Threat Database Trojans Trojan.Agent.ENA

Trojan.Agent.ENA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 359
Threat Level: 80 % (High)
Infected Computers: 9,258
First Seen: July 5, 2024
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.ENA on your system indicates a potential security threat. This type of malware is designed to compromise the security of your computer, allowing unauthorized access to your personal data and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Trojan.Agent.ENA?

Trojan.Agent.ENA is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan.Agent.ENA" suggests that it is a type of agent-based malware, but without more specific information, it is difficult to determine its exact characteristics or behavior. Trojan horses often exploit vulnerabilities in software or operating systems to gain unauthorized access to a computer system.

How Trojan.Agent.ENA Operates

Like other types of Trojan horses, Trojan.Agent.ENA likely operates by disguising itself as a legitimate program or file, allowing it to evade detection by security software. Once installed on a system, it may attempt to connect to a command and control server to receive instructions from its creators or to transmit stolen data. Trojan horses can also create backdoors, allowing hackers to access the infected system remotely. The exact mechanisms used by Trojan.Agent.ENA are unknown, but its behavior is likely similar to that of other Trojan horses.

Symptoms of Infection

Systems infected with Trojan.Agent.ENA may exhibit a range of symptoms, including unusual network activity, slow system performance, and unexplained changes to system settings. You may also notice unfamiliar programs or files on your system, or receive unexpected pop-ups or alerts. In some cases, the malware may not produce any noticeable symptoms, making it difficult to detect without the use of security software.

  • Unexplained system crashes or freezes
  • New, unfamiliar icons or programs on your desktop or in your system tray
  • Changes to your browser settings or homepage
  • Unusual network activity, such as unexpected incoming or outgoing connections

How to Remove Trojan.Agent.ENA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your knowledge or consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Agent.ENA from your system requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above and using reputable security software, you can help protect your system and your personal data from the threats posed by this type of malware. It is also essential to take steps to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus protection, and avoiding suspicious downloads or email attachments.

Analysis Report

General information

Family Name: Trojan.Agent.ENA
Signature status: No Signature

Known Samples

MD5: 0aa7bedfcaff37ec3869f0847c6490a0
SHA1: b27fda4e652590dd110dc1c32abee4d8c084e9d3
File Size: 7.64 MB, 7638016 bytes
MD5: 3f7ac3831a7a4d231634dc5165400865
SHA1: f1f7e01c2c788d37440cf0c16c177fa13e7c8710
SHA256: A3161E0FEAA4942080E3A38E6030A9CF1609EEF863AD366172D3196F2316D0EB
File Size: 7.77 MB, 7771992 bytes
MD5: 32220f80a3e868ac505bc6e422c61ee5
SHA1: 9c9c6e9555b229a1687b9f0b836f2f4cf95d8666
SHA256: 9EE8CAA5F90F42D62D843AF18D75AFCE8600CCDED0F496A5EEFE629444F6BD7F
File Size: 7.85 MB, 7850080 bytes
MD5: 081093404258133ed30d27c63679a739
SHA1: e5104761d1e7d5cc4bbf386736edad7c6c0eb00e
SHA256: 176816F4D19A67DD571971E26056B760F3D7BA1FD7B03880A0A42A377E27A3BA
File Size: 6.54 MB, 6539380 bytes
MD5: f850354ffd241471d59271f95c977a51
SHA1: 1f19f7d3e3464c509506cd0acd24b63e26d086be
SHA256: 6053C74D0DFDFAA678D5162E5B756E75F72A519FE0D5709CC2175C3839698D2F
File Size: 5.95 MB, 5950617 bytes
Show More
MD5: 9465bd99fe47ce6b1d54b1aeb7f75bdf
SHA1: 7ae4e8ba6a76d3b59ac0819130b66865bccbc0e7
SHA256: A45BF46EC512AD2E52ED4E77842BF5351B53E5670CF2F311022148071CAADA92
File Size: 6.84 MB, 6837824 bytes
MD5: 9406991027661844a872d4caa36c4656
SHA1: 5e4bfa0ae2bedd70f6d3a417eaad55ea5254658a
SHA256: 56C37054D0ECE2B290244182F569B108169CA7C56BAA6807F8D27EC5DE3E810A
File Size: 8.41 MB, 8409600 bytes
MD5: 6603adf1281c091cbc2a32e51b2c1ddd
SHA1: e98b1289af03fbf0a95f72b3ccfebe8e3aacad36
SHA256: 9935969220C861623C6B6D8DF2BF08ABA73863F2BA4CC0995AE29D248D7F0B50
File Size: 7.64 MB, 7638016 bytes
MD5: 6e0926861fc966016faaeb74e1a16a5d
SHA1: 7b5898e8a10b406c5f883331843017906009460d
SHA256: DC74316F673AE30E2131A7253C6C7C0D5069E39FC9C0099031B7B9EF29CB507F
File Size: 7.64 MB, 7638064 bytes
MD5: 6bbf188a102ea67241c55426947832a7
SHA1: befe0b37dabce9e7b06889af5cab81b9368c0f74
SHA256: 5E8170A3EDC0F06DA9EC6215A4595A072DD99C268342920BEE263398A73EC243
File Size: 2.58 MB, 2584576 bytes
MD5: 054d17927ff01b37330934246a3f1f5e
SHA1: f271d66ed7ccfb7bd0e7f3f3c918b611288ae3d9
SHA256: 9D3A97DF30D09B450BEEBF69C37A6F271C7A4A916857950B2D9CE03C3DC62AFE
File Size: 7.64 MB, 7638064 bytes
MD5: e1dc250fa8c14e6073ef038b3b983be1
SHA1: 0beae32a73b424fd4c1580938a2c010c26141483
SHA256: ED421BF73FCA41F958B6938905AB50788E5C8AD85B18CD9B7A64A11A0F0A2227
File Size: 7.64 MB, 7638064 bytes
MD5: da470bb4467cc487cc0131bead628b76
SHA1: 49fb6744b95f93c984a2bf2224f4d02c90306769
SHA256: B0EFF3EAC5177A10AB441498665E822A1A7FD8CD51F276BE645BCC450E3097E7
File Size: 4.69 MB, 4689920 bytes
MD5: 0f71a9fa38b3363951dee8ad4c481453
SHA1: 0742d2e056a9465d07b019e02461665b047dc275
SHA256: 5BC1ECC09BBF5FFFEDC2D90C4EB2D6BFA0365E657A766016097C50CF139EE924
File Size: 4.81 MB, 4812288 bytes
MD5: 5ae164c9879e077d0bba068af57baddf
SHA1: 6ff23c128c45cf9347af2250f393997389f735b0
SHA256: 8B5289DEDD4462BE59CFC97B54510EACA5A6492FE15FE4283EE4F8E4BFB709D7
File Size: 7.64 MB, 7638064 bytes
MD5: bda7e08e0524fd0d6963c37f4dc0fe6b
SHA1: 683053a23efdd2261d07ebb8ec2a4fe03dd12d2e
SHA256: 6D6849C67530D39F3467CF6A23B9AE66C9AF6EEBF4E4A194C77F60BF06CDDE5F
File Size: 7.64 MB, 7638016 bytes
MD5: e3bd06717d715433cfeada5856deace2
SHA1: 072e4466b5eb7ae8058e4b3bf28194684afb665a
SHA256: 6B59664EF0BE1D9DC588A539BCD8A27C8C4DF18B6823E0DCECAA4BB3714A23D4
File Size: 7.64 MB, 7638064 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • DirtyHarry Unattendeds
  • Wicked
Company Name
  • Adobe Inc.
  • Microsoft
  • Microsoft Corporation
  • Synaptics
File Description
  • Adobe Installer
  • DirtyHarry Unattendeds
  • Synaptics Pointing Device Driver
  • Wicked
  • Win32 Cabinet Self-Extractor
File Version
  • 11.00.19041.1 (WinBuild.160101.0800)
  • 6.6.0.611
  • 5.9.0.372
  • 5.7.1.1
  • 5.3.1.470
  • 3.3.16.1
  • 1.00
  • 1.0.0.4
Internal Name
  • Adobe Installer
  • TJprojMain
  • Wextract
  • Win
Legal Copyright
  • © 2020 Adobe. All rights reserved.
  • © 2020-2022 Adobe. All rights reserved.
  • © 2020-2025 Adobe. All rights reserved.
  • © DirtyHarry Unattendeds 2020
  • © Microsoft Corporation. All rights reserved.
  • ©Wicked
Original Filename
  • Adobe Installer
  • TJprojMain.exe
  • WEXTRACT.EXE .MUI
  • Win.exe
Product Name
  • Adobe Installer
  • Internet Explorer
  • Project1
  • Synaptics Pointing Device Driver
  • Win
Product Version
  • 11.00.19041.1
  • 6.6.0.611
  • 5.9.0.372
  • 5.7.1.1
  • 5.3.1.470
  • 3.3.16.1
  • 1.00
  • 1.0.0.0

Digital Signatures

Signer Root Status
Adobe Inc. DigiCert EV Code Signing CA (SHA2) Hash Mismatch

File Traits

  • CryptUnprotectData
  • dll
  • GetConsoleWindow
  • Installer Version
  • No Version Info
  • x86

Block Information

Total Blocks: 9,024
Potentially Malicious Blocks: 2,006
Whitelisted Blocks: 7,018
Unknown Blocks: 0

Visual Map

x x x x x x 0 0 x 0 0 x x 0 0 x x 0 0 x x x 0 0 x 0 0 x x 0 x 0 x x 0 0 0 0 0 x 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x 0 0 0 x x x x x x x x 0 x 0 x x 0 x x x x x x x 0 0 0 x x x x x 0 0 0 x 0 x x 0 x x x x x 0 x x x 0 x 0 x 0 x x x x x x 0 x 0 x x x 0 0 0 x x 0 x 0 x 0 0 x x 0 0 x x x x x x x x 0 x x x x x x x x x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 x 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 x x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 x x x x x x 0 0 x x x x x x 0 x x 0 0 x x 0 x 0 x x x 0 x x 0 x 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 x x x x x x x x x 0 x 0 x 0 0 0 0 x x x x x 0 x x x 0 0 x 0 0 0 x 0 0 x 0 x 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 x x 0 x x x x x x 0 0 x x x x x x x x x 0 x x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x x 0 x x x x x 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 x x 0 x 0 x 0 0 0 x x x 0 x x x 0 0 0 0 0 0 x 0 x x 0 0 0 x 0 x x x 0 x 0 x 0 x x x 0 0 0 0 x 0 0 0 0 0 0 x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x x x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 x 0 x x 0 x 0 x 0 x x x x x 0 x 0 x 0 x x 0 0 0 x x 0 x x x 0 0 0 x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x x 0 0 0 x x x 0 0 0 x 0 0 0 x 0 x 0 x 0 x 0 x x x x x 0 0 0 0 x 0 x 0 x x x 0 x x x 0 x x 0 x 0 x 0 0 x 0 0 0 0 0 x 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 x x x x x x x x 0 0 x x x x x x 0 x x x x 0 x x x 0 x 0 x x x x 0 0 0 x x 0 x 0 x 0 0 x 0 0 x 0 0 x 0 x 0 x x x x 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 x 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 x 0 0 x 0 0 x 0 x x x x 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 x x x 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 x x 0 0 0 0 0 0 x x x 0 x 0 0 0 x x x 0 x x x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 x x x x 0 x x x x 0 x 0 x 0 x x 0 x x x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 x x x x x 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 x x x x x x x x x x 0 0 x x x x x 0 0 0 0 0 x x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 x x 0 0 0 x 0 0 x 0 x 0 x 0 0 x 0 0 x x x x x x x x 0 0 0 x x x x x x 0 0 x 0 0 x 0 x 0 x x x 0 x x x x x x 0 x x 0 x 0 x 0 x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 0 x x x x x x x x x x 0 x x x x x x 0 0 0 0 x x x x x x 0 x x x 0 0 x x x x x 0 0 0 x 0 0 x 0 x x x x 0 0 0 0 x 0 0 x 0 0 0 x x x x 0 0 x x x 0 x 0 0 x x x x 0 x 0 0 x x 0 x x x 0 0 0 0 x 0 0 x 0 0 0 x x 0 x 0 x 0 x 0 x 0 x 0 0 0 x 0 x 0 0 x 0 x 0 x 0 x 0 x 0 0 x x x 0 0 0 0 0 0 x 0 0 0 x x x x x 0 x x x x x 0 0 x x 0 x 0 x x x 0 x 0 x 0 x x x x x 0 0 x 0 0 x 0 x 0 0 0 x x x 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 x x x x 0 0 x x 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 x 0 x x x 0 0 x 0 0 x x 0 0 0 0 0 0 0 x x 0 x x x x 0 0 x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.ENA
  • Agent.FDGD
  • Tedy.L

Files Modified

File Attributes
c:\ibinstaller_98220.exe Generic Write,Read Attributes
c:\program files\windows nt\accessories\install\adobe_block.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows nt\accessories\install\adobe_block.bat Generic Write,Read Attributes
c:\program files\windows nt\accessories\install\netoff.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\program files\windows nt\accessories\install\netoff.cmd Generic Write,Read Attributes
c:\program files\windows nt\accessories\install\neton.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\program files\windows nt\accessories\install\neton.cmd Generic Write,Read Attributes
c:\program files\windows nt\accessories\install\set-up.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows nt\accessories\install\set-up.exe Generic Write,Read Attributes
c:\program files\windows nt\accessories\install\skull2.gif Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
Show More
c:\program files\windows nt\accessories\install\skull2.gif Generic Write,Read Attributes
c:\program files\windows nt\accessories\install\white.gif Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\program files\windows nt\accessories\install\white.gif Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut373e.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut38e5.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3a1f.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3a2f.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3a40.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut4354.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut45a7.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\creativecloud\acc\adobedownload\hdinstaller.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\set-up.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\set-up.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\set-up.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp000.tmp\uac.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\uac.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\uac.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsx8e83.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsx8e83.tmp\execcmd.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsx8e83.tmp\execcmd.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsx8e83.tmp\nsisdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsx8e83.tmp\nsisdl.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~dfa58816686bb45fd5.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~dfd250d51e5d6d9395.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation::b27fda4e652590dd110dc1c32abee4d8c084e9d3_0007638016.exe RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation::7b5898e8a10b406c5f883331843017906009460d_0007638064 RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Mdbwkchn\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 未ﳝ쁽ǜ RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation::set-up.exe RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation::0beae32a73b424fd4c1580938a2c010c26141483_0007638064 RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 픿卻풙ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 騔厀풙ǜ RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation::6ff23c128c45cf9347af2250f393997389f735b0_0007638064 RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLockFile
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryTimerResolution
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnlockFile
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ZwMapViewOfSection
Process Shell Execute
  • CreateProcess
  • WriteConsole
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • gethostbyname
  • inet_addr
  • send
  • socket
Process Terminate
  • TerminateProcess
Keyboard Access
  • GetAsyncKeyState

Shell Command Execution

C:\Users\Mdbwkchn\AppData\Local\Temp\IXP000.TMP\UAC.exe
"\IBInstaller_98220.exe"/VERYSILENT /PASSWORD=kSWIzY9AFOirvP3TueIs98220 -token mtn1co3fo4gs5vwq -subid 1878
C:\WINDOWS\system32\cmd.exe /C "\IBInstaller_98220.exe" /VERYSILENT /PASSWORD=kSWIzY9AFOirvP3TueIs98220 -token mtn1co3fo4gs5vwq -subid 1878
WriteConsole: '\IBInstaller_98
C:\Users\Mdbwkchn\AppData\Local\Temp\IXP000.TMP\Set-up.exe
Show More
C:\Program Files\Windows NT\Accessories\install\Set-up.exe --silent --ADOBEINSTALLDIR=C:\InstallDir --INSTALLLANGUAGE=nl_NL
C:\Program Files\Windows NT\Accessories\install\NETOFF.cmd
C:\WINDOWS\system32\netsh.exe netsh interface set interface "Ethernet" admin=disable

Trending

Most Viewed

Loading...