Backdoor.Padodor

Por GoldSparrow em Backdoors
Traduzir Para:

Cartão de pontuação de ameaças

Nível da Ameaça: 80 % (Alto)
Computadores infectados: 0
Visto pela Primeira Vez: July 24, 2009
SO (s) Afetados: Windows


O Backdoor.Padodor um é um Trojan de backdoor, que foi projetado para obter acesso não autorizado à máquina do usuário. Normalmente, O Backdoor.Padodor entra no seu sistema através da exploração da segurança do navegador ou de outros mecanismos ilícitos e antiéticos. Uma vez executado, o Backdoor.Padodor se esconde profundamente no sistema, e trabalha em segundo plano. O Backdoor.Padodor pode explorar as vulnerabilidades dos programas instalados ou do sistema operacional e permitir que um invasor remoto obtenha total controle sobre seu PC. O Backdoor.Padodor é uma séria ameaça para a segurança da sua máquina, portanto, recomendamos removê-lo o mais rapidamente possível.

SpyHunter detecta e remove Backdoor.Padodor

Detalhes Sobre os Arquivos do Sistema

Backdoor.Padodor pode criar o(s) seguinte(s) arquivo(s):
# Nome do arquivo MD5 Detecções
1. Jgcdgqbd.exe 27be0da404473def71c58a87ce1ff260 0

Relatório de análise

Informação geral

Family Name: Trojan.Padodor
Signature status: No Signature

Known Samples

MD5: 69f2150a3d86a4f7475e8d4a4609a7da
SHA1: 91df3793e9e8236a3f011af1edb02e744741cdae
SHA256: 0B5403A51A9F067DC658E7FF91EC0FD0897E845666FE69190B66ADF174F9143D
Tamanho do Arquivo: 89.60 KB, 89600 bytes
MD5: 0184bc3f6f6f7d1006297fca3feb7a00
SHA1: 04027407118581f383b9970b322caaca808c1b17
SHA256: 940F9E4A3EEFD8FB7F9FCA8745AFED3ED9136B12A773AB7A86E9DB1D34D7E13F
Tamanho do Arquivo: 91.65 KB, 91648 bytes
MD5: cb9d058b94ea512201023d4d8eb6d7ad
SHA1: 002ec1a42c620ea8f498782687671926eec162ee
SHA256: 18BB0C7F7B8C9A35F6BCF16D8F18B9319E67B111BAE32E044AF452E43B7F7B12
Tamanho do Arquivo: 80.90 KB, 80896 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • x86

Block Information

Similar Families

  • Qukart.A

Files Modified

File Attributes
c:\windows\syswow64\acmfppob.dll Generic Write,Read Attributes
c:\windows\syswow64\adfkaq32.dll Generic Write,Read Attributes
c:\windows\syswow64\adiejpgl.dll Generic Write,Read Attributes
c:\windows\syswow64\ajglgoif.dll Generic Write,Read Attributes
c:\windows\syswow64\akkame32.dll Generic Write,Read Attributes
c:\windows\syswow64\amaenlae.dll Generic Write,Read Attributes
c:\windows\syswow64\andjdd32.dll Generic Write,Read Attributes
c:\windows\syswow64\apipjplg.dll Generic Write,Read Attributes
c:\windows\syswow64\aqmepf32.dll Generic Write,Read Attributes
c:\windows\syswow64\banknc32.dll Generic Write,Read Attributes
Show More
c:\windows\syswow64\bcoilahd.dll Generic Write,Read Attributes
c:\windows\syswow64\bejbgiqf.dll Generic Write,Read Attributes
c:\windows\syswow64\biibpjmp.dll Generic Write,Read Attributes
c:\windows\syswow64\bkgpkqii.dll Generic Write,Read Attributes
c:\windows\syswow64\bmffeale.dll Generic Write,Read Attributes
c:\windows\syswow64\bmlikg32.dll Generic Write,Read Attributes
c:\windows\syswow64\cbnnmh32.dll Generic Write,Read Attributes
c:\windows\syswow64\cioncf32.dll Generic Write,Read Attributes
c:\windows\syswow64\cjnligob.dll Generic Write,Read Attributes
c:\windows\syswow64\ckamcqgc.dll Generic Write,Read Attributes
c:\windows\syswow64\ckgepfqn.dll Generic Write,Read Attributes
c:\windows\syswow64\cmaohmcd.dll Generic Write,Read Attributes
c:\windows\syswow64\cnhchkhj.dll Generic Write,Read Attributes
c:\windows\syswow64\cnllme32.dll Generic Write,Read Attributes
c:\windows\syswow64\ddffkkgo.dll Generic Write,Read Attributes
c:\windows\syswow64\ddofki32.dll Generic Write,Read Attributes
c:\windows\syswow64\dfiaoefc.dll Generic Write,Read Attributes
c:\windows\syswow64\dhcigg32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dhcigg32.exe Generic Write,Read Attributes
c:\windows\syswow64\dhjohfic.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dhjohfic.exe Generic Write,Read Attributes
c:\windows\syswow64\dhppmh32.dll Generic Write,Read Attributes
c:\windows\syswow64\dhqpebhq.dll Generic Write,Read Attributes
c:\windows\syswow64\dibgqp32.dll Generic Write,Read Attributes
c:\windows\syswow64\dijlbi32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dijlbi32.exe Generic Write,Read Attributes
c:\windows\syswow64\dkgpihcm.dll Generic Write,Read Attributes
c:\windows\syswow64\dkjonnfn.dll Generic Write,Read Attributes
c:\windows\syswow64\dldoce32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dldoce32.exe Generic Write,Read Attributes
c:\windows\syswow64\dmkmbj32.dll Generic Write,Read Attributes
c:\windows\syswow64\dmmjgdde.dll Generic Write,Read Attributes
c:\windows\syswow64\dohekp32.dll Generic Write,Read Attributes
c:\windows\syswow64\dpmnnd32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dpmnnd32.exe Generic Write,Read Attributes
c:\windows\syswow64\dqdcde32.dll Generic Write,Read Attributes
c:\windows\syswow64\dqfpiopd.dll Generic Write,Read Attributes
c:\windows\syswow64\eaamijbm.dll Generic Write,Read Attributes
c:\windows\syswow64\ecehhopd.dll Generic Write,Read Attributes
c:\windows\syswow64\edephp32.dll Generic Write,Read Attributes
c:\windows\syswow64\eeefbibe.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eeefbibe.exe Generic Write,Read Attributes
c:\windows\syswow64\eehbgipb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eehbgipb.exe Generic Write,Read Attributes
c:\windows\syswow64\eemicj32.dll Generic Write,Read Attributes
c:\windows\syswow64\efgoalge.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\efgoalge.exe Generic Write,Read Attributes
c:\windows\syswow64\egdffnbo.dll Generic Write,Read Attributes
c:\windows\syswow64\ehehcd32.dll Generic Write,Read Attributes
c:\windows\syswow64\ehneekon.dll Generic Write,Read Attributes
c:\windows\syswow64\eilhghnc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eilhghnc.exe Generic Write,Read Attributes
c:\windows\syswow64\eioemhlq.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eioemhlq.exe Generic Write,Read Attributes
c:\windows\syswow64\ejfepg32.dll Generic Write,Read Attributes
c:\windows\syswow64\fbecfnjl.dll Generic Write,Read Attributes
c:\windows\syswow64\fbefglga.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fbefglga.exe Generic Write,Read Attributes
c:\windows\syswow64\fefegcjb.dll Generic Write,Read Attributes
c:\windows\syswow64\ffjlgkeb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ffjlgkeb.exe Generic Write,Read Attributes
c:\windows\syswow64\fflhmk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fflhmk32.exe Generic Write,Read Attributes
c:\windows\syswow64\ffnebk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ffnebk32.exe Generic Write,Read Attributes
c:\windows\syswow64\fhpqfpjl.dll Generic Write,Read Attributes
c:\windows\syswow64\fmlnogng.dll Generic Write,Read Attributes
c:\windows\syswow64\fnojfq32.dll Generic Write,Read Attributes
c:\windows\syswow64\folepl32.dll Generic Write,Read Attributes
c:\windows\syswow64\folglmle.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\folglmle.exe Generic Write,Read Attributes
c:\windows\syswow64\fpbaoqca.dll Generic Write,Read Attributes
c:\windows\syswow64\fpjepdid.dll Generic Write,Read Attributes
c:\windows\syswow64\gaikhc32.dll Generic Write,Read Attributes
c:\windows\syswow64\gciamf32.dll Generic Write,Read Attributes
c:\windows\syswow64\gcooge32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gcooge32.exe Generic Write,Read Attributes
c:\windows\syswow64\gelibeld.dll Generic Write,Read Attributes
c:\windows\syswow64\geocha32.dll Generic Write,Read Attributes
c:\windows\syswow64\ggdnncqd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ggdnncqd.exe Generic Write,Read Attributes
c:\windows\syswow64\ghdaqi32.dll Generic Write,Read Attributes
c:\windows\syswow64\ghkaeamn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ghkaeamn.exe Generic Write,Read Attributes
c:\windows\syswow64\giknpddq.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\giknpddq.exe Generic Write,Read Attributes
c:\windows\syswow64\giolbg32.dll Generic Write,Read Attributes
c:\windows\syswow64\gjkdip32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gjkdip32.exe Generic Write,Read Attributes
c:\windows\syswow64\gjnqoo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gjnqoo32.exe Generic Write,Read Attributes
c:\windows\syswow64\gkmmib32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gkmmib32.exe Generic Write,Read Attributes
c:\windows\syswow64\glbdkq32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\glbdkq32.exe Generic Write,Read Attributes
c:\windows\syswow64\glbnbkjh.dll Generic Write,Read Attributes
c:\windows\syswow64\gldqqp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gldqqp32.exe Generic Write,Read Attributes
c:\windows\syswow64\gmgbdb32.dll Generic Write,Read Attributes
c:\windows\syswow64\gpkcfp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gpkcfp32.exe Generic Write,Read Attributes
c:\windows\syswow64\hafaqmdj.dll Generic Write,Read Attributes
c:\windows\syswow64\hbceajhp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hbceajhp.exe Generic Write,Read Attributes
c:\windows\syswow64\hbqhlkjb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hbqhlkjb.exe Generic Write,Read Attributes
c:\windows\syswow64\hcmeoh32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hcmeoh32.exe Generic Write,Read Attributes
c:\windows\syswow64\hcmkhcdf.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hcmkhcdf.exe Generic Write,Read Attributes
c:\windows\syswow64\hcoadhpd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hcoadhpd.exe Generic Write,Read Attributes
c:\windows\syswow64\hcohnc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hcohnc32.exe Generic Write,Read Attributes
c:\windows\syswow64\hdaamfgc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hdaamfgc.exe Generic Write,Read Attributes
c:\windows\syswow64\heckfcee.dll Generic Write,Read Attributes
c:\windows\syswow64\hedkjegb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hedkjegb.exe Generic Write,Read Attributes
c:\windows\syswow64\heknkj32.dll Generic Write,Read Attributes
c:\windows\syswow64\heogpdjl.dll Generic Write,Read Attributes
c:\windows\syswow64\hfejhp32.dll Generic Write,Read Attributes
c:\windows\syswow64\hgcgdh32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hgcgdh32.exe Generic Write,Read Attributes
c:\windows\syswow64\hgfdjgmb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hgfdjgmb.exe Generic Write,Read Attributes
c:\windows\syswow64\hgfkcb32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hgfkcb32.exe Generic Write,Read Attributes
c:\windows\syswow64\higmdb32.dll Generic Write,Read Attributes
c:\windows\syswow64\hijdfa32.dll Generic Write,Read Attributes
c:\windows\syswow64\himjedbn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\himjedbn.exe Generic Write,Read Attributes
c:\windows\syswow64\hjckgf32.dll Generic Write,Read Attributes
c:\windows\syswow64\hjnjfm32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hjnjfm32.exe Generic Write,Read Attributes
c:\windows\syswow64\hnndceaj.dll Generic Write,Read Attributes
c:\windows\syswow64\hqchgg32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hqchgg32.exe Generic Write,Read Attributes
c:\windows\syswow64\iaohcf32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\iaohcf32.exe Generic Write,Read Attributes
c:\windows\syswow64\ibhgbl32.dll Generic Write,Read Attributes
c:\windows\syswow64\ibjkbibg.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ibjkbibg.exe Generic Write,Read Attributes
c:\windows\syswow64\iblhgipe.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\iblhgipe.exe Generic Write,Read Attributes
c:\windows\syswow64\icanjhna.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\icanjhna.exe Generic Write,Read Attributes
c:\windows\syswow64\icfnoblk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\icfnoblk.exe Generic Write,Read Attributes
c:\windows\syswow64\ickgja32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ickgja32.exe Generic Write,Read Attributes
c:\windows\syswow64\icpaeadq.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\icpaeadq.exe Generic Write,Read Attributes
c:\windows\syswow64\idjnde32.dll Generic Write,Read Attributes
c:\windows\syswow64\igkmep32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\igkmep32.exe Generic Write,Read Attributes
c:\windows\syswow64\ignhifpb.dll Generic Write,Read Attributes
c:\windows\syswow64\ihcdepja.dll Generic Write,Read Attributes
c:\windows\syswow64\ihfgmj32.dll Generic Write,Read Attributes
c:\windows\syswow64\iikigjpk.dll Generic Write,Read Attributes
c:\windows\syswow64\ijgllk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijgllk32.exe Generic Write,Read Attributes
c:\windows\syswow64\ikgnka32.dll Generic Write,Read Attributes
c:\windows\syswow64\ikljgjfq.dll Generic Write,Read Attributes
c:\windows\syswow64\ikpceo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ikpceo32.exe Generic Write,Read Attributes
c:\windows\syswow64\iljkadlh.dll Generic Write,Read Attributes
c:\windows\syswow64\ilnlnmal.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ilnlnmal.exe Generic Write,Read Attributes
c:\windows\syswow64\ilqicl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ilqicl32.exe Generic Write,Read Attributes
c:\windows\syswow64\inchljei.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\inchljei.exe Generic Write,Read Attributes
c:\windows\syswow64\inlblkla.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\inlblkla.exe Generic Write,Read Attributes
c:\windows\syswow64\iohooi32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\iohooi32.exe Generic Write,Read Attributes
c:\windows\syswow64\iopdll32.dll Generic Write,Read Attributes
c:\windows\syswow64\ipglil32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ipglil32.exe Generic Write,Read Attributes
c:\windows\syswow64\iqhbbgmg.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\iqhbbgmg.exe Generic Write,Read Attributes
c:\windows\syswow64\iqjohfke.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\iqjohfke.exe Generic Write,Read Attributes
c:\windows\syswow64\jafnde32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jafnde32.exe Generic Write,Read Attributes
c:\windows\syswow64\jahkid32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jahkid32.exe Generic Write,Read Attributes
c:\windows\syswow64\jamdddko.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jamdddko.exe Generic Write,Read Attributes

223 additional files are not displayed above.

Registry Modifications

Key::Value Dados API Name
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Jkgeqmhi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Iljkadlh.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dqdcde32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lmfedkgo.dll RegNtPreCreateKey
Show More
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Folepl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Edephp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mcedha32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Nldjleeo.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Bkgpkqii.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mjcbee32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dmkmbj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Iikigjpk.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Fmlnogng.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lfanoo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ddofki32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mnlgke32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Cmaohmcd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ihcdepja.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Kiobka32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Adfkaq32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Acmfppob.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Klqhan32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Iopdll32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Onpqpmhg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dqfpiopd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lbbmfn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Hnndceaj.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Idjnde32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Jmegek32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Aqmepf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Hjckgf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Oclgpjni.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Bmlikg32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Fefegcjb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dmmjgdde.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mpdilaah.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lfibcbcp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Omcoan32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Cnhchkhj.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ddffkkgo.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ihfgmj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ckgepfqn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Hfejhp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Hijdfa32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Kffkemjh.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Pgcmmo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Pgfgojae.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Oijipc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dkgpihcm.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dohekp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Biibpjmp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lpbmee32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ikljgjfq.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Amaenlae.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Qejjjman.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Eaamijbm.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mimfao32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Kodkpd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Kqqljn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dhppmh32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Bcoilahd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lljkma32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Fhpqfpjl.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dibgqp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Qpamnqbe.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Cbnnmh32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Onpqpmhg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Cjnligob.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ehneekon.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Banknc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Idjnde32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Geocha32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dfiaoefc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Andjdd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ikgnka32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Plbmep32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Gaikhc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ecehhopd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Klglgf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ngocigbp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pjjjnpeg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Akkame32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Heknkj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ignhifpb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Gciamf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lcfpdl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Gmgbdb32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lcheec32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Oijipc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dkjonnfn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Heckfcee.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Biibpjmp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lpbmee32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Omkofl32.dll RegNtPreCreateKey

54 additional registry modifications are not displayed above.

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

C:\WINDOWS\system32\Negndljc.exe

Postagens Relacionadas

Tendendo

Mais visto

Carregando...