HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Health\{5FB73819-35BD-4EA6-9B3C-BC85AA7D9023}
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASAPI32
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASAPI32\\EnableFileTracing
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASAPI32\\EnableAutoFileTracing
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASAPI32\\EnableConsoleTracing
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASAPI32\\FileTracingMask
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASAPI32\\ConsoleTracingMask
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASAPI32\\MaxFileSize
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASAPI32\\FileDirectory
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASMANCS
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASMANCS\\EnableFileTracing
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASMANCS\\EnableAutoFileTracing
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASMANCS\\EnableConsoleTracing
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASMANCS\\FileTracingMask
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASMANCS\\ConsoleTracingMask
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASMANCS\\MaxFileSize
new registry key parameter created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GeorgeFN_RASMANCS\\FileDirectory
new registry key parameter created
%ALLUSERSPROFILE%\music.mp3
new file created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\\{C120DE80-FDE4-49F5-A713-E902EF062B8A} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\LastScreensaverSetThreadExecutionState
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\LastScreensaverState
new registry key parameter created
%SYSTEMROOT%\apppatch\Custom\Custom64\drive.exe
new file created
%ALLUSERSPROFILE%\Microsoft\Media Player
new catalogue created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\MediaLibraryCreateNewDatabase
new registry key parameter created
%LOCALAPPDATA%\Microsoft\Media Player\CurrentDatabase_400.wmdb
new file created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\AutoMetadataCurrentDownloadCount
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\AutoMetadataCurrent500ServerErrorCount
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\AutoMetadataCurrent503ServerErrorCount
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\AutoMetadataCurrentOtherServerErrorCount
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\AutoMetadataCurrentNetworkErrorCount
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\AutoMetadataLastResetTime
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\SyncPlaylistsAdded
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\MLSChangeIndexMusic
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\MLSChangeIndexVideo
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\MLSChangeIndexPhoto
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\MLSChangeIndexList
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\MLSChangeIndexOther
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\MostRecentFileAddOrRemove
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\HME
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\HME\\LocalLibraryID
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Preferences\\LibraryHasBeenRun
new registry key parameter created
%USERPROFILE%\Downloads\smap.exe
new file created
%USERPROFILE%\Downloads\test.dll
new file created
%USERPROFILE%\Downloads\smap.bat
new file created
%LOCALAPPDATA%\Microsoft\CLR_v4.0_32\UsageLogs\GeorgeFN.exe.log
new file created
%LOCALAPPDATA%\Microsoft\Media Player\LocalMLS_3.wmdb
new file created
%LOCALAPPDATA%\Microsoft\Windows\INetCache
new catalogue created
%LOCALAPPDATA%\Microsoft\Windows\INetCache\IE
new catalogue created
%LOCALAPPDATA%\Microsoft\Windows\INetCache\Content.IE5
new catalogue created
%LOCALAPPDATA%\Microsoft\Windows\INetCookies
new catalogue created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\MediaPlayer\Health\{0535A57B-A276-4D07-B700-6C951D6FDE75}
new registry key created
%ALLUSERSPROFILE%\tracer.exe
new file created
%ALLUSERSPROFILE%\hive.exe
new file created
%ALLUSERSPROFILE%\george.exe
new file created
%ALLUSERSPROFILE%\spoofer.bat
new file created