Threat Database Trojans Trojan.Banker.YJ

Trojan.Banker.YJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 7,377
Threat Level: 80 % (High)
Infected Computers: 456
First Seen: August 3, 2023
Last Seen: July 7, 2026
OS(es) Affected: Windows

The detection of Trojan.Banker.YJ on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and potentially steal sensitive information. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Banker.YJ?

Trojan.Banker.YJ is a type of Trojan horse malware that can infect your computer through various means, such as downloading malicious software, opening infected email attachments, or visiting compromised websites. Once installed, it can hide in the background and perform malicious activities without your knowledge or consent. The name "Trojan.Banker" suggests that this malware may be focused on banking or financial information theft, but its capabilities can extend beyond this, potentially leading to a wide range of malicious activities.

How Trojan.Banker.YJ Operates

Trojan.Banker.YJ, like other Trojans, operates by disguising itself as legitimate software. It can create a backdoor on your system, allowing remote access to your computer. This backdoor can be used to download additional malware, steal sensitive information such as login credentials, credit card numbers, and personal data, or even use your computer as part of a botnet for malicious activities like DDoS attacks or spamming. The malware can also modify system settings, disable security software, and interfere with your internet browsing experience.

Symptoms of Infection

Identifying a Trojan.Banker.YJ infection can be challenging because it is designed to remain stealthy. However, some common symptoms may include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You might also notice changes in your browser settings, unexpected pop-ups, or redirects to suspicious websites. Additionally, if the malware is successful in stealing your banking information, you might notice unauthorized transactions or changes in your account settings.

How to Remove Trojan.Banker.YJ

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for a clean environment to perform removal steps.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help detect and remove all components of the Trojan.Banker.YJ malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are sure are malicious or unnecessary.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Banker.YJ requires careful and immediate action to prevent further damage to your system and to protect your sensitive information. By following the steps outlined above and maintaining good computer hygiene practices, such as regularly updating your operating system and security software, avoiding suspicious downloads, and being cautious with email attachments, you can significantly reduce the risk of future infections. Remember, prevention and vigilance are key to protecting your digital security in today's evolving threat landscape.

Analysis Report

General information

Family Name: Trojan.Banker.YJ
Signature status: No Signature

Known Samples

MD5: 2733ac8d1dbf454aec04917bf1179ee0
SHA1: 0fd62ee9c3bbeab9b62db33226930ed950677a1d
SHA256: DB6744026BD5AABC0DAA7A0737FCC1E0D72D20589FDF372137E1D52BBBDD7689
File Size: 1.92 MB, 1921536 bytes
MD5: 2eb5f779a5b3e7f36b7021c95a515972
SHA1: 541c148cce0871c8cfd70a345cbf26d20fcbca03
SHA256: BB72E6DF939B0A8FB99040147C2054853200E465E9787E11729F7A86005078B2
File Size: 1.78 MB, 1779200 bytes
MD5: 49f7e990afd4ca1a4acf87d68a5c4856
SHA1: 4ce6d48536dbe88ae5e2aadc2b3cb52f4dfb2475
SHA256: 71250DFBE0F539F6FB32C926069316C89B27B36B3ABBCC00FE4FCDF28A132C95
File Size: 2.13 MB, 2130944 bytes
MD5: f5ff2b0696403916abdf778defa0f543
SHA1: fda265be01430bb10edaa7e7ab5b9a98f7102f00
SHA256: 7B49948B680CCB0BED39091EB8EEC42460BCB8828F15B10CFC4AE34561A2D2B7
File Size: 7.46 MB, 7459135 bytes
MD5: bd68608d32ef632f165f32d9013822c3
SHA1: cb63268910aefb6187ae3dae88c4b8d1eaead8db
SHA256: 19ABB71530DEDFE7F4C00D2A153AC753397AD19FC41CDF6A1E0D2BD14502EA0A
File Size: 5.42 MB, 5419465 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.3.3.0
  • 1.4.0.0
Comments Identifies hidden data in files
Company Name
  • Cameyo (cameyo.com)
  • Daossoft
  • Digital Confidence
  • www.mipony.net
File Description
  • Hidden Data Detector
  • Loader
  • Mipony
  • Windows Password Rescuer
File Version
  • 6.0.0.1
  • 3, 1, 1446, 0
  • 3, 0, 1407, 0
  • 3, 0, 1398, 0
  • 3, 0, 1390, 0
  • 2.3.3.0
  • 1.4.0.0
Internal Name
  • HiddenDataDetector.exe
  • Loader
  • MiPony.exe
  • Packager.exe
  • WindowsPasswordRescuer.exe
Legal Copyright
  • (c) Cameyo. All rights reserved.
  • Copyright (C) 2006-2014 Daossoft. All rights reserved.
  • Copyright © Digital Confidence 2016
Original Filename
  • HiddenDataDetector.exe
  • Loader.exe
  • MiPony.exe
  • Packager.exe
  • WindowsPasswordRescuer.exe
Product Name
  • Cameyo Application Virtualization
  • Hidden Data Detector
  • Mipony
  • Windows Password Rescuer
Product Version
  • 6.0.0.1
  • 3, 1, 1446, 0
  • 3, 0, 1407, 0
  • 3, 0, 1398, 0
  • 3, 0, 1390, 0
  • 2.3.3.0
  • 1.4.0.0

File Traits

  • 2+ executable sections
  • big overlay
  • BINinO
  • HighEntropy
  • MZ (In Overlay)
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 4,118
Potentially Malicious Blocks: 1,128
Whitelisted Blocks: 2,990
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 1 0 1 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 1 0 x x x x x x 0 x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x 0 x x x x x 0 0 0 0 0 1 1 0 0 0 0 1 x 0 0 x x x x 0 x x x x x x x x 0 x x x x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 x 0 x 0 x x x x x x x x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 1 1 0 0 0 0 0 0 1 0 0 0 0 x 0 0 x 0 0 0 0 x x x 0 0 x x 0 x x x x x 0 x x 0 x x 0 1 0 x x x x x 1 1 x 0 x x x x x x x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x 1 0 x x 0 0 0 x 1 1 1 0 0 x x 0 x 0 x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 1 x x x 1 x x x x x x x x x x 0 x x x x x x x x x x 0 0 0 0 x x x x x x x 0 x x x x x 0 0 x x x x 0 0 x 0 0 x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 1 x x x 0 x 0 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x 0 x x 1 x x x x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 x 0 0 1 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x x x x x x x x x x x x 0 0 x x x x x x x 0 x x x x 0 x 0 x 0 x x x x x x x x x x 0 x x x 0 x 0 x x 0 x 0 x 0 x 0 x 0 x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x x x x x x x x x x 0 x x x x x x x 0 x x x 0 x x x x x x 0 x 0 x x x 0 x 0 0 x 0 x 0 x x x x x x x x x x x x x x 0 x x 0 x 0 0 x 0 x x x 0 x 0 x x x x x x x x x x 0 x x 0 x x 0 x 0 x x x x 0 0 x x x 0 x x 0 x 0 x x x x x x x x x x 0 x x 0 x 0 x x 0 x x x 0 x 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x 0 x x x x x x x x x 0 x x 0 0 0 x x x x x x 0 x x x x 0 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 0 0 x x x x x x x x x 0 0 0 x x x x x x x x x x x x x x x x x x x x 0 0 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x 0 x x x x x 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 x 0 x x 0 x x 0 0 0 x x x x x 0 x x x x x x x x x x 0 x x x x x x x x x x 0 x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x 0 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x 0 0 0 x 0 x x 0 x 0 0 0 x 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 x x x x x x x x x x x x x x x 0 x x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 x x x x 0 x x x 0 x x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x x x x x 0 x x x x x x x x x 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Banker.YJ
  • Banker.YJA

Files Modified

File Attributes
\device\namedpipe\mydbg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df15543afd579f756a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~df818f4c427670b08b.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\appname.15127\appname.15127.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\appname.15127\appname.15127.exe Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\appname.15127\appname.1512764.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\appname.15127\appname.1512764.exe Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\appname.15127\appvirtdll64_appname.15127.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\appname.15127\appvirtdll64_appname.15127.dll Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\appname.15127\appvirtdll_appname.15127.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\roaming\vos\appname.15127\appvirtdll_appname.15127.dll Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\appname.15127\changes\cryptcheck.dat Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\changes\runninginfo.ini Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\changes\virtfiles.db Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\vos\appname.15127\changes\virtfiles.db Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\appname.15127\changes\virtfiles.db Synchronize,Write Data
c:\users\user\appdata\roaming\vos\appname.15127\changes\virtfiles.db.8840.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\changes\virtreg.base.dat Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\vos\appname.15127\changes\virtreg.dat Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\vos\appname.15127\enginestamps\appname.15127.exe.20161214-122749.187.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\enginestamps\appname.1512764.exe.20161214-122749.187.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\enginestamps\appvirtdll64_appname.15127.dll.20161214-122749.062.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\enginestamps\appvirtdll_appname.15127.dll.20161214-122749.046.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\enginestamps\diskmodedeploy.marker Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\enginestamps\sandboxcfg.db.20161214-122749.203.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\enginestamps\virtfiles.prog.db.20161214-122749.203.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\enginestamps\virtreg.prog.dat.20161214-122749.203.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\enginestamps\zipcache.20161214-122749.203.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\sandboxcfg.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\appname.15127\sandboxcfg.db Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\appname.15127\virtapp.ini Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\virtfiles.prog.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\appname.15127\virtfiles.prog.db Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\appname.15127\virtreg.prog.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\appname.15127\virtreg.prog.dat Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\appname.15127\virtreg.prog.dat Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\appname.15127\zipcache Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\appvirtdll64_hidden data detector.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\appvirtdll64_hidden data detector.dll Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\appvirtdll_hidden data detector.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\appvirtdll_hidden data detector.dll Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\changes\%windows%\rgiad23.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\changes\%windows%\rgiad23.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\changes\%windows%\rgiada1.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\changes\%windows%\rgiada1.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\changes\%windows%\rgiade0.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\changes\%windows%\rgiade0.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\changes\%windows%\rgiae20.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\changes\%windows%\rgiae20.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\changes\c:\users\user\appdata\local\temp\tmp4352$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\roaming\vos\hidden data detector\changes\cryptcheck.dat Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\changes\runninginfo.ini Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\changes\virtfiles.db Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\vos\hidden data detector\changes\virtfiles.db Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\changes\virtfiles.db Synchronize,Write Data
c:\users\user\appdata\roaming\vos\hidden data detector\changes\virtfiles.db.7136.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\changes\virtreg.base.dat Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\vos\hidden data detector\changes\virtreg.dat Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\vos\hidden data detector\changes\virtreg.dat Read Data,Read Control,Write Data
c:\users\user\appdata\roaming\vos\hidden data detector\changes\virtreg.dat.log1 Read Data,Write Data
c:\users\user\appdata\roaming\vos\hidden data detector\changes\virtreg.dat.log2 Read Data,Write Data
c:\users\user\appdata\roaming\vos\hidden data detector\enginestamps\appvirtdll64_hidden data detector.dll.20160111-194003.371.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\enginestamps\appvirtdll_hidden data detector.dll.20160111-194003.371.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\enginestamps\diskmodedeploy.marker Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\enginestamps\hidden data detector.exe.20160111-194003.387.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\enginestamps\hidden data detector64.exe.20160111-194003.387.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\enginestamps\sandboxcfg.db.20160111-194003.387.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\enginestamps\virtfiles.prog.db.20160111-194003.387.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\enginestamps\virtreg.prog.dat.20160111-194003.387.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\enginestamps\zipcache.20160111-194003.387.stamp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\hidden data detector.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\hidden data detector.exe Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\hidden data detector64.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\hidden data detector64.exe Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%desktop%\downloads.lnk Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%desktop%\downloads.lnk Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%desktop%\hidden data detector.lnk Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%desktop%\hidden data detector.lnk Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%desktop%\uploads.lnk Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%desktop%\uploads.lnk Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%program files (x86)%\digital confidence\hiddendatadetector\hiddendatadetector.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%program files (x86)%\digital confidence\hiddendatadetector\hiddendatadetector.exe Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%programs%\digital confidence\hidden data detector.lnk Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\prog\%programs%\digital confidence\hidden data detector.lnk Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\prog\c_\installed modules\hidden data detector.lnk Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\prog\c_\installed modules\hidden data detector.lnk Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\prog\icons\hiddendatadetector.exe.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\sandboxcfg.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\sandboxcfg.db Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\sandboxcfg.db Synchronize,Write Data
c:\users\user\appdata\roaming\vos\hidden data detector\sandboxcfg.db.7136.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\virtapp.ini Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\virtfiles.prog.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\virtfiles.prog.db Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\virtreg.prog.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\vos\hidden data detector\virtreg.prog.dat Generic Write,Read Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\virtreg.prog.dat Synchronize,Write Attributes
c:\users\user\appdata\roaming\vos\hidden data detector\zipcache Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\vos\hidden data detector::basedirname C:\Users\Hdqrmjdl\AppData\Roaming\VOS\Hidden Data Detector RegNtPreCreateKey
HKCU\software\vos\hidden data detector::carrierexename c:\users\user\downloads\fda265be01430bb10edaa7e7ab5b9a98f7102f00_0007459135 RegNtPreCreateKey
HKCU\software\vos\hidden data detector::dataintegrity X%Program Files (x86)%\Digital Confidence\HiddenDataDetector> RegNtPreCreateKey
HKCU\software\vos\hidden data detector::dataintegrity X%Program Files (x86)%\Digital Confidence\HiddenDataDetector>X%Program Files (x86)%\Digital Confidence\HiddenDataDetector\Hidden RegNtPreCreateKey
HKCU\software\vos\hidden data detector\registry\%currentuser%\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\vos\hidden data detector\registry\%currentuser%\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\vos\hidden data detector\registry\%currentuser%\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\vos\hidden data detector\registry\%currentuser%\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\vos\appname.15127::basedirname C:\Users\Xpyaoguv\AppData\Roaming\VOS\AppName.15127 RegNtPreCreateKey
HKCU\software\vos\appname.15127::carrierexename c:\users\user\downloads\cb63268910aefb6187ae3dae88c4b8d1eaead8db_0005419465 RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 0m�8�1tX�jg �� �6 �v xy ����T������1��dc�%���5����3bBx�<���R �7#�#��$kF%`�&� &�-'�(�(X�(�)A)�`*J*9*�"+��,��-!R0P%1`1�1HO1�D5,]9ߔ=�@V�B��F?G�I RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 1m�8�1tX�jg �� �6 �v xy ����T������1��dc�%���5����3bBx�<���R �7#�#��$kF%`�%�&� &�-'�(�(X�(�)A)�`*J*9*�"+��,��-!R0P%1`1�1HO1�D5,]9ߔ=�@V�B��F? RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 2m�8�1tX�jg �� �6 �v xy ����T������1��dc�%���5����3bBx�<���R �7#�#��$kF%`�%�&� &�-'�(�(X�(�)A)�`*J*9*�"+��,=�,��-!R0P%1`1�1HO1�D5,]9ߔ=�@V�B�� RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
User Data Access
  • GetUserName
Network Wininet
  • HttpQueryInfo
  • InternetOpen
  • InternetOpenUrl
Process Manipulation Evasion
  • NtUnmapViewOfSection

Related Posts

Trending

Most Viewed

Loading...