Threat Database Trojans Trojan.MSIL.KillWin

Trojan.MSIL.KillWin

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 3,715
Threat Level: 80 % (High)
Infected Computers: 591
First Seen: May 23, 2024
Last Seen: July 28, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.KillWin indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to infiltrate and damage your computer, often without your knowledge or consent. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further harm.

What Is Trojan.MSIL.KillWin?

Trojan.MSIL.KillWin is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan.MSIL.KillWin" suggests that it may be related to the .NET framework and could be designed to target Windows systems. However, without more specific information, it is difficult to determine the exact nature and intentions of this threat.

How Trojan.MSIL.KillWin Operates

Trojan horses like Trojan.MSIL.KillWin typically operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can perform a variety of malicious actions, such as stealing sensitive information, installing additional malware, or disrupting system operation. They may also create backdoors, allowing remote access to your system, or engage in other malicious activities that can compromise your security and privacy.

Symptoms of Infection

Systems infected with Trojan.MSIL.KillWin may exhibit a range of symptoms, including slow performance, frequent crashes, or unusual behavior. You may also notice unfamiliar programs or icons on your desktop, or receive unexpected pop-ups or alerts. In some cases, the infection may not produce any noticeable symptoms, making it difficult to detect without the aid of security software.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar or suspicious programs
  • Increased network activity or unusual traffic patterns
  • System crashes or instability

How to Remove Trojan.MSIL.KillWin

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.MSIL.KillWin requires a combination of technical knowledge and the right tools. By following the steps outlined above and taking a proactive approach to system security, you can help protect your computer from this and other types of malware. It is essential to remain vigilant and to regularly update your security software to ensure that you have the latest protections against emerging threats. Remember, prevention is key, and being aware of the risks and taking steps to mitigate them can help you avoid the consequences of a malware infection.

Analysis Report

General information

Family Name: Trojan.MSIL.KillWin
Signature status: No Signature

Known Samples

MD5: 088655e14c66f121158b501256e3bf2b
SHA1: 2f6fca52b1bfe8a397cb217f10e60b5db8bd4883
File Size: 2.76 MB, 2759168 bytes
MD5: 3b3dced2cdbdaa683b492b524cb377aa
SHA1: f97b1c0192017bd72e828f31cba708136acfbb42
File Size: 1.80 MB, 1802240 bytes
MD5: 3b64cfa79378cf26c8d0b03ad3494122
SHA1: 19c7ad087f9920fe016872cb77057df297778c11
SHA256: A5ED69B4AACDFD41D53C667310B4FB2713A53BAD5335A290BE7A9F4F8741AA17
File Size: 1.65 MB, 1650688 bytes
MD5: 26bce72fdbd3574616ea09e175e8f3f3
SHA1: 7ddd2c14317fbb0d3e49c16956b1e006095fd8a1
SHA256: 63C5C1E0D2DB93EB735912E2C3970C19583E5096507BC6282F515BC8E9FCF2A4
File Size: 2.43 MB, 2433536 bytes
MD5: 30e4acb338ec3b50f93e20ce94251cdf
SHA1: d619fee8c45409c60496c8ef9bb95b1f34ac2984
SHA256: B4704D0A1109339FB2EAAC52FAA4EE6E7F905B97C1C51C588121D771F5765C3C
File Size: 713.73 KB, 713728 bytes
Show More
MD5: 6b8bf7b9cb17f358289fb30f1f61bb26
SHA1: 89dd8568359613dbfa231ef0ac038547f8065579
SHA256: 7111678DE168BCC21D37241BC842466DBFCDAC5300E01F2AB56C583D731C7B83
File Size: 1.65 MB, 1654784 bytes
MD5: 61f6bf802445f33ca2001fb7695bc740
SHA1: 651f1ee23e0e270bccb465130797edf2f4caade5
SHA256: 43FFB7DFB784161C3FE308DA40C171D3DDF4A285A6B2E64BD601F60AB82CF006
File Size: 238.59 KB, 238592 bytes
MD5: 8df0fa9794a50cecac005a555df7ffc5
SHA1: 89f4e43e41380a88680067dc633179ed1f1e8545
SHA256: C9B0939520D194B0140F6A65CFCF3708E0947833CD6DD4E161BEC7BDA995F991
File Size: 2.74 MB, 2742272 bytes
MD5: ca2709d69c2bdfefefd36227aa44b2be
SHA1: 1f74b7b9107203dead7c6a1abe5bfcf0b8b4907c
SHA256: D7D26B4A52DC41A731F0C3ADF9DDCC7CFD399F8144E422B0B88336FF56AC58F3
File Size: 2.66 MB, 2663424 bytes
MD5: e5ab5d5cb0302bd62cc8c5e62a0d52fe
SHA1: b184100b69df0ca08a8b8dec1f621c2e75cd44c9
SHA256: 74D73B2D1C18C5B237A44326F0C371337433E37DA95F860F59FE542DD07B39DD
File Size: 67.58 KB, 67584 bytes
MD5: a7c0a12648e3284b3051dbc5e4e75422
SHA1: db5250eeca0d9c1f06372ee21e011593fc136fe0
SHA256: 50BF7D968FCF5B58C1EDBC9379B650788416302F3F5203BA76E2867E7B585679
File Size: 6.05 MB, 6054912 bytes
MD5: 6a37fe248511105d42b8eab92e7876e3
SHA1: 426227d6168c929ea690e73e460f700c697fa5a5
SHA256: 6317C5BA9AED93E2D97DA5B76F04DCE79014C335BA2D329C170C75977B8A0768
File Size: 2.66 MB, 2663424 bytes
MD5: 17ec2a18af0112f8b1e754d92f985cba
SHA1: 6fea4471f9d068e1cb38b675f657997f581353e7
SHA256: 3AB28857360C990A8AD9DB736A1686E519C6A625FCE56F3E536AFDD3A6E9FB50
File Size: 13.82 KB, 13824 bytes
MD5: 339457843416e571f345bfdb3cd13528
SHA1: 806032da5942b872210c42f27c99161b9a2a8f0e
SHA256: 3CFDEAE42C79B27D8AF08FC5F31E35F05EEDC3E4BB9E6AC5E74033046A978F49
File Size: 2.67 MB, 2666496 bytes
MD5: 84a121310670143d5dd1b4f6c46dd51d
SHA1: 2bd5cf1ca0a93a7cf5f61c0b524b20c5028d848a
SHA256: 2B70FA90EC68453680A1AACB31EFEFA9E48CB3323220F73A6C0BD445AFF75BFC
File Size: 32.26 KB, 32256 bytes
MD5: 4358c18d978c6cb887adf5ffcd54b267
SHA1: 93b58708f609623ad60b3a939b50a4b40b7a8497
SHA256: 20F9E059D24C0D400AA9CF0CD313E1E12A25AAD9E68DEBFDEB66EC0D43D2ABE4
File Size: 4.04 MB, 4044087 bytes
MD5: 373087cb46d160310c895821e8ff5eea
SHA1: 462a55a7e46a7e19a0b02fb1333a1cbe82a550dc
SHA256: 80EECF2DFE9E105CC670536071C287608874E9C356307DC2303CE834ABB5C5C5
File Size: 1.57 MB, 1572864 bytes
MD5: 08122f8c76e921c108acec86f00b4265
SHA1: 15b9bd8c304906f1fef2befb0c01541f7e6ba99b
SHA256: 6C79151B438112C00F6496A5DDC1F7305CCA131D900D05D466C41CD6DB96533A
File Size: 6.33 MB, 6331904 bytes
MD5: bc1442276fbb89b93b9d4c3a30d6ca36
SHA1: cab92fc8001879348b8e971a64543d956274e4a4
SHA256: CD09B2EDACD89E8B74B75952180710C91A548AE71CCE62B472D2EC2416BCB794
File Size: 2.66 MB, 2663424 bytes
MD5: f704ff496ffbae1ffbc4613403a54be6
SHA1: a03c4b766bb37f5fc63dcf852ad880e217d0b92d
SHA256: 2B39AF881DB6C6DF1164D5057772442668D77DF704B25BEB265E48704C80B434
File Size: 4.04 MB, 4044087 bytes
MD5: 2e5ae53254909d3d0b6998f5b7717cfe
SHA1: 89e8206298c9a7333a74765d3aa08ee3fe224021
SHA256: 99A31373F140FACEE4A5D148FCE1699D37501FCE192B1C666DE388BED84F8610
File Size: 3.61 MB, 3614007 bytes
MD5: ba48baec3dfa19b509ac403adfa01ba7
SHA1: 54b289e0b64432e6c55cdbb5e50c6edc2c645c09
SHA256: 6CE3137D586AE7B10C6AA76398B8FC9790FB997D9F3BC15E200B399E3A19E8E7
File Size: 2.69 MB, 2688512 bytes
MD5: 292dec2d8fefc54f2176649eddbbce85
SHA1: 53458bb26f4a72a2e8f73aff8d95f145c595aff5
SHA256: 0D85E207C15441FC7F3974B00704C6EC9098280B08F972AFFB4CE2003795B871
File Size: 375.81 KB, 375808 bytes
MD5: cce11ddd778a3c5087a0d1b453401fe0
SHA1: 284549824577cfe0b5504d829920387f2b2f86a8
SHA256: B23836B44580095106ECA124BEC58F375155315930175A0923B7E0B47985A8F0
File Size: 644.61 KB, 644608 bytes
MD5: b9cdf1bebe58ba1d107d8b1e43286efc
SHA1: d07c271ada6eda116c61ab52fdb64d165d2a7da1
SHA256: B7CBEE546939205EBCF0B63CCF31BD7D235A92B686A338C2E24FECA12831A03F
File Size: 2.75 MB, 2752512 bytes
MD5: 50fa19db13ad7b2be40e9a9369c7d4fc
SHA1: 6a5573513736818d2689b829ae8412320949551d
SHA256: D4E2708E51E5442AA693FD545CE183CD307E48A2B4A6B72F02A80ED20FDCBFC0
File Size: 1.66 MB, 1663488 bytes
MD5: 03c73cc95a43699f831926474ae32f61
SHA1: a09f5bfd24b984b68cc0f5a14921a6cfc28681db
SHA256: 95D9E11E0A403D364A762CFBC30BAD5BBD207292F0F232EE5238586D5E5E58F8
File Size: 2.67 MB, 2666496 bytes
MD5: 15eca77dbb272e5a905311b48973cffc
SHA1: 4be366e6cb37a35ddbf5d93ae0d3bfbd26026f83
SHA256: CBECE60AF8E08D43FC85F4CE4B527F23A435D86FDC05DF6E339C2BB14C8D704C
File Size: 2.77 MB, 2768384 bytes
MD5: 5d187a83fe102cdc980e08bd83ae70ed
SHA1: 6f7d80715f110969167a272bb16882473236a97f
SHA256: 5AD071EC5FBC5BEBCEFF93E7697823926A18FD9759BBAD56B3836A5D3AB6CD0E
File Size: 3.62 MB, 3622199 bytes
MD5: c3da387418b8b90d0b5ffa551d85e8d5
SHA1: 179fa8a06349e7ebd52120c79b3f0d1677701cd9
SHA256: 2B2ED02D25C03A23BACF534DCB6D01683AAABFEC09D2A48BE69D7091A3DF063A
File Size: 1.67 MB, 1671168 bytes
MD5: eb8347c0430a6af6bbeb11c658445750
SHA1: 86d753e1b8ccacb502ea11a2aaa8118a46878940
SHA256: 0D95AFA2EB869C59980EE7D5E17318C50B48220ED1572F2EA7D38D442577E239
File Size: 2.85 MB, 2848256 bytes
MD5: 18fa4297d8b38ed794ad212a695884ef
SHA1: e7238e12734d0e31f37a6cc076fbad6bb6dbdc51
SHA256: 751E450696506A032A43246AED87D602594FB5F585D0190ABE5FC0F615B6A7B8
File Size: 1.41 MB, 1412096 bytes
MD5: f284568010505119f479617a2e7dc189
SHA1: e23707625cce0035e3c1d2255af1ed326583a1ea
SHA256: 26C8F13EA8DC17443A9FA005610537CB6700AEBAF748E747E9278D504E416EB1
File Size: 1.10 MB, 1102848 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Assembly Version
  • 25.8.28.0
  • 9.2.0.0
  • 5.7.3.0
  • 5.6.0.0
  • 5.5.0.0
  • 5.3.1.0
  • 5.1.0.0
  • 5.0.45.0
  • 5.0.44.0
  • 5.0.34.0
Show More
  • 5.0.31.0
  • 4.42.0.0
  • 4.3.0.0
  • 3.3.1.0
  • 3.1.2.0
  • 2.0.5.0
  • 1.5.1.0
  • 1.5.0.2
  • 1.4.1.0
  • 1.3.2.0
  • 1.1.0.0
  • 1.0.7.0
  • 1.0.2.0
  • 1.0.0.1
  • 1.0.0.0
Comments
  • Advanced Windows Appearance Editor
  • Audio Device Driver
  • CrystalCry Intelligent Memory Cleaning Service
  • Ether Optimizer - your free tool to optimize PC.
  • Learn ways to get started with Windows
  • Sistema de Home Based TMKT
  • 分享也是一种美,亦是美网络。
Company Name
  • Abdelrhman-AK
  • CarpiFPS.Core
  • CrystalCry Team
  • Custom S.p.a.
  • ezgamebooster
  • GuidoAusili
  • ImSwordQueen
  • Klo Tweaker
  • Lafer Srl
  • MarkAdderly
Show More
  • Rayen Ghanmi
  • Realtek Inc
  • TMKT Serviços de Telemarketing
  • vagon.io
File Description
  • CarpiFPS.Core
  • CrystalCry Intelligent Memory Cleaning Service
  • DragonKMS
  • Ether Optimizer
  • ezgamebooster
  • GAOCX
  • Getting Started
  • GTA V InstallPath Tool
  • HelperApp
  • Home Based
Show More
  • Klo Tweaker
  • MakuTweaker
  • Managers
  • Realtek Audio Driver
  • RyTuneX
  • TaskBar
  • Updater
  • WinPaletter
File Version
  • 25.08.28
  • 9.2
  • 5.7.3
  • 5.6
  • 5.5
  • 5.3.1
  • 5.1.0
  • 5.0.45
  • 5.0.44
  • 5.0.34
Show More
  • 5.0.31
  • 4.42.0.0
  • 4.3.0
  • 3.3.1.0
  • 3.1.2.0
  • 2.50.0.0
  • 2.0.5.0
  • 1.5.1.0
  • 1.5.0.2
  • 1.4.1.0
  • 1.3.2.0
  • 1.1.0
  • 1.0.7.0
  • 1.0.2
  • 1.0.0.1
  • 1.0.0.0
  • 1.0.0
Internal Name
  • AV.exe
  • CarpiFPS.Core.dll
  • CCMemoryCleanerService.dll
  • DragonKMS.exe
  • Ether Optimizer.exe
  • ezgamebooster.dll
  • GAOCX.dll
  • GTA V InstallPath Tool.exe
  • HelperApp.exe
  • HomeBased.exe
Show More
  • Klo Tweaker.dll
  • MakuTweaker.dll
  • Managers.dll
  • MyKiosk.exe
  • RyTuneX.dll
  • Updater.exe
  • Win8To7 Getting Started.exe
  • Windows 7 Getting Started.exe
  • WinPaletter.exe
Legal Copyright
  • Copyright © 2011
  • Copyright © 2014
  • Copyright © 2017
  • Copyright © 2018
  • Copyright © 2019
  • Copyright © 2022
  • Copyright © 2022-2023
  • Copyright © 2024
  • CrystalCry Team
  • Licensed under Unlicense License
Show More
  • MarkAdderly
  • TMKT 2015
  • ©ChaosPlayer & ©GTA5-Mods.com 2018-2025 ©Gang1111
  • 这是一款免费软件。
Legal Trademarks WinPaletter
Original Filename
  • AV.exe
  • CarpiFPS.Core.dll
  • CCMemoryCleanerService.dll
  • DragonKMS.exe
  • Ether Optimizer.exe
  • ezgamebooster.dll
  • GAOCX.dll
  • GTA V InstallPath Tool.exe
  • HelperApp.exe
  • HomeBased.exe
Show More
  • Klo Tweaker.dll
  • MakuTweaker.dll
  • Managers.dll
  • MyKiosk.exe
  • RyTuneX.dll
  • Updater.exe
  • Win8To7 Getting Started.exe
  • Windows 7 Getting Started.exe
  • WinPaletter.exe
Product Name
  • CarpiFPS.Core
  • CrystalCry Intelligent Memory Cleaning Service
  • DragonKMS
  • Ether Optimizer
  • ezgamebooster
  • GAOCX
  • Getting Started Applet
  • GTA V InstallPath Tool
  • HelperApp
  • Home Based
Show More
  • Klo Tweaker
  • MakuTweaker
  • Managers
  • Realtek Audio Driver
  • RyTuneX
  • TaskBar
  • Updater
  • Windows 8 to Windows 7 Transformation Pack
  • WinPaletter
Product Version
  • 25.08.28
  • 9.2
  • 5.7.3
  • 5.6
  • 5.5
  • 5.3.1
  • 5.1.0
  • 5.0.45
  • 5.0.44
  • 5.0.34
Show More
  • 5.0.31
  • 4.42.0.0
  • 4.3.0
  • 3.3.1.0
  • 3.1.2.0
  • 2.50.0.0
  • 2.0.5.0
  • 1.5.1+0b100aa3cf91d84e3f382fb72be824077cc4d005
  • 1.5.1
  • 1.5.0.2
  • 1.4.1+0bb5bb3cf7f04610214822b6b98b9f0aed2a2b4e
  • 1.3.2+03a43b4aa43c22e607d47447993dc0b9b880fc5d
  • 1.0.7.0
  • 1.0.2
  • 1.0.0.1
  • 1.0.0.0
  • 1.0.0+fb30f10ec874e5fc53997712dffd530471b45c2c
  • 1.0.0

File Traits

  • .NET
  • .sdata
  • dll
  • Gdrive
  • HighEntropy
  • Installer Version
  • NewLateBinding
  • ntdll
  • RijndaelManaged
  • Run
Show More
  • x64
  • x86

Block Information

Total Blocks: 166
Potentially Malicious Blocks: 89
Whitelisted Blocks: 77
Unknown Blocks: 0

Visual Map

x x x x 0 x x x x x x x x x 0 x x x 0 x x x 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 x x 0 0 0 x 0 0 x x x 0 x x x x 0 x x x 0 0 0 x x x x x x 0 0 0 0 0 x x 0 x x 0 x 0 x x x 0 x x x 0 x x 0 x x 0 x x x 0 x x x x 0 x x x 0 0 0 x x x x x x 0 x 0 x x x x 0 0 x 0 0 x x x 0 x 0 0 x x 0 x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.FakeAV.B
  • MSIL.Gametool.X

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\dly0cfjr.newcfg Generic Write,Read Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\dly0cfjr.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\o4n2bgds.newcfg Generic Write,Read Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\o4n2bgds.newcfg Synchronize,Write Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\o4n2bgds.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\rks3qhwd.newcfg Generic Write,Read Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\rks3qhwd.newcfg Synchronize,Write Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\rks3qhwd.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\uo0s4tsd.newcfg Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\uo0s4tsd.newcfg Synchronize,Write Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\uo0s4tsd.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\user.config Generic Write,Read Attributes
c:\users\user\appdata\local\gta_v_install_path_tool\462a55a7e46a7e19a0b02fb13_url_j1keluogzvwqi3dlgca1w4dazylcltn4\9.2.0.0\user.config Synchronize,Write Data
c:\users\user\appdata\local\gta_v_install_path_tool\gta v installpath tool.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\downloads\tsa.crt Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\winpaletter\settings::licenseaccepted RegNtPreCreateKey
HKCU\software\winpaletter\settings::autoupdateschecking  RegNtPreCreateKey
HKCU\software\winpaletter\settings::autoaddext  RegNtPreCreateKey
HKCU\software\winpaletter\settings::draganddroppreview  RegNtPreCreateKey
HKCU\software\winpaletter\settings::win7livepreview  RegNtPreCreateKey
HKCU\software\winpaletter\settings::openingpreviewinapp_or_appliesit  RegNtPreCreateKey
Show More
HKCU\software\winpaletter\settings::autorestartexplorer  RegNtPreCreateKey
HKCU\software\winpaletter\settings::autoapplycursors  RegNtPreCreateKey
HKCU\software\winpaletter\settings::resetcursorstoaero RegNtPreCreateKey
HKCU\software\winpaletter\settings::custompreviewconfig_enabled RegNtPreCreateKey
HKCU\software\winpaletter\settings::showlogwhilesaving RegNtPreCreateKey
HKCU\software\winpaletter\settings::complexsaveresult 2.1 RegNtPreCreateKey
HKCU\software\winpaletter\settings::showsaveconfirmation  RegNtPreCreateKey
HKCU\software\winpaletter\settings::saveforlegacywp RegNtPreCreateKey
HKCU\software\winpaletter\settings::mainformwidth і RegNtPreCreateKey
HKCU\software\winpaletter\settings::mainformheight ˕ RegNtPreCreateKey
HKCU\software\winpaletter\settings::mainformstatus RegNtPreCreateKey
HKCU\software\winpaletter\settings::updatechannel RegNtPreCreateKey
HKCU\software\winpaletter\settings::appearance_dark  RegNtPreCreateKey
HKCU\software\winpaletter\settings::appearance_auto  RegNtPreCreateKey
HKCU\software\winpaletter\settings::appearance_custom RegNtPreCreateKey
HKCU\software\winpaletter\settings::appearance_schemename Default Dark RegNtPreCreateKey
HKCU\software\winpaletter\settings::appearance_custom_dark  RegNtPreCreateKey
HKCU\software\winpaletter\settings::appearance_accent 凒＀ RegNtPreCreateKey
HKCU\software\winpaletter\settings::appearance_back ᤙ9 RegNtPreCreateKey
HKCU\software\winpaletter\settings::appearance_rounded  RegNtPreCreateKey
HKCU\software\winpaletter\settings::appearance_win11_mica  RegNtPreCreateKey
HKCU\software\winpaletter\settings::whatsnewrecord RegNtPreCreateKey
HKCU\software\winpaletter\settings::language RegNtPreCreateKey
HKCU\software\winpaletter\settings::language_file RegNtPreCreateKey
HKCU\software\winpaletter\settings::nerd_stats  RegNtPreCreateKey
HKCU\software\winpaletter\settings::nerd_stats_hexhash  RegNtPreCreateKey
HKCU\software\winpaletter\settings::nerd_stats_kind RegNtPreCreateKey
HKCU\software\winpaletter\settings::terminal_bypass RegNtPreCreateKey
HKCU\software\winpaletter\settings::terminal_otherfonts RegNtPreCreateKey
HKCU\software\winpaletter\settings::terminal_path_deflection RegNtPreCreateKey
HKCU\software\winpaletter\settings::terminal_stable_path C:\Users\user\AppData\Local\Packages\Microsoft.WindowsTerminal_8wekyb3d8bbwe\LocalState\settings.json RegNtPreCreateKey
HKCU\software\winpaletter\settings::terminal_preview_path C:\Users\user\AppData\Local\Packages\Microsoft.WindowsTerminalPreview_8wekyb3d8bbwe\LocalState\settings.json RegNtPreCreateKey
HKCU\software\winpaletter\settings::cmd_overrideuserpreferences  RegNtPreCreateKey
HKCU\software\winpaletter\settings::log_showapplying  RegNtPreCreateKey
HKCU\software\winpaletter\settings::log_countdown_enabled  RegNtPreCreateKey
HKCU\software\winpaletter\settings::log_countdown  RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l�8�tX�jg �� �6 �v �Z xy ��T�������%���5��3bBx!wz#��$kF%`�&� &�-(�(X�(�)�`*J*9*�"-!R1`1�1HO5,]@V�A��G�IH[uH�pH��J��N$N�X�.X�_�zb"hc�wg�jh�ri��j�bk`k�ql(� RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱睂켜ʚ꺇뺶 켜ʚ꺇뺶켜ʚ꺇뺶켜ʚ꺇뺶켜ʚ릵犱洎ʫጉ嵑ⴣ픋˹耀뫹躧隞̃섁耀꧌ł⋨ RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 隞̃ँ耀꧌á RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush

43 additional items are not displayed above.

User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Other Suspicious
  • AdjustTokenPrivileges
Cert Store Read
  • CertOpenStore
Cert Store Write
  • CertAddCertificateContextToStore

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\19c7ad087f9920fe016872cb77057df297778c11_0001650688.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\89dd8568359613dbfa231ef0ac038547f8065579_0001654784.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\651f1ee23e0e270bccb465130797edf2f4caade5_0000238592.,LiQMAxHB
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 1052
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\179fa8a06349e7ebd52120c79b3f0d1677701cd9_0001671168.,LiQMAxHB
Show More
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 1152