\SymVPN.dll
new file created
%SYSTEMROOT%\System32\snacnp.dll
new file created
%SYSTEMROOT%\SysWOW64\snacnp.dll
new file created
%SYSTEMROOT%\SysWOW64\FwsVpn.dll
new file created
%SYSTEMROOT%\SysWOW64\SymVPN.dll
new file created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\VolatileServiceBoot\\Default
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\VolatileInstallData
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\\LowBandwidth
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink\\hash
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\IntelligentUpdater
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\IntelligentUpdater\LocalDLLs
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\IntelligentUpdater\LocalDLLs\\SAVIUAuth
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\IntelligentUpdater\LocalDLLs\\SAVIUDeploy
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs\DefWatch
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs\DefWatch\Handlers
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs\DefWatch\Handlers\\dwLdPntScan.dll
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs\DefWatch\Handlers\\nnewdefs.dll
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedDefs\DefWatch\\DefVersion
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedUsage
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedUsage\\Location1
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Preferences
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Preferences\\All Transports Available
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SymNetDrv
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SymNetDrv\\Version
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SymNetDrv\Parameters
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SymNetDrv\Parameters\\SettingsPath
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\InstalledApps\\SRTSP
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\InstalledApps\\Savrt
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SRTSP
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SRTSP\\Version
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion
new registry key created
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion\\SymbolicLinkValue
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion\\SymbolicLinkValue
new registry key parameter created
%SYSTEMROOT%\SysWOW64\sysfer.dll
new file created
%SYSTEMROOT%\System32\sysfer.dll
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\TransactedTemp\Folder1\file12
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\NonTransactedTemp\file25.log
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\NonTransactedTemp\file78.bak
file renamed
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\Data\Definitions\NTRDefs\tmp48dc.tmp\v.sig
file moved
%PROGRAMFILES(X86)%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\Bin\LUReg\{EDBD3BD0-BEEF-4d4d-BAC9-19DD32EF4758}.dat.bak
file renamed
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\{B4E42322-D805-4E00-A4DA-69143336117F}\Common Client\ccIPC\Endpoints
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans\Default FullScan Options
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans\VirusSweep\\Exts
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\\HoldOnClose
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\{B4E42322-D805-4E00-A4DA-69143336117F}\OBJID\{B14923CC-CCBF-4f81-92E1-C01327FA42ED}\\Inproc64
new registry key parameter created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\EDR\edrSettings.dat
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\NonTransactedTemp\file63.bak
file renamed
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\Definitions\SMRDefs\tmp2c3e.tmp
new catalogue created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\\VersionNT
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\{B4E42322-D805-4E00-A4DA-69143336117F}\Submissions\CAT\\Status
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\Content\{022B4952-5022-4181-AB2D-332582C72E43}\\LastUpdateTime
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans\A46A1E8B-B30F-11E9-B854-7130C94F5037\Schedule\\MissedEventEnabled
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\HeuristicScanning\FileHash\Admin\3:1ab0d0e579e4c637610cad8dd74564d7\\ThreatName
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\HeuristicScanning\FileHash\Admin\2:745fc9584315a6d823d6a057c4a6dd894d18eef00a27ec011d2bb7c4d96c4071\\Owner
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\HeuristicScanning\FileHash\Admin\3:ca7c2449f2806fa42d63f66e70919131\\FileSize
new registry key parameter created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\Lue\Downloads\Patch96\STICc.dis
file moved
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\Lue\Downloads\Patch8121\virscan1.dat
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\DB\av.db
new file created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans\A46A1E8B-B30F-11E9-B854-7130C94F5037\Schedule\\ScanWindowStart
new registry key parameter created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\IRON\120FDA5911EB7135B04024990582F434.dat
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\IRON\120FDB4A11EB7135B04024990582F434.dat
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\IRON\120FDC9E11EB7135B04024990582F434.dat
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\IRON\120FDDB211EB7135B04024990582F434.dat
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\IRON\120FDEC511EB7135B04024990582F434.dat
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\IRON\120FDFD811EB7135B04024990582F434.dat
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\IRON\sdmys_526D4B6B58F54D3B82243051
file renamed
%SystemDrive%\Config.Msi\cf9cd2.rbf
new file created
%SystemDrive%\Config.Msi\cf9d26.rbf
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\CmnClnt\ccGLog\LM_{0AF2CEED-7803-4243-B545-5CB2E43CAD12}.tmp
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\CmnClnt\ccGLog\LM_{7C24F1AB-1D64-4ddc-AA70-2D734CA886A2}.tmp
new file created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\{B4E42322-D805-4E00-A4DA-69143336117F}\Submissions\MrClean\\Status
new registry key parameter created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\Definitions\SDSDefs\20210217.007\hf_1.flt
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\CmnClnt\ccGLog\LM_{C898657E-61FC-4cdd-83ED-2AF0DA43680E}.tmp
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\Data\PchEpmpCStorage.dat
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\NonTransactedTemp\file78.log
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\Data\Definitions\NTRDefs\tmp48dc.tmp\virscan1.dat
file moved
%PROGRAMFILES(X86)%\Symantec\Symantec Endpoint Protection\14.2.3332.1000.105\Bin\LUReg\{0F3370CC-CB7C-4976-9315-22E436B26137}.dat._bak
new file created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\{B4E42322-D805-4E00-A4DA-69143336117F}\Common Client\ccIPC\Endpoints\\{6247714F-7E79-43D4-B0DE-153557F9F2EC}
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans\Default FullScan Options\\ExcludedByExtensions
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans\VirusSweep\\ScanProcesses
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\Filesystem\RealTimeScan\\ScanNotifyTerminateProcess
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\{B4E42322-D805-4E00-A4DA-69143336117F}\OBJID\{a91c8c44-02b9-4b02-97b6-6196893c6f2b}
new registry key created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\NonTransactedTemp\file11
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\NonTransactedTemp\file63.log
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\Definitions\SMRDefs\tmp2c3e.tmp\catalog.dat
file moved
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\CurrentVersion
new catalogue created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\{B4E42322-D805-4E00-A4DA-69143336117F}\Common Client\ccIPC\Channels\\SEP_RepMgtTIM_SERVER_{78279C7F-A932-4512-9193-9284C9709AE0}
new registry key parameter created
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\Content\{02335EF8-ADE1-4DD8-9F0F-2A9662352E65}
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans\A46A1E8B-B30F-11E9-B854-7130C94F5037\Schedule\\TimeWindowDaily
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\HeuristicScanning\FileHash\Admin\3:1ab0d0e579e4c637610cad8dd74564d7\\FileHash
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\HeuristicScanning\FileHash\Admin\2:745fc9584315a6d823d6a057c4a6dd894d18eef00a27ec011d2bb7c4d96c4071\\ProtectionTechnology
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Exclusions\HeuristicScanning\FileHash\Admin\3:ca7c2449f2806fa42d63f66e70919131\\HashAlgorithm
new registry key parameter created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\Lue\Downloads\Patch4699
new catalogue created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\Lue\Downloads\Patch8121\v.grd
new file created
%ALLUSERSPROFILE%\Symantec\Symantec Endpoint Protection\14.2.4559.1100.105\Data\DB\av.db-journal
new file created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\LocalScans\A46A1E8B-B30F-11E9-B854-7130C94F5037\Schedule\\ScanWindowDayOfWeek
new registry key parameter created