Threat Database Adware Adware.Optserve

Adware.Optserve

By JubileeX in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 51
First Seen: December 1, 2009
Last Seen: October 23, 2025
OS(es) Affected: Windows

Adware.Optserve is a malicious adware application. A PC infected with Adware.Optserve may have had several popup alerts displayed on a consistent basis. Some of the adverts could lead to phishing sites or forms that are designed to collect personal data. To completely eliminate the threat of Adware.Optserve, a computer user may need to take use of a trusted spyware removal program.

Aliases

14 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AVG Generic3.EFL
Avast Win32:Adware-gen
McAfee Generic PUP.x!dm
Sunbelt Adware.Optserve
Panda Generic Malware
NOD32 Win32/Adware.Optmedia
McAfee-GW-Edition Riskware.Tool.Small.40960.21003
McAfee potentially unwanted program Generic PUP
Ikarus Virus.Win32.AdWare
F-Secure Adware:W32/Optserve.A
Comodo ApplicUnwnt.Win32.Adware.Optmedia
BitDefender Gen:Trojan.Heur.VB.cm0@dC3oycdi
AntiVir SPR/Tool.Small.40960.21003
a-squared Virus.Win32.AdWare!IK

SpyHunter Detects & Remove Adware.Optserve

File System Details

Adware.Optserve may create the following file(s):
# File Name MD5 Detections
1. optserve.exe b4e15375247764b6f03c54d65ea5e7fd 6
2. LP.exe a6b01a26cd060ee979a1affa1f851452 5

Analysis Report

General information

Family Name: Adware.Optserve
Signature status: Self Signed

Known Samples

MD5: 7e4ee31db440d60608298f1197a49524
SHA1: 7b7daac9ab6636a02452ca9ded0dd3eb1ed2c133
SHA256: 03C96D9FE8D9BED3E7C1BB404C1794B93A3CE2609BCFF4F5839D7DA6C1DFA125
File Size: 9.79 MB, 9788304 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Macrovision Corporation
File Description Setup.exe
File Version 10.50.125
Internal Name Setup
Legal Copyright Copyright (C) 2004 Macrovision Corporation
Original Filename Setup.exe
Product Name InstallShield (R)
Product Version 10.50

Digital Signatures

Signer Root Status
Optlynx CO., LTD. VeriSign Class 3 Code Signing 2004 CA Self Signed

Files Modified

File Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ctof36f.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ctof36f.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ctor.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\dotf33f.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\dotf33f.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\dotnetinstaller.exe Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\igdi.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ikef30f.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ikef30f.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ikernel.dll Synchronize,Write Data
Show More
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\iscf3af.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\iscf3af.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\iscript.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ispf144.tmp\setup.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ispf144.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ispf222.tmp\igdi.dll Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ispf222.tmp\igdi.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\ispf222.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\iuser.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\iusf3cf.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\iusf3cf.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\setf155.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\50\intel32\setup.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\ikernel.rgs Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\ikernel.rgs Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\ispf3ff.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\ispf3ff.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\isprobe.tlb Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\program files (x86)\common files\installshield\professional\runtime\objectps.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\objf43e.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\objf43e.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\_sef263.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\byeeed1.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\byeeed1.tmp\disk1\data1.cab Generic Write,Read Attributes
c:\users\user\appdata\local\temp\byeeed1.tmp\disk1\data1.hdr Generic Write,Read Attributes
c:\users\user\appdata\local\temp\byeeed1.tmp\disk1\engine32.cab Generic Write,Read Attributes
c:\users\user\appdata\local\temp\byeeed1.tmp\disk1\layout.bin Generic Write,Read Attributes
c:\users\user\appdata\local\temp\byeeed1.tmp\disk1\setup.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\byeeed1.tmp\disk1\setup.ibt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\byeeed1.tmp\disk1\setup.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\byeeed1.tmp\disk1\setup.inx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\f7d9.rra Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\igdf233.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ispackfiles.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ispf221.tmp\_setup.dll Synchronize,Write Data
c:\users\user\appdata\local\temp\ispf221.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\issefbd.tmp\setup.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{37c46315-8316-48cf-bc60-881ef6c9fa3c}\{ae76836f-7e27-4738-816c-3bbb7ca8f635}\setufa0b.rra Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{37c46315-8316-48cf-bc60-881ef6c9fa3c}\{ae76836f-7e27-4738-816c-3bbb7ca8f635}\setup.inx Synchronize,Write Attributes
c:\users\user\appdata\local\temp\{37c46315-8316-48cf-bc60-881ef6c9fa3c}\{ae76836f-7e27-4738-816c-3bbb7ca8f635}\setup.inx Synchronize,Write Data
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\6c8224a969ef03817452b235c88b65a3_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{f4817e4b-04b6-11d3-8862-00c04f72f303}\inprocserver32:: C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f4817e4b-04b6-11d3-8862-00c04f72f303}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f4817e4b-04b6-11d3-8862-00c04f72f303}:: PSFactoryBuffer RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f4817e4b-04b6-11d3-8862-00c04f72f303}\proxystubclsid32:: {F4817E4B-04B6-11D3-8862-00C04F72F303} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f4817e4b-04b6-11d3-8862-00c04f72f303}:: ISetupServiceProvider RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f4817e4b-04b6-11d3-8862-00c04f72f303}\nummethods:: 6 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9b697780-dbbc-11d2-80c7-00104b1f6cea}\proxystubclsid32:: {F4817E4B-04B6-11D3-8862-00C04F72F303} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9b697780-dbbc-11d2-80c7-00104b1f6cea}:: ISetupObjectClass RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9b697780-dbbc-11d2-80c7-00104b1f6cea}\nummethods:: 5 RegNtPreCreateKey
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0:: InstallShield Setup Kernel RegNtPreCreateKey
Show More
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0\flags:: 0 RegNtPreCreateKey
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0\0\win32:: C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\IsProBE.tlb RegNtPreCreateKey
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0\helpdir:: C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}:: ISetupTransferEvents RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}:: ISetupTransferEvents RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}:: ISetupFeature RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}:: ISetupFeature RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}:: ISetupBasicFeature RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}:: ISetupBasicFeature RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLog RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLog RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLogs RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLogs RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpSequence RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpSequence RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}:: ISetupLogDB RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}:: ISetupLogDB RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpTypes RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpTypes RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpType RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpType RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}:: ISetupBasicFeatureStateEvents RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}:: ISetupBasicFeatureStateEvents RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}:: ISetupFeatures RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}:: ISetupFeatures RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}:: ISetupTransferEvents2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}:: ISetupTransferEvents2 RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}:: ISetupTransferEvents3 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}:: ISetupTransferEvents3 RegNtPreCreateKey
HKLM\software\classes\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}:: ISetupLogDB2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}:: ISetupLogDB2 RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}:: ISetupOpSequence2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}:: ISetupOpSequence2 RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2a652f47-a8ce-414c-bbb4-203a59031056}:: ISetupScriptDebugEngineOld_3 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2a652f47-a8ce-414c-bbb4-203a59031056}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2a652f47-a8ce-414c-bbb4-203a59031056}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2a652f47-a8ce-414c-bbb4-203a59031056}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{2a652f47-a8ce-414c-bbb4-203a59031056}:: ISetupScriptDebugEngineOld_3 RegNtPreCreateKey
HKLM\software\classes\interface\{2a652f47-a8ce-414c-bbb4-203a59031056}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{2a652f47-a8ce-414c-bbb4-203a59031056}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{2a652f47-a8ce-414c-bbb4-203a59031056}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a434ac6f-7286-42c3-982b-20f00263501b}:: ISetupScriptStackFrameOld_3 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a434ac6f-7286-42c3-982b-20f00263501b}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a434ac6f-7286-42c3-982b-20f00263501b}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a434ac6f-7286-42c3-982b-20f00263501b}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{a434ac6f-7286-42c3-982b-20f00263501b}:: ISetupScriptStackFrameOld_3 RegNtPreCreateKey
HKLM\software\classes\interface\{a434ac6f-7286-42c3-982b-20f00263501b}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{a434ac6f-7286-42c3-982b-20f00263501b}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{a434ac6f-7286-42c3-982b-20f00263501b}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6d0a2c7b-875f-40e7-b7be-2e909a3a9026}:: ISetupScriptErrorOld_3 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6d0a2c7b-875f-40e7-b7be-2e909a3a9026}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6d0a2c7b-875f-40e7-b7be-2e909a3a9026}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6d0a2c7b-875f-40e7-b7be-2e909a3a9026}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{6d0a2c7b-875f-40e7-b7be-2e909a3a9026}:: ISetupScriptErrorOld_3 RegNtPreCreateKey
HKLM\software\classes\interface\{6d0a2c7b-875f-40e7-b7be-2e909a3a9026}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{6d0a2c7b-875f-40e7-b7be-2e909a3a9026}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{6d0a2c7b-875f-40e7-b7be-2e909a3a9026}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{fbd42940-b837-40eb-bdb4-86ae00e1d0d1}:: ISetupScriptDebuggerOld_3 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{fbd42940-b837-40eb-bdb4-86ae00e1d0d1}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{fbd42940-b837-40eb-bdb4-86ae00e1d0d1}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{fbd42940-b837-40eb-bdb4-86ae00e1d0d1}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{fbd42940-b837-40eb-bdb4-86ae00e1d0d1}:: ISetupScriptDebuggerOld_3 RegNtPreCreateKey
HKLM\software\classes\interface\{fbd42940-b837-40eb-bdb4-86ae00e1d0d1}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{fbd42940-b837-40eb-bdb4-86ae00e1d0d1}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{fbd42940-b837-40eb-bdb4-86ae00e1d0d1}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a06d036f-984f-4482-ad5c-ebd11a638b4c}:: ISetupScriptDebuggerOld2_3 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a06d036f-984f-4482-ad5c-ebd11a638b4c}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a06d036f-984f-4482-ad5c-ebd11a638b4c}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a06d036f-984f-4482-ad5c-ebd11a638b4c}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{a06d036f-984f-4482-ad5c-ebd11a638b4c}:: ISetupScriptDebuggerOld2_3 RegNtPreCreateKey
HKLM\software\classes\interface\{a06d036f-984f-4482-ad5c-ebd11a638b4c}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{a06d036f-984f-4482-ad5c-ebd11a638b4c}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{a06d036f-984f-4482-ad5c-ebd11a638b4c}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}:: ISetupScriptDebugEngineOld_2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}:: ISetupScriptDebugEngineOld_2 RegNtPreCreateKey
HKLM\software\classes\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}:: ISetupScriptStackFrameOld_2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}:: ISetupScriptStackFrameOld_2 RegNtPreCreateKey
HKLM\software\classes\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}:: ISetupScriptErrorOld_2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}:: ISetupScriptErrorOld_2 RegNtPreCreateKey
HKLM\software\classes\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}:: ISetupScriptDebuggerOld_2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey

760 additional registry modifications are not displayed above.

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

c:\users\user\downloads\7b7daac9ab6636a02452ca9ded0dd3eb1ed2c133_0009788304 -deleter

Trending

Most Viewed

Loading...