Qukart.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,939
Threat Level: 80 % (High)
Infected Computers: 142
First Seen: March 10, 2020
Last Seen: June 15, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Qukart.A
Signature status: No Signature

Known Samples

MD5: bc37ebdb5ea6db8b460f74a4b2e74c9f
SHA1: 70acc66ffdf1dbc22ed171fc1985fba39871adff
SHA256: 1BDF0C3B80E8E507094AFD8C1FCB13181B880AC166EADE47A11034515C8AFAF0
File Size: 89.62 KB, 89625 bytes
MD5: 72b82dc39aecb5d74e844351eac6595c
SHA1: cbdae5df3968566be73afc0570948ea14b1f9553
SHA256: 0BA3397133EC167C5B9D17C21D6F6CC2E1FF9FAABA86862EBA4726F5216B24EF
File Size: 60.46 KB, 60458 bytes
MD5: 21a475ab7e141698c7aa493ce4664926
SHA1: 03e2c74717808825957b15b978a37ec810d366a0
SHA256: 03D495EE6BE0FED8B2561430FCA0B6C4D05165004798EED66D3E5058D2F0691A
File Size: 71.19 KB, 71194 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 1
Potentially Malicious Blocks: 1
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Files Modified

File Attributes
c:\windows\syswow64\aakbjo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\aakbjo32.exe Generic Write,Read Attributes
c:\windows\syswow64\aanopo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\aanopo32.exe Generic Write,Read Attributes
c:\windows\syswow64\abbfli32.dll Generic Write,Read Attributes
c:\windows\syswow64\acgbakgk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\acgbakgk.exe Generic Write,Read Attributes
c:\windows\syswow64\acmfppob.dll Generic Write,Read Attributes
c:\windows\syswow64\adfkaq32.dll Generic Write,Read Attributes
c:\windows\syswow64\afcaggib.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
Show More
c:\windows\syswow64\afcaggib.exe Generic Write,Read Attributes
c:\windows\syswow64\ahakcfop.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ahakcfop.exe Generic Write,Read Attributes
c:\windows\syswow64\ahchhfmm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ahchhfmm.exe Generic Write,Read Attributes
c:\windows\syswow64\ahjebgeh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ahjebgeh.exe Generic Write,Read Attributes
c:\windows\syswow64\ahlbhg32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ahlbhg32.exe Generic Write,Read Attributes
c:\windows\syswow64\ahlfhakl.dll Generic Write,Read Attributes
c:\windows\syswow64\aidaooaa.dll Generic Write,Read Attributes
c:\windows\syswow64\aipanb32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\aipanb32.exe Generic Write,Read Attributes
c:\windows\syswow64\ajfdidkc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ajfdidkc.exe Generic Write,Read Attributes
c:\windows\syswow64\ajjbjk32.dll Generic Write,Read Attributes
c:\windows\syswow64\aljknejl.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\aljknejl.exe Generic Write,Read Attributes
c:\windows\syswow64\ammgqimq.dll Generic Write,Read Attributes
c:\windows\syswow64\anckpcee.dll Generic Write,Read Attributes
c:\windows\syswow64\andjdd32.dll Generic Write,Read Attributes
c:\windows\syswow64\apncjokn.dll Generic Write,Read Attributes
c:\windows\syswow64\bahpel32.dll Generic Write,Read Attributes
c:\windows\syswow64\bbahmg32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bbahmg32.exe Generic Write,Read Attributes
c:\windows\syswow64\bdhkhiii.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bdhkhiii.exe Generic Write,Read Attributes
c:\windows\syswow64\bedppepo.dll Generic Write,Read Attributes
c:\windows\syswow64\befhle32.dll Generic Write,Read Attributes
c:\windows\syswow64\bfdknd32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bfdknd32.exe Generic Write,Read Attributes
c:\windows\syswow64\bgclkhlf.dll Generic Write,Read Attributes
c:\windows\syswow64\bhfenekj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bhfenekj.exe Generic Write,Read Attributes
c:\windows\syswow64\bhmfaplo.dll Generic Write,Read Attributes
c:\windows\syswow64\bhogddcp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bhogddcp.exe Generic Write,Read Attributes
c:\windows\syswow64\bjgmlb32.dll Generic Write,Read Attributes
c:\windows\syswow64\bjmjicek.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bjmjicek.exe Generic Write,Read Attributes
c:\windows\syswow64\blcmddaa.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\blcmddaa.exe Generic Write,Read Attributes
c:\windows\syswow64\blffjg32.dll Generic Write,Read Attributes
c:\windows\syswow64\blfjjcpn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\blfjjcpn.exe Generic Write,Read Attributes
c:\windows\syswow64\blflck32.dll Generic Write,Read Attributes
c:\windows\syswow64\blhgoc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\blhgoc32.exe Generic Write,Read Attributes
c:\windows\syswow64\bmecenje.dll Generic Write,Read Attributes
c:\windows\syswow64\bmiipo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bmiipo32.exe Generic Write,Read Attributes
c:\windows\syswow64\bpeifk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bpeifk32.exe Generic Write,Read Attributes
c:\windows\syswow64\bpfpfj32.dll Generic Write,Read Attributes
c:\windows\syswow64\bpmlph32.dll Generic Write,Read Attributes
c:\windows\syswow64\bqeola32.dll Generic Write,Read Attributes
c:\windows\syswow64\calkamhb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\calkamhb.exe Generic Write,Read Attributes
c:\windows\syswow64\cbbaddjk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cbbaddjk.exe Generic Write,Read Attributes
c:\windows\syswow64\cdckcgok.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cdckcgok.exe Generic Write,Read Attributes
c:\windows\syswow64\cfkqoc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cfkqoc32.exe Generic Write,Read Attributes
c:\windows\syswow64\cggjdgkd.dll Generic Write,Read Attributes
c:\windows\syswow64\cgjija32.dll Generic Write,Read Attributes
c:\windows\syswow64\chadjd32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\chadjd32.exe Generic Write,Read Attributes
c:\windows\syswow64\chdaoc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\chdaoc32.exe Generic Write,Read Attributes
c:\windows\syswow64\chfnecmh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\chfnecmh.exe Generic Write,Read Attributes
c:\windows\syswow64\chhjjcke.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\chhjjcke.exe Generic Write,Read Attributes
c:\windows\syswow64\chkgpb32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\chkgpb32.exe Generic Write,Read Attributes
c:\windows\syswow64\chmoki32.dll Generic Write,Read Attributes
c:\windows\syswow64\cigpfoen.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cigpfoen.exe Generic Write,Read Attributes
c:\windows\syswow64\claqao32.dll Generic Write,Read Attributes
c:\windows\syswow64\cngdqm32.dll Generic Write,Read Attributes
c:\windows\syswow64\cocmja32.dll Generic Write,Read Attributes
c:\windows\syswow64\cpfbniie.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cpfbniie.exe Generic Write,Read Attributes
c:\windows\syswow64\daancjfj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\daancjfj.exe Generic Write,Read Attributes
c:\windows\syswow64\dagkmkne.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dagkmkne.exe Generic Write,Read Attributes
c:\windows\syswow64\dapcfk32.dll Generic Write,Read Attributes
c:\windows\syswow64\dbqkmjjc.dll Generic Write,Read Attributes
c:\windows\syswow64\dcnapcpn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dcnapcpn.exe Generic Write,Read Attributes
c:\windows\syswow64\ddkkaf32.dll Generic Write,Read Attributes
c:\windows\syswow64\deblblaa.dll Generic Write,Read Attributes
c:\windows\syswow64\dfiaoefc.dll Generic Write,Read Attributes
c:\windows\syswow64\dginlbdi.dll Generic Write,Read Attributes
c:\windows\syswow64\diajkdjm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\diajkdjm.exe Generic Write,Read Attributes
c:\windows\syswow64\dicfpdhj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dicfpdhj.exe Generic Write,Read Attributes
c:\windows\syswow64\dicpan32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dicpan32.exe Generic Write,Read Attributes
c:\windows\syswow64\dijcjepe.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dijcjepe.exe Generic Write,Read Attributes
c:\windows\syswow64\dimppe32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dimppe32.exe Generic Write,Read Attributes
c:\windows\syswow64\diomee32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\diomee32.exe Generic Write,Read Attributes
c:\windows\syswow64\dkblkqbc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dkblkqbc.exe Generic Write,Read Attributes
c:\windows\syswow64\dklhoh32.dll Generic Write,Read Attributes
c:\windows\syswow64\dlfoml32.dll Generic Write,Read Attributes
c:\windows\syswow64\dpaaig32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dpaaig32.exe Generic Write,Read Attributes
c:\windows\syswow64\eacdpf32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eacdpf32.exe Generic Write,Read Attributes
c:\windows\syswow64\eahnkemk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eahnkemk.exe Generic Write,Read Attributes
c:\windows\syswow64\eammohlm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eammohlm.exe Generic Write,Read Attributes
c:\windows\syswow64\ecehhopd.dll Generic Write,Read Attributes
c:\windows\syswow64\eciqla32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eciqla32.exe Generic Write,Read Attributes
c:\windows\syswow64\edephp32.dll Generic Write,Read Attributes
c:\windows\syswow64\eemdkell.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eemdkell.exe Generic Write,Read Attributes
c:\windows\syswow64\efamfd32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\efamfd32.exe Generic Write,Read Attributes
c:\windows\syswow64\eflmij32.dll Generic Write,Read Attributes
c:\windows\syswow64\egbpfp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\egbpfp32.exe Generic Write,Read Attributes
c:\windows\syswow64\eifcfdfh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eifcfdfh.exe Generic Write,Read Attributes
c:\windows\syswow64\eilbhlce.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eilbhlce.exe Generic Write,Read Attributes
c:\windows\syswow64\eiojhjdp.dll Generic Write,Read Attributes
c:\windows\syswow64\ejdjhaon.dll Generic Write,Read Attributes
c:\windows\syswow64\ejfacidi.dll Generic Write,Read Attributes
c:\windows\syswow64\ekloaojh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ekloaojh.exe Generic Write,Read Attributes
c:\windows\syswow64\enjdbp32.dll Generic Write,Read Attributes
c:\windows\syswow64\epljof32.dll Generic Write,Read Attributes
c:\windows\syswow64\epmaee32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\epmaee32.exe Generic Write,Read Attributes
c:\windows\syswow64\fadkcnma.dll Generic Write,Read Attributes
c:\windows\syswow64\fafpegcb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fafpegcb.exe Generic Write,Read Attributes
c:\windows\syswow64\fakkpe32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fakkpe32.exe Generic Write,Read Attributes
c:\windows\syswow64\fanbomjg.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fanbomjg.exe Generic Write,Read Attributes
c:\windows\syswow64\fbjdle32.dll Generic Write,Read Attributes
c:\windows\syswow64\fbmgfd32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fbmgfd32.exe Generic Write,Read Attributes
c:\windows\syswow64\fdbplcei.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fdbplcei.exe Generic Write,Read Attributes
c:\windows\syswow64\ffphcllh.dll Generic Write,Read Attributes
c:\windows\syswow64\fgmgpj32.dll Generic Write,Read Attributes
c:\windows\syswow64\fgnobofo.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fgnobofo.exe Generic Write,Read Attributes
c:\windows\syswow64\fhhokk32.dll Generic Write,Read Attributes
c:\windows\syswow64\fhlhof32.dll Generic Write,Read Attributes
c:\windows\syswow64\fjaeji32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fjaeji32.exe Generic Write,Read Attributes
c:\windows\syswow64\fjhbck32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fjhbck32.exe Generic Write,Read Attributes
c:\windows\syswow64\fjjoij32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\fjjoij32.exe Generic Write,Read Attributes
c:\windows\syswow64\fkjgkn32.dll Generic Write,Read Attributes
c:\windows\syswow64\flmmle32.dll Generic Write,Read Attributes
c:\windows\syswow64\fnfgfp32.dll Generic Write,Read Attributes
c:\windows\syswow64\gafkci32.dll Generic Write,Read Attributes
c:\windows\syswow64\gbbljm32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gbbljm32.exe Generic Write,Read Attributes
c:\windows\syswow64\gbgapj32.dll Generic Write,Read Attributes
c:\windows\syswow64\gbgeelbm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gbgeelbm.exe Generic Write,Read Attributes
c:\windows\syswow64\gcfehd32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gcfehd32.exe Generic Write,Read Attributes
c:\windows\syswow64\gcncnn32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gcncnn32.exe Generic Write,Read Attributes
c:\windows\syswow64\gggbhm32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gggbhm32.exe Generic Write,Read Attributes
c:\windows\syswow64\ghochhnj.dll Generic Write,Read Attributes
c:\windows\syswow64\gjbjjnph.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gjbjjnph.exe Generic Write,Read Attributes
c:\windows\syswow64\gjpaiapi.dll Generic Write,Read Attributes
c:\windows\syswow64\gkkqcbmb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gkkqcbmb.exe Generic Write,Read Attributes
c:\windows\syswow64\gkmobc32.dll Generic Write,Read Attributes

226 additional files are not displayed above.

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Fhlhof32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Qpahhhdj.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Nbfajaqg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lbockjbn.dll RegNtPreCreateKey
Show More
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mamnih32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dginlbdi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Limmoc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ammgqimq.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Pclome32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Fbjdle32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ickkihbn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Nomkhgeg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Fgmgpj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mfjjpmko.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ddkkaf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ajjbjk32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Aidaooaa.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Kbodmojo.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ifgikp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Jqmgokpa.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Bpfpfj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Fadkcnma.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lbgnbngd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Nenfdf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Jecccn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mclieb32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ocfajiil.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Eiojhjdp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Cggjdgkd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Jomgdf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Gafkci32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Epljof32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Npeigjqd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Abbfli32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mncmifff.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ldaifiac.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Befhle32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Khndanpa.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Oihebg32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Pfabhh32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Oohoma32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dapcfk32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Jpgbhben.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Heplaieh.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Iiciejjk.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Bpmlph32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Nnqeqf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Jdggpa32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Hajcak32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Pjijac32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Bmecenje.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hhfnim32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ndbmea32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Npjclcnp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Pdcmanhd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Offqff32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Edephp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kdibkhhd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dlfoml32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Pigogdnc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ahlfhakl.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Bgclkhlf.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hbjknpbb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Anckpcee.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ibijnf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Nqmdji32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hkdpkogm.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dklhoh32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Npafbk32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Odejeclc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kiobka32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Adfkaq32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Acmfppob.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jbobebpc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Bqeola32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ppaqkl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kmhfhc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Deblblaa.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Fkjgkn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mjmgcd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Flmmle32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dfiaoefc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Andjdd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Cgjija32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hinpjk32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Chmoki32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kioqfheg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ecehhopd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Klglgf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ngocigbp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kmjahm32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dbqkmjjc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Blffjg32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Goehim32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Opibpi32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Gogmjebe.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mkbfdl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Odhdko32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ejdjhaon.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mbfgmkcg.dll RegNtPreCreateKey

42 additional registry modifications are not displayed above.

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

C:\WINDOWS\system32\Fbmgfd32.exe

Related Posts

Trending

Most Viewed

Loading...