Garku
Trainer
my Norton detected some suspicious activity preformed by the application, im only posting this so that in case some other people are having trouble with version .48 and they dont have Norton
Filename: pokemon.exe
Threat name: SONAR.Heuristic.120
Full Path: Not Available
____________________________
Details
Very Few Users, Very New, Risk High
Origin
Downloaded from Unknown
Activity
Actions performed: 101
____________________________
On computers as of 5/29/2014 at 11:17:22 PM
Last Used 5/29/2014 at 11:17:22 PM
Startup Item No
Launched Yes
____________________________
Very Few Users
Fewer than 5 users in the Norton Community have used this file.
Very New
This file was released less than 1 week ago.
High
This file risk is high.
SONAR Protection monitors for suspicious program activity on your computer.
____________________________
Source: External Media
Source File:
pokemon3d.exeFile Created:
pokemon.exe
____________________________
File Actions
File: c:\users\aaron\desktop\pokemon\gamemodes\kolben\gamemode.datRemoved
File: c:\users\aaron\desktop\pokemon\log.datRemoved
File: c:\users\aaron\desktop\pokemon\save\gamejoltacc.datRemoved
File: c:\users\aaron\desktop\pokemon\save\options.datRemoved
File: c:\users\aaron\desktop\pokemon\save\keyboard.datRemoved
File: c:\users\aaron\desktop\pokemon\save\server_list.datRemoved
File: c:\users\aaron\desktop\content\temp\635360066692630000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166273532000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166275332000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166291472000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166296032000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166281812000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166302232000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166361312000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366167429342000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366167580342000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366167824572000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168148272000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168171212000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168162172000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168386992000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168631952000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366169196582000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366169650242000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366170712142000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366173239402000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366173249312000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366173259172000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366175252412000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366177533632000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366177551702000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366177561172000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366273404094000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274425124000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274427414000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274425544000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274451204000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274444154000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274454414000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274471404000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274473164000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274494284000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274482864000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502909272000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502915812000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502926872000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502915482000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502934152000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502935702000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502946352000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558156952000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558169562000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558172322000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558166752000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558192232000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558201612000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558213102000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558234192000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558238632000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558239592000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558291162000.tmpRemoved
Event: Running process: c:\users\aaron\desktop\pokemon\pokemon.exeTerminated
Event: Running process: c:\users\aaron\desktop\pokemon\pokemon.exeRestart Required
Infected file: c:\users\aaron\desktop\pokemon\pokemon.exeRemoved
____________________________
Registry Actions
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Direct3D\MostRecentApplication->Name:mblctr.exeRepaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{332A5465-6192-4CAA-9D58-95746A324CDF}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{749ae53e-e0a4-11e1-8ca0-806e6f6e6963}->BaseClass
riveRepaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{749ae53b-e0a4-11e1-8ca0-806e6f6e6963}->BaseClass
riveRepaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{749ae53a-e0a4-11e1-8ca0-806e6f6e6963}->BaseClass
riveRepaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Preferences->MediaLibraryCreateNewDatabase:0Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Preferences\HME->LocalLibraryID:{6E8646EC-500A-448E-96C9-2A0310382667}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{332A5465-6192-4CAA-9D58-95746A324CDF}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{A801B3DB-8F00-4048-9A3A-0348828C13DE}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{A801B3DB-8F00-4048-9A3A-0348828C13DE}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{FF25FA87-5EA2-4EC5-8563-024BD0AA5BEE}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{FF25FA87-5EA2-4EC5-8563-024BD0AA5BEE}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{F1E3F5C3-EC84-4722-9B2B-EEFC5C659B4C}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Multimedia\ActiveMovie\Filter CacheNo Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Multimedia\ActiveMovie\Filter Cache->0No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{F1E3F5C3-EC84-4722-9B2B-EEFC5C659B4C}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{A2DB842D-F19C-4C84-A1DE-430705F9A3B4}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{A2DB842D-F19C-4C84-A1DE-430705F9A3B4}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{0C21A35A-CB51-4BCD-9137-FF507C819CEB}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{0C21A35A-CB51-4BCD-9137-FF507C819CEB}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{5B6ECC40-DF26-4D21-82E4-AAFF42845FC3}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{5B6ECC40-DF26-4D21-82E4-AAFF42845FC3}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{BE76F50F-7209-46A6-9A88-58F2CC4BC437}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{BE76F50F-7209-46A6-9A88-58F2CC4BC437}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{DF4AC005-A82C-42D2-ABEB-20F933DE8EB9}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{DF4AC005-A82C-42D2-ABEB-20F933DE8EB9}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{6BA0F759-99AF-4993-8B86-C9DCE9AF7297}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{6BA0F759-99AF-4993-8B86-C9DCE9AF7297}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{0CB6E20C-8F7D-4A03-BD5B-FB53F46C666E}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{0CB6E20C-8F7D-4A03-BD5B-FB53F46C666E}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{729EDBD3-16D5-47B4-B6F1-09747885D401}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{729EDBD3-16D5-47B4-B6F1-09747885D401}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{6D4A98D1-0A46-4644-A9E5-5B89FE354B5F}No Action Required
____________________________
System Settings Actions
Event: Process start (Performed by c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508)No action taken
Event: Process start: c:\Windows\explorer.exe, PID:5992 (Performed by c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508)No action taken
Event: Process start: c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508 (Performed by c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508)No action taken
____________________________
Suspicious Actions
Event: Keystroke capture (Performed by c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508)No action taken
____________________________
File Thumbprint - SHA:
1bbe02d081f768e77fe4a2b5335641a9eadebdf1a9f2b367c2dc865e5fe5f69f
File Thumbprint - MD5:
Not available
Filename: pokemon.exe
Threat name: SONAR.Heuristic.120
Full Path: Not Available
____________________________
Details
Very Few Users, Very New, Risk High
Origin
Downloaded from Unknown
Activity
Actions performed: 101
____________________________
On computers as of 5/29/2014 at 11:17:22 PM
Last Used 5/29/2014 at 11:17:22 PM
Startup Item No
Launched Yes
____________________________
Very Few Users
Fewer than 5 users in the Norton Community have used this file.
Very New
This file was released less than 1 week ago.
High
This file risk is high.
SONAR Protection monitors for suspicious program activity on your computer.
____________________________
Source: External Media
Source File:
pokemon3d.exeFile Created:
pokemon.exe
____________________________
File Actions
File: c:\users\aaron\desktop\pokemon\gamemodes\kolben\gamemode.datRemoved
File: c:\users\aaron\desktop\pokemon\log.datRemoved
File: c:\users\aaron\desktop\pokemon\save\gamejoltacc.datRemoved
File: c:\users\aaron\desktop\pokemon\save\options.datRemoved
File: c:\users\aaron\desktop\pokemon\save\keyboard.datRemoved
File: c:\users\aaron\desktop\pokemon\save\server_list.datRemoved
File: c:\users\aaron\desktop\content\temp\635360066692630000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166273532000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166275332000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166291472000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166296032000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166281812000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166302232000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366166361312000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366167429342000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366167580342000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366167824572000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168148272000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168171212000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168162172000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168386992000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366168631952000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366169196582000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366169650242000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366170712142000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366173239402000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366173249312000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366173259172000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366175252412000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366177533632000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366177551702000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366177561172000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366273404094000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274425124000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274427414000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274425544000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274451204000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274444154000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274454414000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274471404000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274473164000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274494284000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366274482864000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502909272000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502915812000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502926872000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502915482000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502934152000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502935702000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366502946352000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558156952000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558169562000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558172322000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558166752000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558192232000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558201612000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558213102000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558234192000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558238632000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558239592000.tmpRemoved
File: c:\users\aaron\desktop\content\temp\635366558291162000.tmpRemoved
Event: Running process: c:\users\aaron\desktop\pokemon\pokemon.exeTerminated
Event: Running process: c:\users\aaron\desktop\pokemon\pokemon.exeRestart Required
Infected file: c:\users\aaron\desktop\pokemon\pokemon.exeRemoved
____________________________
Registry Actions
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Direct3D\MostRecentApplication->Name:mblctr.exeRepaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{332A5465-6192-4CAA-9D58-95746A324CDF}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{749ae53e-e0a4-11e1-8ca0-806e6f6e6963}->BaseClass
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{749ae53b-e0a4-11e1-8ca0-806e6f6e6963}->BaseClass
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{749ae53a-e0a4-11e1-8ca0-806e6f6e6963}->BaseClass
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Preferences->MediaLibraryCreateNewDatabase:0Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Preferences\HME->LocalLibraryID:{6E8646EC-500A-448E-96C9-2A0310382667}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{332A5465-6192-4CAA-9D58-95746A324CDF}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{A801B3DB-8F00-4048-9A3A-0348828C13DE}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{A801B3DB-8F00-4048-9A3A-0348828C13DE}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{FF25FA87-5EA2-4EC5-8563-024BD0AA5BEE}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{FF25FA87-5EA2-4EC5-8563-024BD0AA5BEE}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{F1E3F5C3-EC84-4722-9B2B-EEFC5C659B4C}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Multimedia\ActiveMovie\Filter CacheNo Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\Multimedia\ActiveMovie\Filter Cache->0No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{F1E3F5C3-EC84-4722-9B2B-EEFC5C659B4C}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{A2DB842D-F19C-4C84-A1DE-430705F9A3B4}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{A2DB842D-F19C-4C84-A1DE-430705F9A3B4}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{0C21A35A-CB51-4BCD-9137-FF507C819CEB}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{0C21A35A-CB51-4BCD-9137-FF507C819CEB}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{5B6ECC40-DF26-4D21-82E4-AAFF42845FC3}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{5B6ECC40-DF26-4D21-82E4-AAFF42845FC3}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{BE76F50F-7209-46A6-9A88-58F2CC4BC437}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{BE76F50F-7209-46A6-9A88-58F2CC4BC437}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{DF4AC005-A82C-42D2-ABEB-20F933DE8EB9}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{DF4AC005-A82C-42D2-ABEB-20F933DE8EB9}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{6BA0F759-99AF-4993-8B86-C9DCE9AF7297}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{6BA0F759-99AF-4993-8B86-C9DCE9AF7297}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{0CB6E20C-8F7D-4A03-BD5B-FB53F46C666E}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{0CB6E20C-8F7D-4A03-BD5B-FB53F46C666E}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{729EDBD3-16D5-47B4-B6F1-09747885D401}No Action Required
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{729EDBD3-16D5-47B4-B6F1-09747885D401}Repaired
Registry change: HKEY_USERS\S-1-5-21-2348911198-634374161-2407797843-1000\Software\Microsoft\MediaPlayer\Health\{6D4A98D1-0A46-4644-A9E5-5B89FE354B5F}No Action Required
____________________________
System Settings Actions
Event: Process start (Performed by c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508)No action taken
Event: Process start: c:\Windows\explorer.exe, PID:5992 (Performed by c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508)No action taken
Event: Process start: c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508 (Performed by c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508)No action taken
____________________________
Suspicious Actions
Event: Keystroke capture (Performed by c:\users\aaron\desktop\pokemon\pokemon.exe, PID:5508)No action taken
____________________________
File Thumbprint - SHA:
1bbe02d081f768e77fe4a2b5335641a9eadebdf1a9f2b367c2dc865e5fe5f69f
File Thumbprint - MD5:
Not available