Threat Database Bad Toolbars FunMoods Toolbar

FunMoods Toolbar

By CagedTech in Bad Toolbars

Threat Scorecard

Popularity Rank: 2,506
Threat Level: 50 % (Medium)
Infected Computers: 146,538
First Seen: January 18, 2012
Last Seen: April 17, 2026
OS(es) Affected: Windows

File System Details

FunMoods Toolbar may create the following file(s):
# File Name MD5 Detections
1. chromestb.exe 82505ac4ae4839d83b76065c6f6f58c6 3,172
2. funmoods.exe c6feedb53033258797c4769861ba9f3d 21
3. Toolbar_Phpnuke.exe 8c5fff3409e4fddf109a0956e117e556 8
4. UpdateTask.exe 0e259e4b82811137a1e88cdfd349f412 7
More files

Registry Details

FunMoods Toolbar may create the following registry entry or registry entries:
CLSID
{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}
{75A4D144-506D-4BE5-81DB-EC7DA1E7F840}
{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
{965B9DBE-B104-44AC-950A-8A5F97AFF439}
{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
{A9DB719C-7156-415E-B49D-BAD039DE4F13}
{EA28B360-05E0-4F93-8150-02891F1D8D3C}
{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9}
File name without path
funmoods-speeddial.crx
Regexp file mask
%LOCALAPPDATA%\funmoods-speeddial_sf.crx
%LOCALAPPDATA%\funmoods.crx
%LOCALAPPDATA%\funmoods.exe
%USERPROFILE%\Local Settings\Application Data\funmoods-speeddial_sf.crx
%USERPROFILE%\Local Settings\Application Data\funmoods.crx
SOFTWARE\Classes\AppID\escort.DLL
SOFTWARE\Classes\AppID\escortApp.DLL
SOFTWARE\Classes\AppID\escortEng.DLL
SOFTWARE\Classes\AppID\escorTlbr.DLL
SOFTWARE\Classes\AppID\esrv.EXE
SOFTWARE\Classes\escort.escortIEPane
SOFTWARE\Classes\escort.escortIEPane.1
SOFTWARE\Classes\esrv.funmoodsESrvc
SOFTWARE\Classes\esrv.funmoodsESrvc.1
SOFTWARE\Classes\funmoods.dskBnd
SOFTWARE\Classes\funmoods.dskBnd.1
SOFTWARE\Classes\funmoods.funmoodsHlpr
SOFTWARE\Classes\funmoods.funmoodsHlpr.1
SOFTWARE\Classes\funmoodsApp.appCore
SOFTWARE\Classes\funmoodsApp.appCore.1
SOFTWARE\Classes\Wow6432Node\AppID\escort.DLL
SOFTWARE\Classes\Wow6432Node\AppID\escortApp.DLL
SOFTWARE\Classes\Wow6432Node\AppID\escortEng.DLL
SOFTWARE\Classes\Wow6432Node\AppID\escorTlbr.DLL
SOFTWARE\Classes\Wow6432Node\AppID\esrv.EXE
Software\funmoods
Software\funmoodsToolbar
Software\Microsoft\Internet Explorer\DOMStorage\searchfunmoods.com
Software\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Funmoods
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
SOFTWARE\Wow6432Node\Classes\AppID\escort.DLL
SOFTWARE\Wow6432Node\Classes\AppID\escortEng.DLL
SOFTWARE\Wow6432Node\Classes\AppID\esrv.EXE
SOFTWARE\Wow6432Node\Funmoods
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
SOFTWARE\Wow6432Node\Microsoft\Tracing\FunmoodsSetup_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\FunmoodsSetup_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\FUNMOO~1_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\FUNMOO~1_RASMANCS
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}

Directories

FunMoods Toolbar may create the following directory or directories:

%APPDATA%\Funmoods
%PROGRAMFILES%\Funmoods
%PROGRAMFILES(x86)%\Funmoods
%USERPROFILE%\AppData\LocalLow\Funmoods

URLs

FunMoods Toolbar may call the following URLs:

http://searchfunmoods.com/results.php?q

Analysis Report

General information

Family Name: FunMoods Toolbar
Packers: UPX
Signature status: Self Signed

Known Samples

MD5: 013bb9e47f387d987335d5b22ca0035a
SHA1: f1653f0771a0956e734cb6fb95ab0cf877822be4
SHA256: 7FF082B572AC6D0F15F0D9C648236EB5F2414674742A27DFE6EAF53C86532AFA
File Size: 669.40 KB, 669400 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name InstallCore ©
File Description InstallCore© Installer
File Version 1, 0, 0, 9
Internal Name Installer Powered by installcore.com - SDK v2.1
Legal Copyright Copyright © InstallCore
Product Name InstallCore© Installer
Product Version 1, 0, 0, 9

Digital Signatures

Signer Root Status
Volonet Ltd Volonet Ltd Self Signed

Block Information

Total Blocks: 3,735
Potentially Malicious Blocks: 341
Whitelisted Blocks: 2,959
Unknown Blocks: 435

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x ? ? 0 0 x ? 0 0 0 0 0 0 0 x x x x 0 x 0 x x 0 x 0 0 0 0 0 0 0 0 0 x x x x x x x x ? x 0 x x x x 0 0 x 0 x 0 0 x x x x 0 ? 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 x x x x x x x x 0 ? 0 0 0 0 0 x 0 x 0 x ? 0 ? ? 0 0 0 x ? 0 0 0 0 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\1vtp0f0a0c0e0m0o0o0d0stp1v Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\1vtp0f0a0c0e0m0o0o0d0stp1v_test Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\0020b913.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\0032c9ae.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\css\ie6_main.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\css\ie6_main.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\css\ie6_main.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\browse.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\browse.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\browse.css Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\button.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\button.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\button.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\checkbox.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\checkbox.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\checkbox.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\images\button-bg.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\images\button-bg.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\images\button-bg.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\images\progress-bg.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\images\progress-bg.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\images\progress-bg.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\progress-bar.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\progress-bar.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\css\sdk-ui\progress-bar.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\css\style.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\css\style.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\css\style.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\defaultoffer\ad_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\defaultoffer\ad_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\defaultoffer\ad_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\defaultoffer\ad_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\bb-logo.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\bb-logo.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\bb-logo.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\box-facemoods.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\box-facemoods.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\box-facemoods.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\box.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\box.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\box.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\butt-grn.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\butt-grn.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\butt-grn.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\butt-gry.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\butt-gry.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\butt-gry.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\buttons.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\buttons.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\buttons.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\en.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\en.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\en.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\es.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\es.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\es.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\fr.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\fr.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\fr.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\it.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\it.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\it.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\logo.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\logo.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\logo.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\never-miss.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\never-miss.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\never-miss.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\package\babylon_logo.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\package\babylon_logo.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\package\babylon_logo.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\package\installer-pic.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\package\installer-pic.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\package\installer-pic.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\package\pkg_screenshot.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\package\pkg_screenshot.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\package\pkg_screenshot.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\progress-bg.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\progress-bg.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\progress-bg.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\wdt.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\wdt.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\wdt.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\images\x.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\images\x.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\images\x.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\license\license_en.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\license\license_en.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\license\license_en.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\license\license_es.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\license\license_es.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\license\license_es.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\license\license_fr.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\license\license_fr.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\license\license_fr.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\license\license_it.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\license\license_it.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\license\license_it.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\locale\en.locale Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\locale\en.locale Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\locale\en.locale Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\locale\es.locale Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\locale\es.locale Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\locale\es.locale Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\locale\fr.locale Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\locale\fr.locale Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\locale\fr.locale Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\locale\it.locale Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\locale\it.locale Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\locale\it.locale Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\ask\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\ask\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\ask\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\ask\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\ask\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\ask\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\bb\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\bb\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\bb\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\bb\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\bb\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\bb\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\dp\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\dp\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\dp\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\dp\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\dp\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\dp\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\fm\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\fm\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\fm\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\fm\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\fm\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\fm\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\sn\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\sn\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\sn\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\sn\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\sn\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\sn\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\wdt\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\wdt\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\wdt\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\wdt\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\offers\wdt\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\offers\wdt\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish2144531\sdk\exceptlist.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish2144531\sdk\exceptlist.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish2144531\sdk\exceptlist.txt Synchronize,Write Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Network Info Queried
  • GetAdaptersInfo
Network Wininet
  • InternetOpen

Related Posts

Trending

Most Viewed

Loading...