PUP.MSIL.Bulz.PN

The detection of PUP.MSIL.Bulz.PN on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.MSIL.Bulz.PN?

PUP.MSIL.Bulz.PN is a type of malware that is classified as a potentially unwanted program. This means that it is not necessarily a virus or a Trojan, but rather a program that may be installed on your system without your knowledge or consent. PUPs can be bundled with other software, downloaded from the internet, or installed through exploits. They often exhibit behaviors that are annoying, disruptive, or potentially malicious, such as displaying unwanted ads, collecting user data, or modifying system settings.

How PUP.MSIL.Bulz.PN Operates

Once installed, PUP.MSIL.Bulz.PN can operate in various ways, depending on its intended purpose. It may run in the background, consuming system resources and slowing down your computer. It may also interact with other programs, modifying their behavior or stealing sensitive information. In some cases, PUPs can be used to distribute other types of malware, such as viruses or Trojans, which can lead to more severe consequences, including data loss, identity theft, or system compromise.

Symptoms of Infection

The symptoms of a PUP.MSIL.Bulz.PN infection can vary, but common signs include unexpected pop-ups, slow system performance, unfamiliar programs or icons, and changes to your browser's homepage or search engine. You may also notice that your computer is behaving erratically, crashing frequently, or displaying unusual error messages. If you suspect that your system is infected with PUP.MSIL.Bulz.PN, it's crucial to take action promptly to prevent further damage.

How to Remove PUP.MSIL.Bulz.PN

  1. Boot your computer in Safe Mode with Networking to prevent the PUP from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of PUP.MSIL.Bulz.PN.
  3. Uninstall any suspicious programs or applications that may be related to the PUP, taking care to follow the uninstallation instructions carefully.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons.
  5. Reboot your computer and perform another scan to ensure that the PUP has been completely removed and that your system is clean.

Conclusion

Removing PUP.MSIL.Bulz.PN from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above and taking proactive measures to protect your computer, you can help prevent future infections and keep your system running smoothly. Remember to always be cautious when downloading software, avoid suspicious links or attachments, and keep your operating system and security software up to date to minimize the risk of malware infections.

Analysis Report

General information

Family Name: PUP.MSIL.Bulz.PN
Signature status: Modified signature

Known Samples

MD5: fd56c072a9bfb4d57914d43ed66a59ca
SHA1: c3a4cf5e98de26b88b7452c55d6f238f7eccdc3b
File Size: 1.84 MB, 1836768 bytes
MD5: 21e34ecb232153fc48f7f602e99fd717
SHA1: 0e01aa90b20d29e67581e2a52c985f5f4bc59f52
File Size: 1.84 MB, 1836768 bytes
MD5: 0d5cee4c0f8bfe055aca2a6644369a41
SHA1: 1fbfb7b16ef8cbcbe133c22d62f08b11969bb57e
File Size: 1.84 MB, 1836768 bytes
MD5: 1649001192703aada73362d81d4817e3
SHA1: a1bdee7187884bef0e7902f21c569bdf60f93b77
File Size: 1.84 MB, 1836768 bytes
MD5: 4e2c219a7cc081afcc3171d8b8c89ec8
SHA1: 9d89e75a914174395fc5ebf9a459c01fef36a013
SHA256: 32AAD97E8FC819304847A023B025616B9F96A6BDF12EB95B1CD4CC6E7972B4C1
File Size: 1.84 MB, 1836768 bytes
Show More
MD5: 4e08e7bc76c75351f980f652a0a17379
SHA1: 73303eb89be5c219fb60a8cdbe2941da96b510ca
SHA256: A819C3F468E64609D7A65CBC52859E1959FF5421EF80EA57E2864CB568831EAB
File Size: 1.84 MB, 1836768 bytes
MD5: b59cca4f5460820ecace686f1610e15a
SHA1: ada88267699c6d291fc3d00d38ace80e5375abc9
SHA256: AB699F9C49A3011D23A28ECB9FE76296E0C1C8979982334F4A8B0F65AC50B28A
File Size: 1.84 MB, 1836768 bytes
MD5: ad875d5fb8938662e09c50f28a7dfe80
SHA1: c243eb07d177fdbca79888cdcc53753e22c178f4
SHA256: 9ADF478819BAD884AFFC15219187FF9F744D275AC75384E16BD774E9A0E2AFDD
File Size: 1.84 MB, 1836768 bytes
MD5: 75440ed2ef1685068f3177aa4bd1def2
SHA1: 6cbca2162821054a473cca69a327c05ff7f18ba0
SHA256: 4246868987A0501F20B0A7BCEE5B4EB7D675C599C906CC73888977AB2BF32E48
File Size: 1.84 MB, 1836768 bytes
MD5: 90c09fc1143c9765298aae88285ebebe
SHA1: 4761eb99589d393d2ac50f334ffa5f5398797956
SHA256: C9C8FB88550BC84331F26EC6473F00A0B9628862F430AAFD3E3E8313C53D8A91
File Size: 1.84 MB, 1836768 bytes
MD5: 2648de7e670bc1116b0e3e686ef7be84
SHA1: 7b87518623dd296ee21000585d56494a43488f2d
SHA256: 900B9F87AA5B84DB74CDF18926D7B9E63FDC8F087BEE26015B5FDCC321DAEB54
File Size: 1.84 MB, 1836768 bytes
MD5: 10a78bcbb3bef90d542f3ec9558af219
SHA1: 0a80f9604bcfe2ee2cef3758536acd7fdb02d9e0
SHA256: EEE36B513BDFC4FF9E18B6FC923C53B9E4FF47394F9786503C265FE3B745CF33
File Size: 1.84 MB, 1836768 bytes
MD5: 8472b2f567187d013a7d8f76413682fd
SHA1: a0d422381d223a7cf16b6398f037a68e9c158961
SHA256: 6AB491293E635DC8A979152943DD3761A3347B18D771A2C8435000B930BDAA52
File Size: 1.84 MB, 1836768 bytes
MD5: 48014093509b5e9151bf2878999fefc1
SHA1: e9f9d18ed2b2a039677ba0f1959b5e1c1d0718a7
SHA256: FE094929BCCA9C1AA18732AD5723BAA84D986A1B3362E0757B33A5919FA3980F
File Size: 1.84 MB, 1836768 bytes
MD5: 5a3de6b8c26fff3c317a68885963276e
SHA1: cce112585ca9603856113b934e1cbedb98c34cf0
SHA256: 21628CFBFE7BE9DF55F0B6DE8A7D5394CA29B3A6411032B78645B3C4A979D6D1
File Size: 1.84 MB, 1836768 bytes
MD5: 8d7e692d56557a5f613ad0cd092e5f39
SHA1: 915ebbed46971a158634d2e671ee457f23b03004
SHA256: 689EE2042DD06AF1F88DF869254336CEE87CDF9917681FB77260F575551E0F06
File Size: 1.84 MB, 1836768 bytes
MD5: 58c4bf7bcd038ac2cbec5abe8c3af507
SHA1: fa3c36d1d9b7c8f59d4a41237f5067ebf984526d
SHA256: 8663153AE594978EBD0CBDD4DFEA9BA593846097D1ACFB6A76FC17B8C59EDB27
File Size: 1.84 MB, 1836768 bytes
MD5: 578b467d4df2ca0584916956dd3f8c7d
SHA1: 35cd72e1802ffdfa6d5f2237f61a68730347e2a4
SHA256: 17A459D6B8BEC17A0615091F6087E690BB61B1EB6797B76F6D3E64A1F617D3AE
File Size: 1.84 MB, 1836768 bytes
MD5: 618601c6d466fdbcc4c78c760ae88d02
SHA1: 33df4f9c0265fe527e8567d50bb9cdb95804d9ac
SHA256: 9E7DDE8E2460043D91F88F9CE27D470D42C426472FEED6B3DBF2ACDC1E4E1311
File Size: 1.84 MB, 1836768 bytes
MD5: d8e511c40080168b1503f2ccea6a285b
SHA1: 3c54824f9625541086e9097eeb806ea136cfe3e1
SHA256: 07F7147702A68169EB94161D5644D036CBADECD492C53ED994083F18CED0B1A3
File Size: 1.84 MB, 1836768 bytes
MD5: 123962f14dabe85415ce7864ccc97216
SHA1: 690275fee295e95e758bd42a173a16e304e72885
SHA256: 355DEF3616D2C7AFC863CCCA1FDA74C051CC3B30CF0F94DD3DADF86F5A621AA7
File Size: 1.84 MB, 1836768 bytes
MD5: 3ee117696f0caa90ccd8c2e0700a3923
SHA1: b9ef600752825cc7f84dc21ee1a933579fb6cf34
SHA256: BE022471070057A65A3D37B2BDE964705C2A20DF7D6C9D720F33B4208AC02C0D
File Size: 1.84 MB, 1836768 bytes
MD5: 2eb41bbc2edf15a3b05320fa987ae4de
SHA1: 81a7d2852b7312ad02572834bdbaa0f6c224b520
SHA256: B3D0AC0943C8024E4752225271055590AEE769FA10F27F5FCB93CE7D8E0A1F6D
File Size: 1.84 MB, 1836768 bytes
MD5: 61196915b8fd6c76d3223e6db00a86f1
SHA1: 8b36ef906b57808b2c3684912ce0e37c74896e99
SHA256: 045BBC62A27D208C4A72EB2EA72FCA00A13785C6F43B6693F80091D8D08F6682
File Size: 1.84 MB, 1836768 bytes
MD5: 07c963de98bac66ff04326b86fad4f00
SHA1: 744ccc359aa53e224aa1de934cddf4d0fd0b25b1
SHA256: D41E4CF3B83DD0BC6297B88DAEB3052A6F524CE879AEFF4030E165FE529F3B5A
File Size: 1.84 MB, 1836768 bytes
MD5: c76a0c150adba2b84c58efe9b062f4b8
SHA1: be92b0a6254c53dfd98c47edc34f29c591624c8d
SHA256: 6DF2CC2BC557637E1547DE698B0F8DD336E38FC06909E13DFE78AA97E04F83AD
File Size: 1.84 MB, 1836768 bytes
MD5: cb1426babdb6d54fb2c4008f7a13f365
SHA1: 3669d3daf1adc2552403b2b8ec8afdacfcdc5a8c
SHA256: 89C7C191E980E61D58A3DE986641B14D7816B84E3403B6ADD840085BD19E7232
File Size: 1.84 MB, 1836768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Yandex
  • Яндекс
File Description
  • YandexDiskSetup
File Version
  • 3.2.30.4914
Internal Name
  • YandexDiskSetup
Legal Copyright
  • © 2016-2023 ООО "ЯНДЕКС"
Original Filename
  • YandexDiskSetup.exe
Product Name
  • Yandex.Disk
  • Яндекс.Диск
Product Version
  • 3.2.30.4914

File Traits

  • Installer Version
  • x86

Block Information

Total Blocks: 3,926
Potentially Malicious Blocks: 361
Whitelisted Blocks: 3,454
Unknown Blocks: 111

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? ? ? ? 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? ? ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 1 0 0 0 x 0 ? ? ? 0 ? 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? ? 0 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 x x 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x x x x x x x x x x x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x x x x x x x x x 0 0 0 0 x 0 0 x x x 0 x x x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x 0 x x 0 x 0 x 0 x x x 0 0 x x x x 0 x 0 0 x x x 0 x 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 x x x 0 x 0 x x 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 x x x x x 0 x x 0 x x x x x x x x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x x x 0 x 0 x 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 x x x x 0 x x x x x x x 0 x 0 x 0 0 0 0 0 x x x 0 x x x 0 x x x x x 0 x 0 x 0 x x x x 0 x x x x 0 x 0 x x x 0 x 0 0 x x 0 x x x 0 x x x x x x x x x 0 0 0 x x x x x x x x x x x x 0 x 0 x 0 x 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 x x 0 0 0 0 x x x x x x x 0 0 x 0 0 0 0 x x 0 0 0 x x x 0 x x x 0 x 0 x x x x x 0 x x x x x 0 x x x 0 x x 0 x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x x x 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Bulz.PN

Files Modified

File Attributes
c:\programdata\yandex\yandex.disk.2\{3fe0ef39-1462-4094-9a42-43b4ee3c383b}\yandexdisk30setup_x64.exe Generic Write,Read Attributes
c:\users\user\appdata\local\yandex\yandex.disk.2\events_setup.dat Generic Write,Read Attributes
c:\users\user\appdata\local\yandex\yandex.disk.2\events_setup.dat.lock Generic Write,Read Attributes
c:\users\user\appdata\local\yandex\yandex.disk.2\yandexdisksetup.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\yandex\ui Generic Write,Read Attributes
c:\users\user\appdata\roaming\yandex\ui_yd2 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ck�|v8���B �� �6 �v �� 7� xy �� ���T�B���������%����Bx�<�!�R#��$kF$��%�&� '�!(�(X�(�) ;)�`*9*�",=�1`1�1HO5,]5�G>��@V�@�*B E�mF Fy�H[uH�pH��J��M�lN$N� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 qk �v1�1HO@V�N�y�9{b��P��/�����X����m�����$წ���=�SB1_T�Vw���%�������AE��D��&��$���L RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 rk �v(�1�1HO@V�N�y�9{b��P��/�����X����m�����$წ���=�SB1_T�Vw���%�������AE��D��&��$���L RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 sk|v �v(�1�1HO@V�N�y�9{b��P��/�����X����m�����$წ���=�SB1_T�Vw���%�������AE��D��&��$���L RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ,k|v8��8tXz��B�8 �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 2k |v8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P% RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 *k�|v8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�0 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 +k�|v8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�0 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Zk�|vjg�B �� �6 �v �� 7� �� ���T�B�������%��Bx�<�!$��%�&� '�!(�(X�(�) ;)�`*J*9*�",=�-!R1`1�1HO5,]5�G>��@V�@�*A��B E�mF Fy�G�IH[uH�pH��M�lN$N�P@jR��U_*X � RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k�8�tX��8 �6 �v xy ��T���������5����3bBx��!wz#�#��$kF%:�&� (�(X�)E*J*9+�[,��/9�/��1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$N�R20U_*V �X�`�2b"h RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k�|v8�tX��8 �6 �v xy ��T���������5����3bBx��!wz#�#��$kF%:�&� (�(X�)E*J*9+�[,��/9�/��1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$N�R20U_*V �X�`�2 RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::left RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::top RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l�|v8��8tXz�jg�8 �� �6 �v z �Z xy ����T�B���������%���5���� +3bBx�<��5 �!wz"Wc#�#��$kF$��%:�%`�%�&� &�-(�(X�(�)�`*J*9*�"+�[,=�,��-!R/9�/��0P% RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
Encryption Used
  • CryptAcquireContext

Related Posts

Trending

Most Viewed

Loading...