- Filename: sophostester x.exe
- Threat name: SONAR.Cryptlck!g141Full Path: Not Available
- ____________________________
- ____________________________
- On computers as of
- 9/9/2023 at 9:12:51 PM
- Last Used
- 9/9/2023 at 9:12:51 PM
- Startup Item
- No
- Launched
- Yes
- Behavioral Protection monitors for suspicious program activity on your computer.
- ____________________________
- sophostester x.exeThreat name: SONAR.Cryptlck!g141
- Locate
- Very Few Users
- Fewer than 5 users in the Norton Community have used this file.
- Very New
- This file was released less than 1 week ago.
- High
- This file risk is high.
- ____________________________
- Source: External Media
- Source File:
- sophostester x.exe
- ____________________________
- File Actions
- File: c:\Users\User\Desktop\sophostester x.exeRestart Required
- File: c:\program files (x86)\Sophos\sophos tester\sophostester.exeThreat Removed
- File: c:\Users\User\AppData\Local\Temp\sophostester-install.logThreat Removed
- File: c:\programdata\microsoft\Windows\start menu\Programs\sophos tester\sophos tester.lnkThreat Removed
- Directory: c:\program files (x86)\SophosRestart Required
- Directory: c:\program files (x86)\Sophos\sophos testerRestart Required
- Directory: c:\programdata\microsoft\windows\start menu\programs\sophos testerThreat Removed
- ____________________________
- Registry Actions
- Registry change: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tester, Registry Hive: 64 bitThreat Removed
- Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sophos Tester, Registry Hive: 64 bitThreat Removed
- ____________________________
- System Settings Actions
- Event: Process start (Performed by c:\users\user\desktop\sophostester x.exe, PID:1876)No action taken
- (Performed by c:\users\user\desktop\sophostester x.exe, PID:1876)No action taken
- Event: Process start: c:\Users\User\Desktop\sophostester x.exe, PID:1732 (Performed by c:\users\user\desktop\sophostester x.exe, PID:1876)No action taken
- Event: Process start (Performed by c:\users\user\desktop\sophostester x.exe, PID:1732)No action taken
- Event: Process start: c:\Users\User\Desktop\sophostester x.exe, PID:1876 (Performed by c:\users\user\desktop\sophostester x.exe, PID:1876)No action taken
- Event: PE file creation: c:\program files (x86)\sophos\sophos tester\sophostester.exe (Performed by c:\users\user\desktop\sophostester x.exe, PID:1732)No action taken
- Event: PE file creation: c:\program files (x86)\Sophos\sophos tester\helper.exe (Performed by c:\users\user\desktop\sophostester x.exe, PID:1732)No action taken
- (Performed by c:\users\user\desktop\sophostester x.exe, PID:1732)No action taken
- Event: Process start: c:\Users\User\Desktop\sophostester x.exe, PID:1732 (Performed by c:\users\user\desktop\sophostester x.exe, PID:1732)No action taken
- Event: Process start (Performed by c:\users\user\desktop\sophostester x.exe, PID:5920)No action taken
- (Performed by c:\users\user\desktop\sophostester x.exe, PID:5920)No action taken
- Event: Process start: c:\Users\User\Desktop\sophostester x.exe, PID:4640 (Performed by c:\users\user\desktop\sophostester x.exe, PID:5920)No action taken
- Event: Process start (Performed by c:\users\user\desktop\sophostester x.exe, PID:4640)No action taken
- Event: Process start: c:\Users\User\Desktop\sophostester x.exe, PID:5920 (Performed by c:\users\user\desktop\sophostester x.exe, PID:5920)No action taken
- Event: PE file creation: c:\program files (x86)\sophos\sophos tester\sophostester.exe (Performed by c:\users\user\desktop\sophostester x.exe, PID:4640)No action taken
- Event: PE file creation: c:\program files (x86)\Sophos\sophos tester\helper.exe (Performed by c:\users\user\desktop\sophostester x.exe, PID:4640)No action taken
- Event: PE file creation: c:\Windows\SysWOW64\tester86.dll (Performed by c:\users\user\desktop\sophostester x.exe, PID:4640)No action taken
- Event: PE file creation: c:\Windows\System32\tester64.dll (Performed by c:\users\user\desktop\sophostester x.exe, PID:4640)No action taken
- Event: PE file creation: c:\Windows\System32\drivers\tester64.sys (Performed by c:\users\user\desktop\sophostester x.exe, PID:4640)No action taken
- (Performed by c:\users\user\desktop\sophostester x.exe, PID:4640)No action taken
- ____________________________
- Suspicious Actions
- (Performed by c:\users\user\desktop\sophostester x.exe, PID:1732)No action taken
- (Performed by c:\users\user\desktop\sophostester x.exe, PID:4640)No action taken
- ____________________________
- File Thumbprint - SHA:
- Not available
- File Thumbprint - MD5:
- Not available
复制代码 |