PUP.Keygen.Agent.A

The detection of PUP.Keygen.Agent.A on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Keygen.Agent.A?

PUP.Keygen.Agent.A is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are often bundled with other software or downloaded from untrusted sources, and they can cause a range of problems, including slowing down your computer, displaying unwanted ads, and potentially exposing your personal data to risk.

How PUP.Keygen.Agent.A Operates

PUPs like PUP.Keygen.Agent.A typically operate by installing themselves on your system and then running in the background, often without your knowledge or consent. They may collect data about your browsing habits, search history, and other online activities, and use this information to display targeted ads or sell it to third-party companies. In some cases, PUPs may also install additional software or malware on your system, which can further compromise your security and privacy.

Symptoms of Infection

If your system is infected with PUP.Keygen.Agent.A, you may notice a range of symptoms, including slow system performance, unwanted ads or pop-ups, and unexpected changes to your browser settings or homepage. You may also notice that your system is running more slowly than usual, or that you are experiencing frequent crashes or errors. In some cases, you may not notice any symptoms at all, which is why it's essential to run regular virus scans and monitor your system for suspicious activity.

  • Slow system performance
  • Unwanted ads or pop-ups
  • Unexpected changes to browser settings or homepage
  • Frequent crashes or errors

How to Remove PUP.Keygen.Agent.A

  1. Boot your system in Safe Mode with Networking to prevent the PUP from running and interfering with the removal process.
  2. Run a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of PUP.Keygen.Agent.A.
  3. Uninstall any suspicious programs or software that may be related to the PUP, and remove any unwanted browser extensions or add-ons.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by the PUP.
  5. Reboot your system and run a follow-up scan to ensure that all instances of the PUP have been removed and that your system is clean.

Conclusion

Removing PUP.Keygen.Agent.A from your system requires a combination of technical expertise and caution. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and keep your personal data safe. Remember to always be cautious when downloading software or clicking on links from untrusted sources, and to run regular virus scans to detect and remove any potential threats.

Analysis Report

General information

Family Name: PUP.Keygen.Agent.A
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 386278c667119a085a054443bc0ac92e
SHA1: a1a4010b4dc063c740b754661d645b7f8cc4ced3
SHA256: B8578A9CDE82AC6B29F2177D4C417CDB30F9F4A014B0D3BB628522A2A40D3385
File Size: 739.33 KB, 739328 bytes
MD5: 2c1433c2ffe11dee51e7cc5ffe669e90
SHA1: 1eb0cd3a465489d3761fabcb82a3e65b59e05ca0
SHA256: E58DA5236CAD32B4308D06D1A2362DE1B4E015B88004DB5D6893E9C8AA5A00C5
File Size: 7.57 MB, 7574580 bytes
MD5: ec10781a9875cb35d4b132d3b8b31bb5
SHA1: 4746701bf8774d62a1cccebb9767b312dc17c318
SHA256: 3181D71CB62E25D8FCC20E5DA7641E170F9B2B4C2D20EF96E76C3FD74ABD9664
File Size: 236.03 KB, 236032 bytes
MD5: c77d03605afc378f96b9593e8b8b4bdd
SHA1: 4f78864a6f06bd7f1425372d1d18b2c19be8d57d
SHA256: 669C44BD8EEA14118F51152137F21A5C20A5FE6B00689CE12F44106BFCDC7438
File Size: 316.42 KB, 316416 bytes
MD5: 0c5796e00b978df4316eebe99a2b166d
SHA1: 371a847b87cbdb3d89ee28652b47967ecc75faa2
SHA256: BED0433362A47E2FB300A8EE3E233FB8C3B6A5C1C73ADC6CCD3796934A249955
File Size: 269.31 KB, 269312 bytes
Show More
MD5: 77645e7aa7293fe308d1e72d183e7a2e
SHA1: e9a15f30112ecbd9f12dcd7503c1cdafa24390a3
SHA256: 05D378EF634358F70B58CB0F3871EC1868B4BC8923F4D0C37F7450498D5B9DAB
File Size: 992.26 KB, 992256 bytes
MD5: 382ee9572b6dd427de9ed92a8958ed66
SHA1: 669494296b1c046a6cdcb0c64ad801464a07485b
SHA256: 33C0FEACC8B9B514EA0D6356D23E492353C85DE04C0D4C0D54F57B130A946CF1
File Size: 7.30 MB, 7304737 bytes
MD5: e919e8f66d96c43efdca0981fe8932f8
SHA1: e69dd6d3b1c59f9655d309baad4a8541bfa35bf3
SHA256: EECDE9FA13A4AE64F1925CE1944A7178E6B29DF99133814B8E41BB97F5749D4B
File Size: 152.58 KB, 152576 bytes
MD5: 9813a5c6ee69205efed12e30478bd8ff
SHA1: ad5a0c5755acb2074d4a2ba0522f9de143a7575d
SHA256: 4FF3C0F5724E21ED7A7F1C0564CA2C9B8B229A8D41DF651F8B1F6A1754B36AB1
File Size: 3.71 MB, 3706946 bytes
MD5: cc7819f7919e547234c0f9771d5cd1a2
SHA1: 20f9430a358470ee7879094ad682bd7aecf7ac35
SHA256: 21F3E63ACD3C4BB84591C8A342AA5D60908B9F96E72587EB3110E577B33238F7
File Size: 706.56 KB, 706560 bytes
MD5: 95e317fd4c153bbe3cc7e9e3894d8b43
SHA1: bf5563053bf32b6fcc02993f614f361ef1597e6b
SHA256: 35BE05C6AA7185F9C392D89C4AFB757A45CFD17A4C96C940B9AA9264B75127FD
File Size: 992.26 KB, 992256 bytes
MD5: 83c4a6b794a70a3ec4026a69899a12cc
SHA1: daed3d92903f04e90093fdb066192c741cc86171
SHA256: E4A4A050C89FE4F4411174523563EA1BB2D0291E4E4C4A79E5D4584C2B7D7E9B
File Size: 1.05 MB, 1050112 bytes
MD5: e9a32623e6496d92623c9191f0688823
SHA1: 9fad668ff5d90ace5d30b3eab7b2245106e2aa70
SHA256: 3B6EDCC816A0AB1A7ADC8CB6CEF2F0761D03CFFC6E1E3B6FE109D259F07B8179
File Size: 509.53 KB, 509531 bytes
MD5: 9317694f728db721ebccefe91adf0119
SHA1: f316995ead90e86d8eec741f2ba86cee1a6ad6f6
SHA256: 0F2635A4B5426B55746658A9D292EFED0FFF0BA20A9CF4AB69E8B06C1E291DF3
File Size: 74.75 KB, 74752 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Alcohol Activator v1.3
Comments
  • This installation was built with Inno Setup.
Company Name
  • KaOsKrew
  • Sokaris Paweł Łuczak
File Description
  • Sokaris Przelewy Setup
  • The.Walking.Dead.A.New.Frontier.Episode.4.REPACK-KaOs Setup
File Version
  • 1.3.0.0
  • 1.1.4.20
Legal Copyright Copyright © 1999-2007 Sokaris Paweł Łuczak
Product Name The.Walking.Dead.A.New.Frontier.Episode.4.REPACK-KaOs
Product Version
  • 3.0
  • 1.0.0.0

File Traits

  • 00 section
  • 2+ executable sections
  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 7
Potentially Malicious Blocks: 0
Whitelisted Blocks: 1
Unknown Blocks: 6

Visual Map

? ? ? ? ? ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • BadJoke.XA
  • Banker.GF
  • Injector.KPP
  • Lamer.B
  • Malat.A
Show More
  • QHost.XG
  • Trojan.Agent.Gen.AKH

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\11336545\bassmod.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\dos_font.fon Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\exit_normal.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\exitskin.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\flc_doit.xm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\generell.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\install_normal.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\instskin.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\linezer0_fixed.x Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\11336545\lz0.nfo Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\main_mask.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\main_normal.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\main_over.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\mainskin.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\nfo_mask.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\nfo_normal.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\nfo_over.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\nfoskin.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\unrar.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\11336545\unzdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7335911\bassmod.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\exit-up.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\exit1-mask.bmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\exitskin.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\generell.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\icf.zip Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\infected.nfo Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\install-over.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\install-up.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\installer1-mask.bmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\instskin.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\main-over.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\main-up.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\mainskin.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\nfo-mask.bmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\nfo-over.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\nfo-up.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\nfoskin.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\smalldos.fon Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\spt!rota.mod Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7335911\unrar.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\fhbgrkcittbyvgqsomeu.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\fttgxskqcc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\gqlrjgnnpspbtazwvskc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-p0854.tmp\ad5a0c5755acb2074d4a2ba0522f9de143a7575d_0003706946.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp Write Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\01.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\02.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\03.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\04.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\05.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\06.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\07.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\08.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-v4t6o.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-v4t6o.tmp\bass.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\callbackctrl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-v4t6o.tmp\isdone.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\juatafjnczwgrmnnuoqs.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mlxhgguhopqqxoasuswc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ockmtehlhltuelnmqihx.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\prxruveaddxrqkpgupao.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rrzfviqwpj.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\sae6357.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\test.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\uvtsmadomdlskyyecpip.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\vbjxchmqorcxidyezyuc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\xndiwwyohw.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ywbpbxkcwd.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs560.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs561.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5610.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5611.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5612.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5613.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5614.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5615.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5616.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5617.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5618.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5619.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs562.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs5620.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs563.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs564.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs565.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs566.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs567.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs568.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~fs569.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\csrv.exe Generic Write,Read Attributes
c:\users\user\downloads\temp\shsandbox-win32.dll-5.22.1.9999-x86.dmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\temp\mp9857.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ���� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\directdraw\mostrecentapplication::name 20f9430a358470ee7879094ad682bd7aecf7ac35_0000706560 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\directdraw\mostrecentapplication::id 帙⩂ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\direct3d\mostrecentapplication::name 20f9430a358470ee7879094ad682bd7aecf7ac35_0000706560 RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
Keyboard Access
  • GetKeyState
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Terminate
  • TerminateProcess

Shell Command Execution

"C:\Users\Tkswclai\AppData\Local\Temp\is-P0854.tmp\ad5a0c5755acb2074d4a2ba0522f9de143a7575d_0003706946.tmp" /SL5="$80244,3257056,55296,c:\users\user\downloads\ad5a0c5755acb2074d4a2ba0522f9de143a7575d_0003706946"
"C:\WINDOWS\system32\attrib.exe" +s +h C:\Users\Tkswclai\AppData\Local\Temp\is-V4T6O.tmp
cSrv.exe