Malware Log Analysis

shared / Advanced_Meaning8261
content copied

content

Start CreateRestorePoint: CloseProcesses: FirewallRules: [TCP Query User{78637EED-FFCE-4B78-B19F-D39A2DC8B0A7}C:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) C:\riot games\riot client\riotclientelectron\riot client.exe => No File FirewallRules: [UDP Query User{78D0B2A9-1531-40D3-897A-30B041A368CB}C:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) C:\riot games\riot client\riotclientelectron\riot client.exe => No File HKU\S-1-5-21-2664321715-2315589813-2789204376-1001\...\Run: [RiotClient] => C:\Riot Games\Riot Client\RiotClientServices.exe --launch-background-mode (No File) CHR HomePage: Default -> hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP91C63220-4B2A-46A4-8DF4-07D791E80AE6&SSPV= CHR StartupUrls: Default -> "hxxp://www.mystartsearch.com/?type=hppp&ts=1421181727&from=wpc&uid=HitachiXHDS721010CLA332_JP9960HZ241G0U241G0UX","hxxp://www.oursurfing.com/?type=hp&ts=1441093093&z=2b0ab6fad6a9513eccef361gcz9zdgfg9m0t1o6zbg&from=amt&uid=TOSHIBAXMQ01ABD075_24GTP6AJTXX24GTP6AJT","hxxp://www.mystartsearch.com/?type=hp&ts=1441093548&z=49dd01eb1bc15eb638d7673g2z2z1g1gfm6t4w6q0q&from=cmi&uid=TOSHIBAXMQ01ABD075_24GTP6AJTXX24GTP6AJT" EmptyTemp: End