PUP.SparkOnSoft

The detection of PUP.SparkOnSoft on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it to prevent potential harm. In this report, we will provide an overview of PUP.SparkOnSoft, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is PUP.SparkOnSoft?

PUP.SparkOnSoft is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, privacy, and security. They often come bundled with other software or are downloaded from the internet, and can be difficult to remove without proper guidance.

How PUP.SparkOnSoft Operates

PUP.SparkOnSoft, like other PUPs, may operate by collecting user data, displaying unwanted advertisements, or modifying system settings without permission. It may also install additional software or components that can further compromise your system's security and performance. The exact operating methods of PUP.SparkOnSoft may vary, but it is essential to be aware of the potential risks and take steps to mitigate them.

Symptoms of Infection

Systems infected with PUP.SparkOnSoft may exhibit a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and unexpected changes to system settings. You may also notice unfamiliar programs or icons on your desktop, or experience issues with your internet browser, such as redirected searches or unwanted toolbars. If you are experiencing any of these symptoms, it is crucial to take action to remove the PUP and prevent further damage.

How to Remove PUP.SparkOnSoft

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for internet access. This will enable you to download and install removal tools if necessary.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of PUP.SparkOnSoft. This may require purchasing a license or subscription to the removal tool.
  3. Uninstall any suspicious programs or applications that may be related to the PUP. Be cautious when uninstalling programs, as some may be legitimate or required for system operation.
  4. Reset your internet browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions, toolbars, or settings that may have been modified by the PUP.
  5. Reboot your system and perform a follow-up scan to ensure that all components of PUP.SparkOnSoft have been removed. This will help to verify that the removal was successful and that your system is clean.

Conclusion

Removing PUP.SparkOnSoft from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined in this report, you can effectively remove the PUP and prevent potential harm to your system. It is essential to remain vigilant and take proactive steps to protect your system from future threats, including keeping your operating system and software up to date, using reputable anti-malware tools, and being cautious when downloading and installing software from the internet. Remember to always prioritize your system's security and performance to ensure a safe and efficient computing experience.

Analysis Report

General information

Family Name: PUP.SparkOnSoft
Signature status: Self Signed

Known Samples

MD5: ca7aee4051ba32dc74eafa1d2f74513c
SHA1: 80eea992a773237bb601d75058f862f7feaffeba
SHA256: D878E829C49EB5FD247EE15633E949B20270F6E0B93971DE59532B70E64B98EB
File Size: 9.13 MB, 9133552 bytes
MD5: c0a9127f8ced890563d9f38dddd29469
SHA1: ab268ba34430904cbf7f944281f9d00fef83cb1b
SHA256: B524281FE3F466EC5AF4D147BE1ADF96B076A3AC14AB2AD2F1122AA4F5DFB45A
File Size: 2.83 MB, 2828583 bytes
MD5: a1312895bb804a7c52ece6edd72bc8ce
SHA1: 3361cd48c2d2c6e35c94389718f4fc3f072ee620
SHA256: D95F2642DD2E1E1160FB86ADDE91A28C0A5B2DE2CED5F45004C19C24C61BCBA0
File Size: 749.12 KB, 749120 bytes
MD5: 5cb9fe5d3f190a6e1d83df1b82cb4f1d
SHA1: 1fd9df2e381f1f1b060fb0d6e57b915ad35774dc
SHA256: 6A5400F9E6694A262CB57007BE91E2DBCF98DA77C041A9556B1A8120C084FD7E
File Size: 2.80 MB, 2801408 bytes
MD5: 3c4c8e054a99286792d4843b87155342
SHA1: 6ffdbfe79c0df9b2f8b1df80eec7c9f36f5c7a4c
SHA256: 25ED1C694ABD1B26690DC86CD6F2C293A23DC9A6E300620D77DC49927D3F63A0
File Size: 1.66 MB, 1655864 bytes
Show More
MD5: 9fb769484a284808ba7f1bdc486a1927
SHA1: 699e41de3393c9509ceef07a2ddc3d4599f01ae8
SHA256: FEDEC49876C2AA8DCF13B78297F5B4D9C437F1509862ABB02E3980FCA9E3AD7D
File Size: 2.97 MB, 2966000 bytes
MD5: 065ee5084a584caf62b66475f93e15f4
SHA1: 23180e8671cf435bc244a8d9eb1e2ddbd3b02534
SHA256: 5FA0684AEED9A7AE766BB4CE17D4C0FEDDDDB80B1433D21C39497BC153D97DE5
File Size: 2.86 MB, 2855560 bytes
MD5: 8d71fb862b8b1cc8cd182b281cbf473e
SHA1: 51d89e5df160d052f30cee7fd509d551225488d4
SHA256: D61282F7D90A6C3C3E5D883B43AEF8B715863DA7E19F9469F6E5F020CDF0FC0B
File Size: 473.67 KB, 473667 bytes
MD5: 3681ee646eb0de915a26a74bc8b4971c
SHA1: 31e7e0f9667f00ea69d1e697a60225fbe9415238
SHA256: A36013F6D57B5FF80C609FFD89C61EEA8A6A15F81B893DE40BF94C465C286AAC
File Size: 2.39 MB, 2393664 bytes
MD5: eee0046f4f4d2241b80bec9b30b05741
SHA1: 92e8149dd07ae68f3bd9852304b904bded9a049d
SHA256: 0E0BB034855945FE207A781A8725F4911D7A912B2BFE5FDE1DF5E775424F5EAE
File Size: 2.89 MB, 2894472 bytes
MD5: 9942bd633937989fa63ac96b646954f3
SHA1: 9b2264a5625e69657a8ea53f5f5073a38f5a326a
SHA256: B976E4207CCE259CC47E3E41210B5B13D3E0B02B4E7647AD1805C898FF8076EB
File Size: 2.45 MB, 2454624 bytes
MD5: 6d9f5c1da256dffdce52d5d223d66a84
SHA1: ef7250e0ee497f0e6b12f74c92fe5550bd738408
SHA256: 859389CDB7C9C3764F9E068DCF79629B8C8322AB1F36A585BDBF1D35BA31BBE7
File Size: 4.05 MB, 4054592 bytes
MD5: aca4acf8037a8ab1f7cc0316b19867a5
SHA1: 77276fe6d558bd28c0d5a39046e60e3f09baa467
SHA256: E3D16951DEAC336FC9D82666CCE322B5AB9A493D9716D9AB484CF16CAEF52286
File Size: 1.93 MB, 1927224 bytes
MD5: 4a9856729d94e9d1139a9adad528a796
SHA1: 47c7f39b4081c0b316a745fa6c05496443a5d548
SHA256: 1F3AE824120BBBA1A359513775229D6D4235CA38C38A3135F71152B5A35DF475
File Size: 4.05 MB, 4054736 bytes
MD5: 70ef83fbe5081a4a298e29a110fd7564
SHA1: ba7cd60517536c5b68e8ed9b40e21f1889ceba41
SHA256: 941F7EF682D0C676AF62923BD2210166238469DD290B8A3CE2F785C1613FAA08
File Size: 4.06 MB, 4063240 bytes
MD5: ab2d69b27ccd7fbe9cfcfa666d8863aa
SHA1: 11d6a666e1fdcdeee966c2d18e4afdb099d72478
SHA256: 89DF1874342B633F0A5A93B933B4241075F7B8AEA1FF0455A1FEDD6007F73E99
File Size: 1.62 MB, 1617245 bytes
MD5: 30e2848e86601701d8c5df12a84562c6
SHA1: 8185ba974e58b465a006dafcd207f8517d00d159
SHA256: 0D4D33CE993DD0E4C3F891D278DAB9049485A5BB9213881390796FED9417D090
File Size: 1.37 MB, 1367664 bytes
MD5: bbe8c4750680f699f56c1713710427b4
SHA1: abfa8c271db62baccc46014321dbf10683a99164
SHA256: D4A5535D754E443843FA9C7BEBED9C9BE43F1BA0C57CB13CE2832B81C2EE87CB
File Size: 2.42 MB, 2416216 bytes
MD5: a8e3d2563df652405a4c29a734376439
SHA1: 2a435184f32cd2cfde2d2e9bddd5647007c49c5c
SHA256: FDD1AFEB298C72873D9C3FA208DA376FA3FAEEFCA033F867629C2BF9EA9E22F0
File Size: 473.67 KB, 473667 bytes
MD5: 6509b1c7a3c450a0036b8c9f6f80fa34
SHA1: aaca7ed7e4c5f066925f7965cb12ef838d35021d
SHA256: 4E62F9469218323EAB43A27FE738C7108D43F09BD58992A2097E21DC724236FF
File Size: 534.07 KB, 534072 bytes
MD5: 8f2400fdf53a8bbdf2d3ee752cb15587
SHA1: 7a6b9d11cedb2a09f907bfe73e6d6bd97fa23a86
SHA256: 28F0CC3DCE3EF774D638488EEB1E3802E23B2ECA73292BF55E0DFE5BD69FC144
File Size: 526.90 KB, 526904 bytes
MD5: 0cc8363973a344db450419c68bcc69b5
SHA1: 46b81b98b7cf8f397736468110f076dca0e03a1f
SHA256: ED01EDC6DC29BDCD5B04706DC74614EAD5A5472A6EF75A94A0EF597DF195A8F8
File Size: 58.94 KB, 58944 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
Show More
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Assembly Version
  • 2.1.0.71
  • 2.0.0.42
  • 2.0.0.38
  • 1.8.0.23
  • 1.6.0.24
  • 1.1.0.6
  • 1.0.0.6
Comments
  • PCHelperAISetup
  • Protect Your Identity with Email Protector
  • This installation was built with Inno Setup.
Company Name
  • Hawk Integrated Inc
  • Mainstay Crypto LLC
  • Secure PC
  • Secure PC Software LLC
  • The libjpeg-turbo Project
File Description
  • Browser Fixer
  • BuyBricksSetup
  • CameraShieldAISetup
  • Email Protector
  • EmailProtector.Utils
  • InstallRecipe
  • Optimal Converter Setup
  • Optima PDF
  • PCHelperAISetup
  • PDF Maestro
Show More
  • PDF Proton
  • PDF_Spark Setup
  • TurboJPEG API DLL
File Version
  • 2.1.0.71
  • 2.0.0.42
  • 2.0.0.38
  • 2.0.0.1
  • 1.8.0.23
  • 1.7.7.21
  • 1.6.0.24
  • 1.4.9.16
  • 1.3.2.2
  • 1.1.0.6
Show More
  • 1.0.0.9
  • 1.0.0.6
  • 0,4,0,0
Internal Name
  • BrowserFixer.exe
  • BuyBricksAISetup.exe
  • CameraShieldAISetup.exe
  • EmailProtector.exe
  • EmailProtector.Utils.dll
  • PCHelperAISetup.exe
  • PDFMaestro.exe
  • turbojpeg
Legal Copyright
  • Copyright Hawk Integrated Inc 2025
  • Copyright © 1991-2024 The libjpeg-turbo Project and many others
  • Copyright © 1991-2025 The libjpeg-turbo Project and many others
  • Copyright © 2025
  • Mainstay Crypto LLC 2025
Original Filename
  • BrowserFixer.exe
  • BuyBricksAISetup.exe
  • CameraShieldAISetup.exe
  • EmailProtector.exe
  • EmailProtector.Utils.dll
  • PCHelperAISetup.exe
  • PDFMaestro.exe
  • turbojpeg.dll
Product Name
  • BrowserFixer
  • BuyBricksSetup
  • CameraShieldAISetup
  • EmailProtector
  • EmailProtector.Utils
  • InstallRecipe
  • libjpeg-turbo
  • Optimal Converter
  • Optima PDF
  • PCHelperAISetup
Show More
  • PDFMaestro
  • PDF Proton
  • PDF_Spark
Product Version
  • 3.1.2
  • 3.1.0
  • 2.1.0.71
  • 2.0.0.42
  • 2.0.0.38
  • 1.8.0.23
  • 1.7.7.21
  • 1.6.0.24
  • 1.4.9.16
  • 1.1.0.6
Show More
  • 1.0.0.9
  • 1.0.0.6

Digital Signatures

Signer Root Status
Secure PC Software LLC DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
Rush Delivery, LLC GlobalSign GCC R45 EV CodeSigning CA 2020 Self Signed
Mainstay Crypto LLC Microsoft Identity Verification Root Certificate Authority 2020 Root Not Trusted
Secure PC Software LLC SSL.com EV Code Signing Intermediate CA RSA R3 Self Signed
APP Craftsmen LLC Sectigo Public Code Signing Root R46 Root Not Trusted
Show More
Smart Contract LLC Sectigo Public Code Signing Root R46 Root Not Trusted

File Traits

  • 2+ executable sections
  • Inno
  • InnoSetup Installer
  • Installer Manifest
  • Installer Version
  • nosig nsis
  • Nullsoft Installer
  • VirtualQueryEx
  • x86

Block Information

Total Blocks: 94
Potentially Malicious Blocks: 6
Whitelisted Blocks: 41
Unknown Blocks: 47

Visual Map

0 ? 0 0 ? ? 0 0 0 0 0 x 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? 0 0 x x 0 x x ? 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 ? ? 0 x ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Brute.BHA
  • Chapak.HBX
  • CobaltStrike.GI
  • CobaltStrike.GIA
  • Injector.FFA
Show More
  • MSIL.MediaArena.K
  • MSIL.TelegramBot.S
  • MSIL.TelegramBot.T
  • MSILZilla.TC
  • Trojan.Agent.Gen.VN
  • Trojan.Injector.Gen.GVK
  • Trojan.Injector.Gen.GVL

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\sb\bb\installconfig.txt Generic Write,Read Attributes
c:\users\user\appdata\local\sb\bb\metadata.txt Generic Write,Read Attributes
c:\users\user\appdata\local\sb\cm\installconfig.txt Generic Write,Read Attributes
c:\users\user\appdata\local\sb\cm\metadata.txt Generic Write,Read Attributes
c:\users\user\appdata\local\sb\cm\systeminfo.txt Generic Write,Read Attributes
c:\users\user\appdata\local\sb\ph\installconfig.txt Generic Write,Read Attributes
c:\users\user\appdata\local\sb\ph\metadata.txt Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\3bb504e0-4f89-11d3-9a0c-0305e82c33lulp\bb\appsettings.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\3bb504e0-4f89-11d3-9a0c-0305e82c33lulp\bbinstaller.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\3cmfc1d58-f4a6-44cc-97e7-9637516da167d2w\camerashieldaisetup.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\3cmfc1d58-f4a6-44cc-97e7-9637516da167d2w\cm\appsettings.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\89fc1d58-f4a6-44cc-97e7-9637516da167ax05\ph\appsettings.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\89fc1d58-f4a6-44cc-97e7-9637516da167ax05\phinstaller.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bb09561d420844ffb050b8378eb0acd3\pchelperai.installerupdaterlib.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bb09561d420844ffb050b8378eb0acd3\pchelperai.installerupdaterlib.dll.lock Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\is-2d7gi.tmp\ba7cd60517536c5b68e8ed9b40e21f1889ceba41_0004063240.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-4vcha.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-4vcha.tmp\physfs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-crm3t.tmp\ef7250e0ee497f0e6b12f74c92fe5550bd738408_0004054592.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-d932l.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-d932l.tmp\physfs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-femh4.tmp\47c7f39b4081c0b316a745fa6c05496443a5d548_0004054736.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-lvfsd.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-lvfsd.tmp\physfs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsi777b.tmp\banner.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsi777b.tmp\blosc2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsi777b.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsk2c27.tmp\banner.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsk2c27.tmp\blosc2.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsk2c27.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr764f.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsr7660.tmp\banner.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr7660.tmp\nsisunz.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr7660.tmp\recipelocale.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nss776a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsu2c16.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\~nsua.tmp\un_a.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\sb\ph::instanceid 765e0d61-c34f-4cd9-818d-9afb014ee068 RegNtPreCreateKey
HKCU\software\sb\ph::macid 42c4b0e3-fc98-141c-9afb-f4c8996fb924 RegNtPreCreateKey
HKCU\software\sb\ph::firstlaunchdate 2026-03-09 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKCU\software\sb\bb::instanceid 7667ae7d-2e97-4be6-9568-f80ad832fce5 RegNtPreCreateKey
HKCU\software\sb\bb::macid 42c4b0e3-fc98-141c-9afb-f4c8996fb924 RegNtPreCreateKey
HKCU\software\sb\bb::firstlaunchdate 2026-03-15 RegNtPreCreateKey
HKCU\software\sb\cm::instanceid 6aa5a2a8-bfa9-4661-947b-433300317e7c RegNtPreCreateKey
HKCU\software\sb\cm::macid 42c4b0e3-fc98-141c-9afb-f4c8996fb924 RegNtPreCreateKey
HKCU\software\sb\cm::firstlaunchdate xT�� RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKCU\software\sb\cm::countrycode UNK RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ?m�8�1tX�jg �� �6 �v xy ����T������1��dc�%���5����3bBx�<��%��R �7!wz#�#��$kF%:�%`�%�&� &�-'�(�(X�(�)A)�`*J*9*�"*�h+��,��-!R0P%1`1�1HO1�D5,]9ߔ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 @m�8�1tX�jg �� �6 �v xy ����T������1��dc�%���5����3bBx�<��%��R �7!wz#�#��$kF%:�%`�%�&� &�-'�(�(X�(�)A)�`*J*9*�"*�h+��,��-!R0P%1`1�1HO1�D5,]9ߔ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 @m�8�1tX�jg �� �6 �v xy ����T������1��dc�%���5����3bBx�<��%��R �7!wz#�#��$kF%:�%`�%�&� &�-'�(�(X�(�)A)�`*J*9*�"*�h+��,��-!R0P%1`1�1HO1�D5,]9ߔ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Am�8�1tX�jg �� �6 �v xy ����T������1��dc�%���5����3bBx�<��%��R �7!wz#�#��$kF%:�%`�%�&� &�-'�(�(X�(�)A)�`*J*9*�"*�h+��,��-!R0P%1`1�1HO1�D5,]9ߔ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 m�8�tXjg �� �6 �v ��T���������%��3bBx%��R!wz#��$kF%:�%`�%�&� (�(X�(�)�`*J*9*�"-!R1�1HO5,];�4>3�@V�B��FH�G�IH[uH�pH��J��N$U_*a$b"hc�wc�zh�ri��j�bk`k�ql(�q@� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 m�8�tXjg �� �6 �v ��T���������%��3bBx%��R!wz#��$kF%:�%`�%�&� (�(X�(�)�`*J*9*�"-!R1�1HO5,];�4>3�@V�B��FH�G�IH[uH�pH��J��N$U_*a$b"hc�wc�ze�vh�ri��j�bk`k�ql(� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �� �v����(�*�"1�1HO@V�H[u_�zb"hc�wk�q{b��P������������m��V����$�8წ����=�S)�B1_T�Vw�`�V�`���%�������AE��"��D��&��$���LA*�" RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �nS� �v �Z xyT������5��!wz%:�&� (�(X�/9�1`1�1HO1�D9ߔ>3�@V�H[uH�pJ��R20V �X�_�z`�2i��k`k�ql(�n�ArnJtǤu�~{b�{�=���P��{�ރ�/������7����b:�������X������6��T��h �T���. RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Service Control
  • OpenSCManager
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Network Winsock2
  • WSAConnect
  • WSASend
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • bind
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcDisconnectPort
  • ntdll.dll!NtAlpcQueryInformation
Show More
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject

21 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Keyboard Access
  • GetKeyState

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\699e41de3393c9509ceef07a2ddc3d4599f01ae8_0002966000.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\23180e8671cf435bc244a8d9eb1e2ddbd3b02534_0002855560.,LiQMAxHB
"C:\Users\Blqkerew\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\92e8149dd07ae68f3bd9852304b904bded9a049d_0002894472.,LiQMAxHB
"C:\Users\Ydtckiks\AppData\Local\Temp\is-CRM3T.tmp\ef7250e0ee497f0e6b12f74c92fe5550bd738408_0004054592.tmp" /SL5="$9040C,1366435,867840,c:\users\user\downloads\ef7250e0ee497f0e6b12f74c92fe5550bd738408_0004054592"
Show More
"C:\Users\Szktldre\AppData\Local\Temp\is-FEMH4.tmp\47c7f39b4081c0b316a745fa6c05496443a5d548_0004054736.tmp" /SL5="$140324,1366435,867840,c:\users\user\downloads\47c7f39b4081c0b316a745fa6c05496443a5d548_0004054736"
"C:\Users\Mvqnpynz\AppData\Local\Temp\is-2D7GI.tmp\ba7cd60517536c5b68e8ed9b40e21f1889ceba41_0004063240.tmp" /SL5="$180380,1363651,867840,c:\users\user\downloads\ba7cd60517536c5b68e8ed9b40e21f1889ceba41_0004063240"
"C:\Users\Cpybdnts\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\