%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend.log
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store
new catalogue created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user
new catalogue created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\defs_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\user_var_0.cfg.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\channels
new catalogue created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\rapport_var_0.cfg.data
new file created
HKEY_USERS\%ID-USER-SID%\Software\Trusteer\Rapport\renv
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Trusteer\Rapport\renv\\localappd
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Trusteer\Rapport\renv\\appd
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Trusteer\Rapport\renv\\commonappd
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Trusteer\Rapport\renv\\limited
new registry key parameter created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\rapport_var_1.cfg.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\safe_stores
new catalogue created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\safe_stores\local_store.lock
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\safe_stores\local_store
new catalogue created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\safe_stores\local_store\store_var_0.metadata.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\CerberusBridge.log
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\sysinfo.log
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\events_history.log
new file created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Edge
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Edge\Extensions
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Edge\Extensions\kajikgogckeajjplomldcempamhidmcc
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Edge\Extensions\kajikgogckeajjplomldcempamhidmcc\\update_url
new registry key parameter created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\gp-in-backend.log
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\fsm_service_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\fsm_service_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\bho-plugins_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\ap-protected_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\ap-whitelisted_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\phishing_data_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\ap-hashes_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\rapport_data_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\rapport_data_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\sysinfo.1.log
file renamed
%LOCALAPPDATA%\Trusteer\Rapport\user\logs
new catalogue created
HKEY_USERS\%ID-USER-SID%\Software\Google\Chrome\Extensions\bbjllphbppobebmjpjcijfbakobcheof
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Google\Chrome\Extensions\bbjllphbppobebmjpjcijfbakobcheof\\update_url
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Wow6432Node\Google
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Wow6432Node\Google\Chrome
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Wow6432Node\Google\Chrome\Extensions
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Wow6432Node\Google\Chrome\Extensions\bbjllphbppobebmjpjcijfbakobcheof
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Wow6432Node\Google\Chrome\Extensions\bbjllphbppobebmjpjcijfbakobcheof\\update_url
new registry key parameter created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend_mfsm_trace.log
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\events_data_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\events_data_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\events_counters_data_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\events_hash_data_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\events_stats_var_0.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\tmp
new catalogue created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend.1.log
file renamed
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\sysinfo.2.log
file renamed
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend-cmd.11096.log
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\tmp\agentevents.status_report.20210211-130355-5C23AA0AE992C3DF8450A715DA8B54888C78B000BCA21AB2122765EFE299A0B2-2441664710.zip
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\tmp\agenteventsfiles.status_report.20210211-130355-5C23AA0AE992C3DF8450A715DA8B54888C78B000BCA21AB2122765EFE299A0B2-2441664710.zip
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\sysinfo.3.log
file renamed
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\sysinfo.4.log
file renamed
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\sysinfo.5.log
file renamed
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend.2.log
file renamed
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend.3.log
file renamed
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend-cmd.16080.log
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\tmp\agentevents.status_report.20210213-170414-21537858C4FA86391A21152AB43C277C0779B7EE970FDC36B8333EFF1D997869-3841820753.zip
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\tmp\agenteventsfiles.status_report.20210213-170414-21537858C4FA86391A21152AB43C277C0779B7EE970FDC36B8333EFF1D997869-3841820753.zip
new file created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\9a\417C44EB\\@%SystemRoot%\system32\dnsapi.dll,-103
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\9a\417C44EB\\@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124
new registry key parameter created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\ap-protected_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\ap-whitelisted_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\phishing_data_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\ap-hashes_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\events_counters_data_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\events_hash_data_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\user\events_stats_var_1.js.data
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\tmp\agentevents.new_user_identifier.20210213-170840-21537858C4FA86391A21152AB43C277C0779B7EE970FDC36B8333EFF1D997869-4077763365.zip
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\tmp\agenteventsfiles.new_user_identifier.20210213-170840-21537858C4FA86391A21152AB43C277C0779B7EE970FDC36B8333EFF1D997869-4077763365.zip
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend-cmd.14344.log
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend-cmd.12032.log
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\CerberusBridge.1.log
file renamed
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node
new registry key created
(x32)HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft
new registry key created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\tmp\agentevents.status_report.20210128-003829-D4DC1B5FA92D7146A44899FBE4DC04C712D690CD8A3A33217E3B67A4E0EA47EB-2478294505.zip
new file created
%LOCALAPPDATA%\Trusteer\Rapport\user\store\tmp\agenteventsfiles.status_report.20210128-003829-D4DC1B5FA92D7146A44899FBE4DC04C712D690CD8A3A33217E3B67A4E0EA47EB-2478294505.zip
new file created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\8d\655C8779\\@%SystemRoot%\system32\dnsapi.dll,-103
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\8d\655C8779\\@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemApps%5CMicrosoft.MicrosoftEdge_8wekyb3d8bbwe%5Cresources.pri\1d6b910c35f3154
new registry key created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemApps%5CMicrosoft.MicrosoftEdge_8wekyb3d8bbwe%5Cresources.pri\1d6b910c35f3154\65d7db91
new registry key created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemApps%5CMicrosoft.MicrosoftEdge_8wekyb3d8bbwe%5Cresources.pri\1d6b910c35f3154\65d7db91\\@{Microsoft.MicrosoftEdge_44.18362.449.0_neutral__8wekyb3d8bbwe?ms-resource://Microsoft.MicrosoftEdge/Resources/AppName}
new registry key parameter created
%LOCALAPPDATA%\Trusteer\Rapport\user\logs\backend_mfsm_trace.1.log
file renamed