Threat Database Browser Hijackers Certified-Toolbar.com

Certified-Toolbar.com

By CagedTech in Browser Hijackers
Published:
Last updated:

Threat Scorecard

Popularity Rank: 7,812
Threat Level: 50 % (Medium)
Infected Computers: 41,440
First Seen: October 29, 2012
Last Seen: October 2, 2026
OS(es) Affected: Windows

The detection of Certified-Toolbar.com on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its characteristics, and the necessary steps to remove it from your system.

What Is Certified-Toolbar.com?

Certified-Toolbar.com is a type of malicious software that has been detected on your system. While the specifics of this threat are not detailed here, it is essential to understand that malicious software like Certified-Toolbar.com can compromise the security and integrity of your computer. Malware of this nature can be used for a variety of malicious purposes, including data theft, unauthorized access, and disruption of system operations.

How Certified-Toolbar.com Operates

Malicious software operates by exploiting vulnerabilities in software or manipulating user behavior to gain unauthorized access to computer systems. Once inside, it can perform a range of malicious activities, from stealing sensitive information to using the infected computer as part of a larger network of compromised machines. The operation of Certified-Toolbar.com, like other malware, is designed to evade detection and persist on the system, making removal challenging without proper tools and techniques.

Symptoms of Infection

Symptoms of a malware infection can vary widely but often include unusual system behavior, such as unexpected pop-ups, slow system performance, and unfamiliar programs or toolbars appearing on your browser. In some cases, the infection may not exhibit obvious symptoms, making it difficult for users to detect without the aid of security software. Regular system monitoring and the use of reputable antivirus tools are crucial in identifying and mitigating such threats.

How to Remove Certified-Toolbar.com

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to identify and remove all components of the malware.
  3. Uninstall any suspicious programs or applications that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and perform another full scan to ensure that all malware components have been removed.

It's essential to follow these steps carefully and consider seeking professional help if you're not comfortable with the process or if the malware persists after attempted removal.

Conclusion

The removal of Certified-Toolbar.com from your system requires a thorough and careful approach to ensure all malicious components are eliminated. By understanding the nature of the threat and following the recommended removal procedures, you can help protect your system and data from further compromise. Regularly updating your security software, practicing safe browsing habits, and maintaining awareness of potential threats are key to preventing future malware infections.

SpyHunter Detects & Remove Certified-Toolbar.com

File System Details

Certified-Toolbar.com may create the following file(s):
# File Name MD5 Detections
1. CertifiedToolbarBRToolbar.dll 7dd14a648302410a63b3795c8b9a4b36 5
2. CertifiedToolbar.dll e6a6662cf3c5834e7a518d028a1e9445 1
3. CertifiedToolbar7art.dll 413551a108860b4cc0fb425008aaa9b5 1
More files

Registry Details

Certified-Toolbar.com may create the following registry entry or registry entries:
CLSID
{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Regexp file mask
%PROGRAMFILES%\Mozilla Firefox\searchplugins\Web Search.xml
%PROGRAMFILES(x86)%\Mozilla Firefox\searchplugins\Web Search.xml
Software\AppDataLow\Software\Simplytech
Software\AppDataLow\Software\Simplytech\CertifiedToolbar
Software\CertifiedToolbar
SOFTWARE\Classes\AppID\CertifiedToolbar.DLL
SOFTWARE\Classes\Wow6432Node\AppID\CertifiedToolbar.DLL
Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{8ce31ebd-051a-495f-9b41-3cc886889da8}
SOFTWARE\Microsoft\Internet Explorer\Extensions\{1c632c0a-9751-4778-8ef1-a1778a4d0caf}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8CE31EBD-051A-495F-9B41-3CC886889DA8}
Software\SimplyTech
Software\SimplyTech\CertifiedToolbar
SOFTWARE\Wow6432Node\Classes\AppID\CertifiedToolbar.DLL
SOFTWARE\Wow6432Node\Microsoft\Tracing\CertifiedToolbar_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\CertifiedToolbar_RASMANCS

Directories

Certified-Toolbar.com may create the following directory or directories:

%APPDATA%\CertifiedToolbar7art
%APPDATA%\CertifiedToolbarBRToolbar
%AppData%\CertifiedToolbar
%PROGRAMFILES%\CertifiedToolbar
%PROGRAMFILES(x86)%\CertifiedToolbar
%ProgramFiles%\DownTangoLauncherToolbar
%UserProfile%\AppData\LocalLow\CertifiedToolbar
%UserProfile%\AppData\LocalLow\DownTangoLauncherToolbar
%UserProfile%\AppData\LocalLow\SimplyTech\Toolbar

Analysis Report

General information

Family Name: Certified-Toolbar.com
Signature status: Root Not Trusted

Known Samples

MD5: d54f999465e0b86b0142260714b16645
SHA1: 2c3920f5ba90b9883303835fa83707960e984020
File Size: 958.28 KB, 958280 bytes
MD5: b66fbe63d4e816e82f3f21ef5a9574a6
SHA1: 61f53a4ae3d2784678bb2c4364338aebe0f20ef8
File Size: 3.63 MB, 3627072 bytes
MD5: 90bec934d0741a7d93d45fc93fdb782a
SHA1: 7511a10cb223592a94090bf910e55777fc5ae9aa
SHA256: 571981C22F9ED0CB58F02DD2E29946E58F73E875933CC5F55F6FEA611A7BCB8C
File Size: 1.03 MB, 1031752 bytes
MD5: 61a10e1d30f8c75d8a493bbc493accf8
SHA1: 955458078929d84d4df17473f8aa79583b746b24
SHA256: CDAD1ABCCC6B306958704CBF8090BA112A9D21484855EA1C90061F52647153E8
File Size: 946.38 KB, 946376 bytes
MD5: 43d135ffca0a541fcbe42ba1b09aeb94
SHA1: 5e8e0d0e4bfe72ff8f9354f26975fcdfe18c4dc8
SHA256: 5743CC0CBA63D2D52A186C0E68627C7C393E9D2BCCB7B36F2E55D93F7A2A6947
File Size: 6.50 MB, 6503038 bytes
Show More
MD5: 751ff0d89ac1f830d67108780639f7bc
SHA1: 8b9d760f06cf247929e318a85b0aeb555e9a98c4
SHA256: 47C3E77FB9BD2ABC0D0BE752369FB081BC4B12264CC9C87A5BBBBE09470B5518
File Size: 4.72 MB, 4718520 bytes
MD5: 613bf49d6b3821e9d71d199271e7ea40
SHA1: 60b81a81b419944760560ea4ebce7a195a5c8678
SHA256: BC526C70EB2CF380F4BF9D202BA0F29BD5CC21E76D2F2EEEB04A785FA6BC4350
File Size: 5.89 MB, 5889560 bytes
MD5: 0d4d274e516e1226ea9c11ca88d7a72e
SHA1: f7234f039d6d57e324cd436f6e2a926835db3293
SHA256: D8EB62FCAEB05D3D7548E6581C92BFB1A22488457C99EEEC54566FF61347DBB1
File Size: 958.31 KB, 958312 bytes
MD5: 6ca5f7e2043e942f24fa703d9132174d
SHA1: eaeee23876759b6ed1591cab03751e63f8e6a504
SHA256: 590216AF46DA5688A8FCD908B6F462D2EBDFDA8DE33679828A02BCA9BC5C8EC4
File Size: 3.75 MB, 3749496 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • Certified-Toolbar By Simplytech
  • This installation was built with Inno Setup.
Company Name
  • CooolSoft, Inc.
  • HomeTab
  • SimplyTech LTD
  • Simplytech Ltd.
File Description
  • HomeTab Setup
  • Installer Setup
  • Power MP3 Recorder Cutter
  • Simplytech toolbar
  • SoloApp Setup
File Version
  • 9.5
  • 8.4
  • 8.2
  • 6.0.0.0
  • 6.0
  • 5.7
  • 4.7
  • 1.9
  • 1.6
Internal Name CertifiedToolbar.DLL
Legal Copyright
  • 2012 Simplytech. All rights reserved.
  • Copyright(c) 2011, CooolSoft, Inc.
  • Copyright (c) 2012, www.simplytech.com
Original Filename CertifiedToolbar.DLL
Product Name
  • HomeTab
  • Installer
  • Power MP3 Recorder Cutter
  • Simplytech Toolbar
  • SoloApp
Product Version
  • 9.5
  • 8.4
  • 8.2
  • 6.0.0.0
  • 6.0
  • 5.7
  • 4.7
  • 1.9
  • 1.6

Digital Signatures

Signer Root Status
Simply Tech Ltd UTN-USERFirst-Object Root Not Trusted
Simply Tech Ltd UTN-USERFirst-Object Hash Mismatch

Block Information

Similar Families

  • Widdit.A

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-19e4g.tmp\61f53a4ae3d2784678bb2c4364338aebe0f20ef8_0003627072.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-19e4g.tmp\interop.iwshruntimelibrary.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-19e4g.tmp\system.data.sqlite.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-1s03v.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-1s03v.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3uhmh.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3uhmh.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3uhmh.tmp\cinshlpr.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3uhmh.tmp\installhelper.dll Synchronize,Write Data
c:\users\user\appdata\local\temp\is-3uhmh.tmp\installhelpernet4.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\is-3uhmh.tmp\interop.iwshruntimelibrary.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3uhmh.tmp\isxdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3uhmh.tmp\mainlogo.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3uhmh.tmp\system.data.sqlite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-4bo5m.tmp\60b81a81b419944760560ea4ebce7a195a5c8678_0005889560.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7bf9f.tmp\5e8e0d0e4bfe72ff8f9354f26975fcdfe18c4dc8_0006503038.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pela.tmp\eaeee23876759b6ed1591cab03751e63f8e6a504_0003749496.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7pela.tmp\interop.iwshruntimelibrary.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-7pela.tmp\system.data.sqlite.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-7radc.tmp\2c3920f5ba90b9883303835fa83707960e984020_0000958280.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-9tfhu.tmp\f7234f039d6d57e324cd436f6e2a926835db3293_0000958312.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-eugnr.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-eugnr.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-fklmr.tmp\955458078929d84d4df17473f8aa79583b746b24_0000946376.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-k4h51.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-k4h51.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-k4h51.tmp\innocallback.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-k4h51.tmp\innosetuphelper.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-k4h51.tmp\isxdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-k4h51.tmp\webbrowser.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-lqjhu.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-lqjhu.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-lqjhu.tmp\cinshlpr.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-lqjhu.tmp\innocallback.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-lqjhu.tmp\innosetuphelper.dll Synchronize,Write Data
c:\users\user\appdata\local\temp\is-lqjhu.tmp\innosetuphelpernet4.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-lqjhu.tmp\isxdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-lqjhu.tmp\webbrowser.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-mm2cq.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-mm2cq.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-mm2cq.tmp\cinshlpr.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-mm2cq.tmp\installhelper.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-mm2cq.tmp\interop.iwshruntimelibrary.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-mm2cq.tmp\isxdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-mm2cq.tmp\system.data.sqlite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-pi8mf.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-pi8mf.tmp\appimage.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\appimageorign.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\appimageorign.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\arrows.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\arrows_trans.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\bottom.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\cinshlpr.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\decline_gray.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\eula.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\finish.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\innocallback.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\innosetuphelper.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\installer_close.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\installer_close_trans.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\isxdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\next.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\next_gray.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\skip.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\top.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\trusted.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\trusted_trans.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pi8mf.tmp\webbrowser.dll Generic Write,Read Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\1f356f4d07fe8c483e769e4586569404 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\3b6e683a7a45cc59bf035c9ba8c7ab9d Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\5457a8ce4b2a7499f8299a013b6e1c7c_d734ec3dd00546f46d368325396086b0 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\b90b117906b8a74c79d1bc450c2b94b1_a54f26a8a41de52c237d54d67f12793f Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\f4d9c889b7aebcf4e1a2daabc5c3628a_68625ac0753813118682bfc7833d0b1e Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\1f356f4d07fe8c483e769e4586569404 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\3b6e683a7a45cc59bf035c9ba8c7ab9d Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\5457a8ce4b2a7499f8299a013b6e1c7c_d734ec3dd00546f46d368325396086b0 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\b90b117906b8a74c79d1bc450c2b94b1_a54f26a8a41de52c237d54d67f12793f Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\f4d9c889b7aebcf4e1a2daabc5c3628a_68625ac0753813118682bfc7833d0b1e Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\simplytech\toolbar\settings.dat Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\approvedextensionsmigration\{7b34775d-ff8b-44b8-a951-d062a0fe77fa}:: RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ������ RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
  • WriteConsole
Encryption Used
  • BCryptOpenAlgorithmProvider
User Data Access
  • GetUserObjectInformation
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiDrawStream
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetEntry
  • win32u.dll!NtGdiGetFontData
  • win32u.dll!NtGdiGetGlyphIndicesW
  • win32u.dll!NtGdiGetOutlineTextMetricsInternalW
  • win32u.dll!NtGdiGetRandomRgn
  • win32u.dll!NtGdiGetRealizationInfo
  • win32u.dll!NtGdiGetTextFaceW
  • win32u.dll!NtGdiGetTextMetricsW
  • win32u.dll!NtGdiGetWidthTable
  • win32u.dll!NtGdiHfontCreate
  • win32u.dll!NtGdiIntersectClipRect
  • win32u.dll!NtGdiQueryFontAssocInfo
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetLayout

61 additional items are not displayed above.

Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Terminate
  • TerminateProcess
Keyboard Access
  • GetKeyState
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

"C:\Users\Wtdgsaii\AppData\Local\Temp\is-7RADC.tmp\2c3920f5ba90b9883303835fa83707960e984020_0000958280.tmp" /SL5="$30240,541375,168448,c:\users\user\downloads\2c3920f5ba90b9883303835fa83707960e984020_0000958280.exe"
"C:\Users\Ejaexwji\AppData\Local\Temp\is-19E4G.tmp\61f53a4ae3d2784678bb2c4364338aebe0f20ef8_0003627072.tmp" /SL5="$5004E,3220606,141824,c:\users\user\downloads\61f53a4ae3d2784678bb2c4364338aebe0f20ef8_0003627072.exe"
open C:\WINDOWS\system32\taskkill /F /IM ProtectedSearch.exe
WriteConsole: ERROR: CoInitial
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7511a10cb223592a94090bf910e55777fc5ae9aa_0001031752.,LiQMAxHB
Show More
"C:\Users\Viczfizl\AppData\Local\Temp\is-FKLMR.tmp\955458078929d84d4df17473f8aa79583b746b24_0000946376.tmp" /SL5="$B005A,526681,146432,c:\users\user\downloads\955458078929d84d4df17473f8aa79583b746b24_0000946376"
"C:\Users\Nwqpdkpf\AppData\Local\Temp\is-7BF9F.tmp\5e8e0d0e4bfe72ff8f9354f26975fcdfe18c4dc8_0006503038.tmp" /SL5="$960064,6116493,140800,c:\users\user\downloads\5e8e0d0e4bfe72ff8f9354f26975fcdfe18c4dc8_0006503038"
"C:\Users\Cteliryq\AppData\Local\Temp\is-4BO5M.tmp\60b81a81b419944760560ea4ebce7a195a5c8678_0005889560.tmp" /SL5="$402E0,5460940,140800,c:\users\user\downloads\60b81a81b419944760560ea4ebce7a195a5c8678_0005889560"
"C:\Users\Tvsqsikg\AppData\Local\Temp\is-9TFHU.tmp\f7234f039d6d57e324cd436f6e2a926835db3293_0000958312.tmp" /SL5="$502EC,541272,168448,c:\users\user\downloads\f7234f039d6d57e324cd436f6e2a926835db3293_0000958312"
"C:\Users\Nuejrvhz\AppData\Local\Temp\is-7PELA.tmp\eaeee23876759b6ed1591cab03751e63f8e6a504_0003749496.tmp" /SL5="$40348,3340468,141824,c:\users\user\downloads\eaeee23876759b6ed1591cab03751e63f8e6a504_0003749496"
WriteConsole: ERROR: The proce
open C:\WINDOWS\system32\taskkill /F /IM WSearchShield.exe
open C:\WINDOWS\system32\taskkill /F /IM SystemSockets.exe
open C:\WINDOWS\system32\taskkill /F /IM WBrowserHandler.exe