Threat Database Trojans Trojan.Padodor.D

Trojan.Padodor.D

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,025
Threat Level: 80 % (High)
Infected Computers: 93
First Seen: November 12, 2021
Last Seen: June 8, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Padodor.D
Signature status: No Signature

Known Samples

MD5: e7135bb5d4afdb8502921d8ecc669c95
SHA1: dc794d1d7da0be0dfd2bba45476ba9f481931e8e
SHA256: 02BF64B4A408B1DC291061E4405C24A0E8C66DEDA2C8C5FCD06210197E06306E
File Size: 95.77 KB, 95770 bytes
MD5: 00fc67b601912ac5109d24ee905be285
SHA1: 2695f7adad526d31e1e082c7f5fc8d02844b0242
SHA256: 2B6B767AC145176EDD317ABCC3B27875EFB754BF7C625DB6173E3925E48218CA
File Size: 67.07 KB, 67072 bytes
MD5: ca08f58a4041b10d7a572f5bb0657030
SHA1: fd95dc1c45e84eefcbfe8287b0b8221bee501439
SHA256: 0482746241450A8DAFC0FC95DDB114F7142F238A36FBD16FFFA32086FD3B7D9C
File Size: 60.46 KB, 60458 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 1
Potentially Malicious Blocks: 1
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Hangup.A
  • Hangup.AA
  • Hangup.AB
  • Hangup.AC
  • Hangup.AD
Show More
  • Hangup.AE
  • Padodor.CC
  • Padodor.D
  • Padodor.DA
  • Padodor.DB
  • Padodor.DC
  • Qukart.B

Files Modified

File Attributes
c:\windows\syswow64\aadljlfl.dll Generic Write,Read Attributes
c:\windows\syswow64\abmmqkei.dll Generic Write,Read Attributes
c:\windows\syswow64\abncdecn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\abncdecn.exe Generic Write,Read Attributes
c:\windows\syswow64\acbiig32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\acbiig32.exe Generic Write,Read Attributes
c:\windows\syswow64\acnonhka.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\acnonhka.exe Generic Write,Read Attributes
c:\windows\syswow64\adeohhdf.dll Generic Write,Read Attributes
c:\windows\syswow64\akmflp32.dll Generic Write,Read Attributes
Show More
c:\windows\syswow64\ammjglki.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ammjglki.exe Generic Write,Read Attributes
c:\windows\syswow64\anaikf32.dll Generic Write,Read Attributes
c:\windows\syswow64\anpilcbe.dll Generic Write,Read Attributes
c:\windows\syswow64\aohkhm32.dll Generic Write,Read Attributes
c:\windows\syswow64\apapmj32.dll Generic Write,Read Attributes
c:\windows\syswow64\apepci32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\apepci32.exe Generic Write,Read Attributes
c:\windows\syswow64\apiinhlp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\apiinhlp.exe Generic Write,Read Attributes
c:\windows\syswow64\aqhnkflf.dll Generic Write,Read Attributes
c:\windows\syswow64\bbcefb32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bbcefb32.exe Generic Write,Read Attributes
c:\windows\syswow64\bfjngalp.dll Generic Write,Read Attributes
c:\windows\syswow64\bfmdqa32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bfmdqa32.exe Generic Write,Read Attributes
c:\windows\syswow64\bidjlman.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bidjlman.exe Generic Write,Read Attributes
c:\windows\syswow64\biibpjmp.dll Generic Write,Read Attributes
c:\windows\syswow64\bjcgfp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bjcgfp32.exe Generic Write,Read Attributes
c:\windows\syswow64\bjfclpfn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\bjfclpfn.exe Generic Write,Read Attributes
c:\windows\syswow64\bogeobnn.dll Generic Write,Read Attributes
c:\windows\syswow64\bqeola32.dll Generic Write,Read Attributes
c:\windows\syswow64\canhjhaj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\canhjhaj.exe Generic Write,Read Attributes
c:\windows\syswow64\cbcmkn32.dll Generic Write,Read Attributes
c:\windows\syswow64\cchnbieo.dll Generic Write,Read Attributes
c:\windows\syswow64\cdcapehi.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cdcapehi.exe Generic Write,Read Attributes
c:\windows\syswow64\cdenedff.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cdenedff.exe Generic Write,Read Attributes
c:\windows\syswow64\ciimnjoe.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ciimnjoe.exe Generic Write,Read Attributes
c:\windows\syswow64\clgkhklk.dll Generic Write,Read Attributes
c:\windows\syswow64\cplojelj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cplojelj.exe Generic Write,Read Attributes
c:\windows\syswow64\cpolpejh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\cpolpejh.exe Generic Write,Read Attributes
c:\windows\syswow64\dbaagp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dbaagp32.exe Generic Write,Read Attributes
c:\windows\syswow64\dbkdgk32.dll Generic Write,Read Attributes
c:\windows\syswow64\dcigho32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dcigho32.exe Generic Write,Read Attributes
c:\windows\syswow64\ddanac32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ddanac32.exe Generic Write,Read Attributes
c:\windows\syswow64\ddniaa32.dll Generic Write,Read Attributes
c:\windows\syswow64\dfiaoefc.dll Generic Write,Read Attributes
c:\windows\syswow64\djmffo32.dll Generic Write,Read Attributes
c:\windows\syswow64\dkcild32.dll Generic Write,Read Attributes
c:\windows\syswow64\dkmccmac.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dkmccmac.exe Generic Write,Read Attributes
c:\windows\syswow64\dlcniomc.dll Generic Write,Read Attributes
c:\windows\syswow64\dmibjhci.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dmibjhci.exe Generic Write,Read Attributes
c:\windows\syswow64\dmmjgdde.dll Generic Write,Read Attributes
c:\windows\syswow64\dncaic32.dll Generic Write,Read Attributes
c:\windows\syswow64\dnmmnn32.dll Generic Write,Read Attributes
c:\windows\syswow64\dogahd32.dll Generic Write,Read Attributes
c:\windows\syswow64\fdabdd32.dll Generic Write,Read Attributes
c:\windows\syswow64\fdhcmiod.dll Generic Write,Read Attributes
c:\windows\syswow64\fffkjj32.dll Generic Write,Read Attributes
c:\windows\syswow64\fkccef32.dll Generic Write,Read Attributes
c:\windows\syswow64\flpfac32.dll Generic Write,Read Attributes
c:\windows\syswow64\fmkaeo32.dll Generic Write,Read Attributes
c:\windows\syswow64\fmmeml32.dll Generic Write,Read Attributes
c:\windows\syswow64\folepl32.dll Generic Write,Read Attributes
c:\windows\syswow64\gbbljm32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gbbljm32.exe Generic Write,Read Attributes
c:\windows\syswow64\gejlcm32.dll Generic Write,Read Attributes
c:\windows\syswow64\ggaahcbg.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ggaahcbg.exe Generic Write,Read Attributes
c:\windows\syswow64\ggdnncqd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ggdnncqd.exe Generic Write,Read Attributes
c:\windows\syswow64\gqccpjmi.dll Generic Write,Read Attributes
c:\windows\syswow64\hbceajhp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hbceajhp.exe Generic Write,Read Attributes
c:\windows\syswow64\hbjknpbb.dll Generic Write,Read Attributes
c:\windows\syswow64\hennea32.dll Generic Write,Read Attributes
c:\windows\syswow64\hgmdlb32.dll Generic Write,Read Attributes
c:\windows\syswow64\hhfnim32.dll Generic Write,Read Attributes
c:\windows\syswow64\hhgnei32.dll Generic Write,Read Attributes
c:\windows\syswow64\hijdfa32.dll Generic Write,Read Attributes
c:\windows\syswow64\hinpjk32.dll Generic Write,Read Attributes
c:\windows\syswow64\hjgcen32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hjgcen32.exe Generic Write,Read Attributes
c:\windows\syswow64\hjjiehoh.dll Generic Write,Read Attributes
c:\windows\syswow64\hkbfdagk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hkbfdagk.exe Generic Write,Read Attributes
c:\windows\syswow64\hmoioc32.dll Generic Write,Read Attributes
c:\windows\syswow64\hnelkl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hnelkl32.exe Generic Write,Read Attributes
c:\windows\syswow64\hnepfmkm.dll Generic Write,Read Attributes
c:\windows\syswow64\hnjefknc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hnjefknc.exe Generic Write,Read Attributes
c:\windows\syswow64\ihfgmj32.dll Generic Write,Read Attributes
c:\windows\syswow64\ijepflob.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijepflob.exe Generic Write,Read Attributes
c:\windows\syswow64\ijgllk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijgllk32.exe Generic Write,Read Attributes
c:\windows\syswow64\ijjiak32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijjiak32.exe Generic Write,Read Attributes
c:\windows\syswow64\ijpfkl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijpfkl32.exe Generic Write,Read Attributes
c:\windows\syswow64\ilebdfib.dll Generic Write,Read Attributes
c:\windows\syswow64\ilnmcofj.dll Generic Write,Read Attributes
c:\windows\syswow64\indlohdn.dll Generic Write,Read Attributes
c:\windows\syswow64\innoak32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\innoak32.exe Generic Write,Read Attributes
c:\windows\syswow64\jaaqpela.dll Generic Write,Read Attributes
c:\windows\syswow64\jclaqemi.dll Generic Write,Read Attributes
c:\windows\syswow64\jeckplja.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jeckplja.exe Generic Write,Read Attributes
c:\windows\syswow64\jeoaem32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jeoaem32.exe Generic Write,Read Attributes
c:\windows\syswow64\jffgec32.dll Generic Write,Read Attributes
c:\windows\syswow64\jhojgh32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jhojgh32.exe Generic Write,Read Attributes
c:\windows\syswow64\jjlfgk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jjlfgk32.exe Generic Write,Read Attributes
c:\windows\syswow64\jjobipgj.dll Generic Write,Read Attributes
c:\windows\syswow64\jjqobjee.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jjqobjee.exe Generic Write,Read Attributes
c:\windows\syswow64\jkgkkj32.dll Generic Write,Read Attributes
c:\windows\syswow64\jlbhamje.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jlbhamje.exe Generic Write,Read Attributes
c:\windows\syswow64\jlpllmlh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jlpllmlh.exe Generic Write,Read Attributes
c:\windows\syswow64\jmfjoj32.dll Generic Write,Read Attributes
c:\windows\syswow64\jnjomi32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jnjomi32.exe Generic Write,Read Attributes
c:\windows\syswow64\kaaafljm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kaaafljm.exe Generic Write,Read Attributes
c:\windows\syswow64\kacnll32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kacnll32.exe Generic Write,Read Attributes
c:\windows\syswow64\kadkmehg.dll Generic Write,Read Attributes
c:\windows\syswow64\kbihop32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kbihop32.exe Generic Write,Read Attributes
c:\windows\syswow64\keghojlb.dll Generic Write,Read Attributes
c:\windows\syswow64\kejqak32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kejqak32.exe Generic Write,Read Attributes
c:\windows\syswow64\keland32.dll Generic Write,Read Attributes
c:\windows\syswow64\kfadcfgb.dll Generic Write,Read Attributes
c:\windows\syswow64\kfngpl32.dll Generic Write,Read Attributes
c:\windows\syswow64\kiobka32.dll Generic Write,Read Attributes
c:\windows\syswow64\kjheciom.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjheciom.exe Generic Write,Read Attributes
c:\windows\syswow64\kjjbhimk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjjbhimk.exe Generic Write,Read Attributes
c:\windows\syswow64\kjlonh32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjlonh32.exe Generic Write,Read Attributes
c:\windows\syswow64\kjolch32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjolch32.exe Generic Write,Read Attributes
c:\windows\syswow64\kllnkonc.dll Generic Write,Read Attributes
c:\windows\syswow64\klqhan32.dll Generic Write,Read Attributes
c:\windows\syswow64\ladclq32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ladclq32.exe Generic Write,Read Attributes
c:\windows\syswow64\lahhgkce.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lahhgkce.exe Generic Write,Read Attributes
c:\windows\syswow64\lamabj32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lamabj32.exe Generic Write,Read Attributes
c:\windows\syswow64\lbadgo32.dll Generic Write,Read Attributes
c:\windows\syswow64\lbgdqn32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lbgdqn32.exe Generic Write,Read Attributes
c:\windows\syswow64\lbmjed32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lbmjed32.exe Generic Write,Read Attributes
c:\windows\syswow64\lbofkd32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lbofkd32.exe Generic Write,Read Attributes
c:\windows\syswow64\leagaj32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\leagaj32.exe Generic Write,Read Attributes
c:\windows\syswow64\lekjhhff.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lekjhhff.exe Generic Write,Read Attributes
c:\windows\syswow64\lganqe32.dll Generic Write,Read Attributes
c:\windows\syswow64\ljahihgb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ljahihgb.exe Generic Write,Read Attributes
c:\windows\syswow64\lkceogep.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lkceogep.exe Generic Write,Read Attributes
c:\windows\syswow64\lmiqjbck.dll Generic Write,Read Attributes
c:\windows\syswow64\lqikeb32.dll Generic Write,Read Attributes
c:\windows\syswow64\maajmikj.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\maajmikj.exe Generic Write,Read Attributes
c:\windows\syswow64\madnpkhn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\madnpkhn.exe Generic Write,Read Attributes
c:\windows\syswow64\magpap32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\magpap32.exe Generic Write,Read Attributes
c:\windows\syswow64\makimppm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\makimppm.exe Generic Write,Read Attributes
c:\windows\syswow64\mamhol32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\mamhol32.exe Generic Write,Read Attributes

103 additional files are not displayed above.

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hhfnim32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mfhlpgbp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Folepl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dkcild32.dll RegNtPreCreateKey
Show More
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lqikeb32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lbadgo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mjcbee32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hbjknpbb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Fkccef32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Fmmeml32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Oiqgmoam.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mnlgke32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pfniejbd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Kiobka32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Abmmqkei.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Klqhan32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Bqeola32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Nmnccd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Nlndahnj.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pbecdo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lganqe32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dfiaoefc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pmnmmf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hinpjk32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dmmjgdde.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lmiqjbck.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Omcoan32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pjjjnpeg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ihfgmj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hhgnei32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Hijdfa32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mkbfdl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Aqhnkflf.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Bogeobnn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Nbfolk32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Biibpjmp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Bfjngalp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dncaic32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dnmmnn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ilebdfib.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mfddbipi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Gqccpjmi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jaaqpela.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Oabenc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hmoioc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mlepno32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jkgkkj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Fdabdd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hnepfmkm.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Obnelmjg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ocqkmdnf.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hgmdlb32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Keland32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kfngpl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Aohkhm32.dll RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ooqkbi32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Keghojlb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Cchnbieo.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Fffkjj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hjjiehoh.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hennea32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Namehg32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Flpfac32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dbkdgk32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Anpilcbe.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jjobipgj.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Clgkhklk.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Qdhoibjn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kfadcfgb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dogahd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Indlohdn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Mgfkljpe.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kllnkonc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Aadljlfl.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Fmkaeo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Dlcniomc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ddniaa32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ndbhmc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ofmllaja.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Anaikf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Adeohhdf.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ilnmcofj.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Djmffo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Nqoenn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jmfjoj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Akmflp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ohcmlmio.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jclaqemi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Ppmgibkg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Nnkbogdp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Kadkmehg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Gejlcm32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Cbcmkn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Jffgec32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Apapmj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Pnklhifo.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Nfmienpn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Fdhcmiod.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Pfoiaj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Nhbnnbap.dll RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

C:\WINDOWS\system32\Nhiokagg.exe
C:\WINDOWS\system32\Namjiham.exe
C:\WINDOWS\system32\Mkaefnlc.exe
C:\WINDOWS\system32\Mllhea32.exe
C:\WINDOWS\system32\Mhnooc32.exe
Show More
C:\WINDOWS\system32\Maajmikj.exe
C:\WINDOWS\system32\Lekjhhff.exe
C:\WINDOWS\system32\Lamabj32.exe
C:\WINDOWS\system32\Lbgdqn32.exe
C:\WINDOWS\system32\Lahhgkce.exe
C:\WINDOWS\system32\Leagaj32.exe
C:\WINDOWS\system32\Kacnll32.exe
C:\WINDOWS\system32\Kaaafljm.exe
C:\WINDOWS\system32\Kejqak32.exe
C:\WINDOWS\system32\Kbihop32.exe
C:\WINDOWS\system32\Jeckplja.exe
C:\WINDOWS\system32\Jhojgh32.exe
C:\WINDOWS\system32\Jeoaem32.exe

Trending

Most Viewed

Loading...