Threat Database Cracks PUP.Crack.PC

PUP.Crack.PC

The detection of PUP.Crack.PC on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it to prevent further problems.

What Is PUP.Crack.PC?

PUP.Crack.PC is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as harmful as other types of malware, such as viruses or Trojans, it can still cause problems with your system and compromise your privacy. PUPs are often installed unintentionally, bundled with other software or downloaded from untrusted sources.

How PUP.Crack.PC Operates

PUP.Crack.PC operates by installing itself on your system, often without your knowledge or consent. Once installed, it can start to display unwanted advertisements, collect your personal data, and even install additional malware. It may also modify your system settings, such as changing your default search engine or homepage, to generate revenue for its creators. PUPs like PUP.Crack.PC can be challenging to remove, as they often use rootkit techniques to hide themselves from detection.

Symptoms of Infection

If your system is infected with PUP.Crack.PC, you may notice several symptoms, including unwanted pop-ups and advertisements, slow system performance, and unfamiliar programs or toolbars installed on your browser. You may also experience redirects to suspicious websites, and your search results may be altered to display unwanted content. Additionally, you may notice that your system is crashing or freezing frequently, or that your personal data is being collected and used for malicious purposes.

  • Unwanted advertisements and pop-ups
  • Slow system performance
  • Unfamiliar programs or toolbars installed on your browser
  • Redirects to suspicious websites
  • Altered search results
  • System crashes or freezes
  • Collection and misuse of personal data

How to Remove PUP.Crack.PC

  1. Boot your system in Safe Mode with Networking to prevent PUP.Crack.PC from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove PUP.Crack.PC and any other malware that may be present.
  3. Uninstall any suspicious programs that may be related to PUP.Crack.PC, and remove any unwanted browser extensions or toolbars.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by PUP.Crack.PC.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that PUP.Crack.PC has been completely removed.

Conclusion

Removing PUP.Crack.PC from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above, you can help to ensure that your system is free from this potentially unwanted program and any other malware that may be present. Remember to always be cautious when downloading software from the internet, and to use reputable anti-malware tools to protect your system from future infections.

Analysis Report

General information

Family Name: PUP.Crack.PC
Signature status: Hash Mismatch

Known Samples

MD5: d0c23073f7387333d10965c1f01e6a65
SHA1: 0026a4438e64570daaf577f88d08ba01f2411bc6
SHA256: DFB0AD0A1BB5F71B8E20223AD4267997C0638C4470033411B5501A270964F600
File Size: 8.59 MB, 8593872 bytes
MD5: 51478c80e6488f874794f511fddb432a
SHA1: e6661c85134dee014c725018de2cad89098b8e87
SHA256: 73C77287CE8C3EF02D741F95FA4E1B66DCBC5D6E0D136682A2FDB2988CC430CB
File Size: 7.32 MB, 7318480 bytes
MD5: 558895f062ec98577b2e329a62eec9d4
SHA1: d4092c62e5f4f90e3e49a556cf3fb022367e1c12
SHA256: 27A6797B6A93D328D12D0AC2D1987B724245EE9DB10A44D4EBC9BF0A169C83FB
File Size: 9.37 MB, 9374680 bytes
MD5: 5ef7e72c9536abad44fc5b1432d723d2
SHA1: af5cd48004fff7780f98639f3c4e3b8b23db36c1
SHA256: 1B36A51B91693822AB5DF1F135F52496D58327BB16825E573AA3631D09C32F5D
File Size: 7.34 MB, 7340032 bytes
MD5: c8cd91b515513107b5f6d80ecda71bae
SHA1: f0ee733743668f61fcd323177cde088f82c7608e
SHA256: EE68130EDE05B88E42555956EE298D379A8FA752FCF973A3DF0CA045B7903376
File Size: 8.59 MB, 8593872 bytes
Show More
MD5: d59c4387b19229fee2a1aeb7ae7a008c
SHA1: ea0303834ab1ab9c233875bdcb769cb6cb2a5236
SHA256: 8C7F868041D649D46238B31FF80DD1CC2961305D05D61B5FD1618707A112CA9E
File Size: 8.60 MB, 8596944 bytes
MD5: 492f5837e9d30cfba3240f174b0892f0
SHA1: 16f6015d1a659db66f6fe6cf8df49e82e4e47d2c
SHA256: F55E208BA7CF1C46E0C1138CF63010945CA41A59CC1FB1A919B9DB7B7BDC9BEE
File Size: 8.96 MB, 8958928 bytes
MD5: 49e285b47473636c0f4761782f9ed5c1
SHA1: 0cdb1b570a5f89c60c4091743810309b013dcc08
SHA256: 3FFD38EE6FEE1486A894DEF37512FF3D54CD15A025C20C703ABFC4F84A789635
File Size: 9.37 MB, 9373600 bytes
MD5: c0dc5450b0d04798fc05f223bdb6f760
SHA1: 956ea9a3c0b7adc08e269818545e58156abd9019
SHA256: E43D2947A0AE66A40910AD10D720B9A89FB2F6E0A245ABA0245CEFB9CDFAF6E7
File Size: 8.59 MB, 8593872 bytes
MD5: 4ee9dc9163955327115b5159463220a5
SHA1: ee9ac5bec9649f52a6e20d1572c43d32ef5e6ec1
SHA256: 88BDDC32147F187B7D05A740752935891D96A89C069D298C66903AD45BE4A21B
File Size: 7.89 MB, 7891928 bytes
MD5: 19ab67fc54116475a31713d7ae3f832a
SHA1: 3a1f3bf637237e71e7e50583bcbeedf9e9e4f126
SHA256: 1C510BC5CBF521E35215260853B5C94DC05BADECF51C4878EFDFC3BDC66DCEEE
File Size: 9.37 MB, 9373600 bytes
MD5: 328147a30fc6f0ba4af313b70f4f966b
SHA1: 300e4ee0d62bb52261c253363c25f0ff761b5923
SHA256: 5517BA17266A10A4FF4FA7F103F23AEEB71D2D1D63CF2AAEE9546C43A581BB3D
File Size: 8.41 MB, 8409768 bytes
MD5: d0d737763161c6ab64cdd635b9541b0e
SHA1: e6bd593e10c76ba6e43bdbb294d5910bfe04e8db
SHA256: 2325BF952D16D3CA38931F741CB252FD8CCDCE0B50C82902407ED1A82DBA0E1B
File Size: 8.31 MB, 8311520 bytes
MD5: 3bd9c5ac9851e25eaec5c5ab0be44431
SHA1: 0fb3c34f8ffc6fcf8f7a2dcc2182986233aedc49
SHA256: DDA1670097557B77CA08BB8C543008A2AB379F78B3AD5B4491A607CD31945D9B
File Size: 6.96 MB, 6957520 bytes
MD5: 723f74743c8ef7c356c59687f1766746
SHA1: 475a80aca513e3316fe1002e4dc98cf844ce4d70
SHA256: 2D3761347EC712867C9D0638AE640F7303220BBEF8EC85AB2B09C8517601AF84
File Size: 8.60 MB, 8596944 bytes
MD5: 2b2fdec80aaea16d14923bda3c67ff42
SHA1: 010a692ad07a3186070c50ede6f91e8f1b69d1a1
SHA256: 526573829090170742520DDBD6AFD7E6778075655CED4A65F7DDBF110D0DE7A4
File Size: 8.60 MB, 8596944 bytes
MD5: 2f90463bb25016e5aa68ff68c6d1ab18
SHA1: ee318aa9b1dbb4db31ffc72c237f7ce7e6729ca4
SHA256: F057738269487B6C95BBEE62CAD29A7557511CE8142DD8736EC6C20932F93DF5
File Size: 9.37 MB, 9374680 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Adobe Systems Inc.
  • Adobe Systems Incorporated.
File Description
  • Acrobat Distiller
  • Acrobat Licensing Service
  • AcroTray
File Version
  • 23.8.20555.0
  • 23.8.20458.0
  • 23.8.20421.0
  • 23.6.20380.0
  • 23.3.20269.0
  • 23.3.20215.0
  • 23.1.20174.0
  • 22.3.20322.0
  • 22.3.20314.0
  • 22.3.20282.0
Show More
  • 22.3.20263.0
  • 22.3.20258.0
  • 22.2.20212.0
  • 21.11.20039.0
Internal Name
  • Acrobat Distiller
  • AcroTray
Legal Copyright
  • Copyright Adobe Systems Inc. 1984-2021
  • Copyright Adobe Systems Inc. 1984-2022
  • Copyright Adobe Systems Inc. 1984-2023
  • Copyright © Adobe Systems Inc. 1992-2022
  • Copyright © Adobe Systems Inc. 1992-2023
Original Filename
  • acrodist.exe
  • AcroTray.exe
Product Name
  • AcroTray - Adobe Acrobat Distiller helper application.
  • Adobe Acrobat
Product Version
  • 23.8.20555.0
  • 23.8.20458.0
  • 23.8.20421.0
  • 23.6.20380.0
  • 23.3.20269.0
  • 23.3.20215.0
  • 23.1.20174.0
  • 22.3.20322.0
  • 22.3.20314.0
  • 22.3.20282.0
Show More
  • 22.3.20263.0
  • 22.3.20258.0
  • 22.2.20212.0
  • 21.11.20039.0

Digital Signatures

Signer Root Status
Adobe Inc. DigiCert EV Code Signing CA (SHA2) Hash Mismatch
Adobe Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • CryptUnprotectData
  • dll
  • x64

Block Information

Total Blocks: 26,005
Potentially Malicious Blocks: 13,801
Whitelisted Blocks: 12,170
Unknown Blocks: 34

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 x x 0 0 x x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 1 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 1 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 x 0 x 0 0 x 0 0 0 x x 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x x x x 0 0 1 0 x x 0 0 0 0 0 x x 0 x x x 0 0 0 x x x 0 x x 0 x 0 0 0 0 0 x x x x 0 0 0 0 0 x x x x x 0 x x x x x 0 x x 0 x x 0 0 0 x x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 1 0 0 0 1 0 0 1 0 0 0 x 0 0 0 x x 0 0 x 0 x 0 0 x 0 0 x 0 0 0 x 0 x 0 x 0 0 x x x x 0 0 x 0 x 0 0 0 x x x x 0 0 0 0 x x x 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 x 0 x x x x x x 0 x 0 0 x 0 1 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x x x x 0 x x x x x x 0 0 0 x x 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Crack.PC

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\distngllog.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ngl Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\adobe\adobe acrobat\dc\adobeviewer::launched  RegNtPreCreateKey
HKLM\software\adobe\adobe acrobat\dc\adobeviewer::launched  RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\adobeviewer::eulaacceptedforbrowser  RegNtPreCreateKey
HKLM\software\adobe\adobe acrobat\dc\adobeviewer::eulaacceptedforbrowser  RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\aventitlement::sappentitlementstatus 低䅖啌E RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\aventitlement::suseremail RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\aventitlement::suserguid RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\aventitlement::sdeviceid RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\aventitlement::sproductversion 12.0 RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\aventitlement::sproductname 摁扯⁥捁潲慢t RegNtPreCreateKey
Show More
HKCU\software\adobe\adobe acrobat\dc\aventitlement::sproductguid ACROBAT_GUID_NGL_DUMMY RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\aventitlement::sproductguid ACRO_RESIDUE RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\ddfb16cd4931c973a2037d3fc83a4d7d775d05e4::blob x�`/���7�S.uI0N��K���j8�XCPx �c,j��C�7�Mf �6o�TTJ�h��91�~�S@0>0 `�H��l00 +�7<�0g� 00 +�7<� 402+++++ 2DigiCert RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\ddfb16cd4931c973a2037d3fc83a4d7d775d05e4::blob \�� y��,��Up��7���I1�s�}?�:M}w]��mƢ3�3���AI'�Y����q]dL�.g?纘�Ob U/{�񧯞l�rO��r@ǎv���� ș� 2DigiCert Trusted Root G4 402 RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\aventitlement::bisdatavalidforngl  RegNtPreCreateKey
HKCU\software\adobe\adobe acrobat\dc\aventitlement::ientitlementlevel  RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetComputerNameEx
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest

Related Posts

Trending

Most Viewed

Loading...