Backdoor.Padodor

Por GoldSparrow em Backdoors
Traduzir Para:


O Backdoor.Padodor um é um Trojan de backdoor, que foi projetado para obter acesso não autorizado à máquina do usuário. Normalmente, O Backdoor.Padodor entra no seu sistema através da exploração da segurança do navegador ou de outros mecanismos ilícitos e antiéticos. Uma vez executado, o Backdoor.Padodor se esconde profundamente no sistema, e trabalha em segundo plano. O Backdoor.Padodor pode explorar as vulnerabilidades dos programas instalados ou do sistema operacional e permitir que um invasor remoto obtenha total controle sobre seu PC. O Backdoor.Padodor é uma séria ameaça para a segurança da sua máquina, portanto, recomendamos removê-lo o mais rapidamente possível.

SpyHunter detecta e remove Backdoor.Padodor

Detalhes Sobre os Arquivos do Sistema

Backdoor.Padodor pode criar o(s) seguinte(s) arquivo(s):
# Nome do arquivo MD5 Detecções
1. Jgcdgqbd.exe 27be0da404473def71c58a87ce1ff260 0

Relatório de análise

Informação geral

Family Name: Trojan.Padodor
Signature status: No Signature

Known Samples

MD5: 69f2150a3d86a4f7475e8d4a4609a7da
SHA1: 91df3793e9e8236a3f011af1edb02e744741cdae
SHA256: 0B5403A51A9F067DC658E7FF91EC0FD0897E845666FE69190B66ADF174F9143D
Tamanho do Arquivo: 89.60 KB, 89600 bytes
MD5: 0184bc3f6f6f7d1006297fca3feb7a00
SHA1: 04027407118581f383b9970b322caaca808c1b17
SHA256: 940F9E4A3EEFD8FB7F9FCA8745AFED3ED9136B12A773AB7A86E9DB1D34D7E13F
Tamanho do Arquivo: 91.65 KB, 91648 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • VirtualQueryEx
  • x86

Block Information

Similar Families

  • Qukart.A

Files Modified

File Attributes
c:\windows\syswow64\acmfppob.dll Generic Write,Read Attributes
c:\windows\syswow64\adfkaq32.dll Generic Write,Read Attributes
c:\windows\syswow64\adiejpgl.dll Generic Write,Read Attributes
c:\windows\syswow64\akkame32.dll Generic Write,Read Attributes
c:\windows\syswow64\amaenlae.dll Generic Write,Read Attributes
c:\windows\syswow64\andjdd32.dll Generic Write,Read Attributes
c:\windows\syswow64\aqmepf32.dll Generic Write,Read Attributes
c:\windows\syswow64\banknc32.dll Generic Write,Read Attributes
c:\windows\syswow64\bcoilahd.dll Generic Write,Read Attributes
c:\windows\syswow64\bejbgiqf.dll Generic Write,Read Attributes
Show More
c:\windows\syswow64\biibpjmp.dll Generic Write,Read Attributes
c:\windows\syswow64\bkgpkqii.dll Generic Write,Read Attributes
c:\windows\syswow64\bmlikg32.dll Generic Write,Read Attributes
c:\windows\syswow64\cbnnmh32.dll Generic Write,Read Attributes
c:\windows\syswow64\cjnligob.dll Generic Write,Read Attributes
c:\windows\syswow64\ckgepfqn.dll Generic Write,Read Attributes
c:\windows\syswow64\cmaohmcd.dll Generic Write,Read Attributes
c:\windows\syswow64\cnhchkhj.dll Generic Write,Read Attributes
c:\windows\syswow64\ddffkkgo.dll Generic Write,Read Attributes
c:\windows\syswow64\ddofki32.dll Generic Write,Read Attributes
c:\windows\syswow64\dfiaoefc.dll Generic Write,Read Attributes
c:\windows\syswow64\dhppmh32.dll Generic Write,Read Attributes
c:\windows\syswow64\dibgqp32.dll Generic Write,Read Attributes
c:\windows\syswow64\dkgpihcm.dll Generic Write,Read Attributes
c:\windows\syswow64\dkjonnfn.dll Generic Write,Read Attributes
c:\windows\syswow64\dmkmbj32.dll Generic Write,Read Attributes
c:\windows\syswow64\dmmjgdde.dll Generic Write,Read Attributes
c:\windows\syswow64\dohekp32.dll Generic Write,Read Attributes
c:\windows\syswow64\dqdcde32.dll Generic Write,Read Attributes
c:\windows\syswow64\dqfpiopd.dll Generic Write,Read Attributes
c:\windows\syswow64\eaamijbm.dll Generic Write,Read Attributes
c:\windows\syswow64\ecehhopd.dll Generic Write,Read Attributes
c:\windows\syswow64\edephp32.dll Generic Write,Read Attributes
c:\windows\syswow64\ehneekon.dll Generic Write,Read Attributes
c:\windows\syswow64\fbecfnjl.dll Generic Write,Read Attributes
c:\windows\syswow64\fefegcjb.dll Generic Write,Read Attributes
c:\windows\syswow64\fhpqfpjl.dll Generic Write,Read Attributes
c:\windows\syswow64\fmlnogng.dll Generic Write,Read Attributes
c:\windows\syswow64\fnojfq32.dll Generic Write,Read Attributes
c:\windows\syswow64\folepl32.dll Generic Write,Read Attributes
c:\windows\syswow64\gaikhc32.dll Generic Write,Read Attributes
c:\windows\syswow64\gciamf32.dll Generic Write,Read Attributes
c:\windows\syswow64\gcooge32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gcooge32.exe Generic Write,Read Attributes
c:\windows\syswow64\geocha32.dll Generic Write,Read Attributes
c:\windows\syswow64\ggdnncqd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ggdnncqd.exe Generic Write,Read Attributes
c:\windows\syswow64\giolbg32.dll Generic Write,Read Attributes
c:\windows\syswow64\gjkdip32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gjkdip32.exe Generic Write,Read Attributes
c:\windows\syswow64\gjnqoo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gjnqoo32.exe Generic Write,Read Attributes
c:\windows\syswow64\gkmmib32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\gkmmib32.exe Generic Write,Read Attributes
c:\windows\syswow64\gmgbdb32.dll Generic Write,Read Attributes
c:\windows\syswow64\hbceajhp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hbceajhp.exe Generic Write,Read Attributes
c:\windows\syswow64\hbqhlkjb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hbqhlkjb.exe Generic Write,Read Attributes
c:\windows\syswow64\hcmkhcdf.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hcmkhcdf.exe Generic Write,Read Attributes
c:\windows\syswow64\hcohnc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hcohnc32.exe Generic Write,Read Attributes
c:\windows\syswow64\hdaamfgc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hdaamfgc.exe Generic Write,Read Attributes
c:\windows\syswow64\heckfcee.dll Generic Write,Read Attributes
c:\windows\syswow64\heknkj32.dll Generic Write,Read Attributes
c:\windows\syswow64\hfejhp32.dll Generic Write,Read Attributes
c:\windows\syswow64\hgfkcb32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hgfkcb32.exe Generic Write,Read Attributes
c:\windows\syswow64\hijdfa32.dll Generic Write,Read Attributes
c:\windows\syswow64\hjckgf32.dll Generic Write,Read Attributes
c:\windows\syswow64\hjnjfm32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hjnjfm32.exe Generic Write,Read Attributes
c:\windows\syswow64\hnndceaj.dll Generic Write,Read Attributes
c:\windows\syswow64\hqchgg32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hqchgg32.exe Generic Write,Read Attributes
c:\windows\syswow64\iaohcf32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\iaohcf32.exe Generic Write,Read Attributes
c:\windows\syswow64\ibjkbibg.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ibjkbibg.exe Generic Write,Read Attributes
c:\windows\syswow64\iblhgipe.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\iblhgipe.exe Generic Write,Read Attributes
c:\windows\syswow64\icfnoblk.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\icfnoblk.exe Generic Write,Read Attributes
c:\windows\syswow64\ickgja32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ickgja32.exe Generic Write,Read Attributes
c:\windows\syswow64\icpaeadq.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\icpaeadq.exe Generic Write,Read Attributes
c:\windows\syswow64\idjnde32.dll Generic Write,Read Attributes
c:\windows\syswow64\igkmep32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\igkmep32.exe Generic Write,Read Attributes
c:\windows\syswow64\ignhifpb.dll Generic Write,Read Attributes
c:\windows\syswow64\ihcdepja.dll Generic Write,Read Attributes
c:\windows\syswow64\ihfgmj32.dll Generic Write,Read Attributes
c:\windows\syswow64\iikigjpk.dll Generic Write,Read Attributes
c:\windows\syswow64\ijgllk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ijgllk32.exe Generic Write,Read Attributes
c:\windows\syswow64\ikgnka32.dll Generic Write,Read Attributes
c:\windows\syswow64\ikljgjfq.dll Generic Write,Read Attributes
c:\windows\syswow64\ikpceo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ikpceo32.exe Generic Write,Read Attributes
c:\windows\syswow64\iljkadlh.dll Generic Write,Read Attributes
c:\windows\syswow64\inchljei.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\inchljei.exe Generic Write,Read Attributes
c:\windows\syswow64\inlblkla.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\inlblkla.exe Generic Write,Read Attributes
c:\windows\syswow64\iopdll32.dll Generic Write,Read Attributes
c:\windows\syswow64\iqhbbgmg.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\iqhbbgmg.exe Generic Write,Read Attributes
c:\windows\syswow64\iqjohfke.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\iqjohfke.exe Generic Write,Read Attributes
c:\windows\syswow64\jafnde32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jafnde32.exe Generic Write,Read Attributes
c:\windows\syswow64\jahkid32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jahkid32.exe Generic Write,Read Attributes
c:\windows\syswow64\jamdddko.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jamdddko.exe Generic Write,Read Attributes
c:\windows\syswow64\jbaabh32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jbaabh32.exe Generic Write,Read Attributes
c:\windows\syswow64\jcbnjqbn.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jcbnjqbn.exe Generic Write,Read Attributes
c:\windows\syswow64\jcidkplf.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jcidkplf.exe Generic Write,Read Attributes
c:\windows\syswow64\jefcoc32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jefcoc32.exe Generic Write,Read Attributes
c:\windows\syswow64\jgpfqohd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jgpfqohd.exe Generic Write,Read Attributes
c:\windows\syswow64\jhbcfofa.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jhbcfofa.exe Generic Write,Read Attributes
c:\windows\syswow64\jjlfgk32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jjlfgk32.exe Generic Write,Read Attributes
c:\windows\syswow64\jjnbmjgh.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jjnbmjgh.exe Generic Write,Read Attributes
c:\windows\syswow64\jjqobjee.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\jjqobjee.exe Generic Write,Read Attributes
c:\windows\syswow64\jkgeqmhi.dll Generic Write,Read Attributes
c:\windows\syswow64\jmegek32.dll Generic Write,Read Attributes
c:\windows\syswow64\jqpgfqnk.dll Generic Write,Read Attributes
c:\windows\syswow64\kbadeehh.dll Generic Write,Read Attributes
c:\windows\syswow64\kbajifnm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kbajifnm.exe Generic Write,Read Attributes
c:\windows\syswow64\kbmqngbb.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kbmqngbb.exe Generic Write,Read Attributes
c:\windows\syswow64\kdpjlo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kdpjlo32.exe Generic Write,Read Attributes
c:\windows\syswow64\kedpqa32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kedpqa32.exe Generic Write,Read Attributes
c:\windows\syswow64\kemjpboc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kemjpboc.exe Generic Write,Read Attributes
c:\windows\syswow64\kffkemjh.dll Generic Write,Read Attributes
c:\windows\syswow64\khclmlho.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\khclmlho.exe Generic Write,Read Attributes
c:\windows\syswow64\khiignpi.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\khiignpi.exe Generic Write,Read Attributes
c:\windows\syswow64\khpogm32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\khpogm32.exe Generic Write,Read Attributes
c:\windows\syswow64\kiobka32.dll Generic Write,Read Attributes
c:\windows\syswow64\kjeimi32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjeimi32.exe Generic Write,Read Attributes
c:\windows\syswow64\kjolch32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kjolch32.exe Generic Write,Read Attributes
c:\windows\syswow64\kleegl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kleegl32.exe Generic Write,Read Attributes
c:\windows\syswow64\klglgf32.dll Generic Write,Read Attributes
c:\windows\syswow64\kljobldm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\kljobldm.exe Generic Write,Read Attributes
c:\windows\syswow64\klqhan32.dll Generic Write,Read Attributes
c:\windows\syswow64\knhkogca.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\knhkogca.exe Generic Write,Read Attributes
c:\windows\syswow64\kodkpd32.dll Generic Write,Read Attributes
c:\windows\syswow64\kqqljn32.dll Generic Write,Read Attributes
c:\windows\syswow64\ladclq32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ladclq32.exe Generic Write,Read Attributes
c:\windows\syswow64\lammka32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lammka32.exe Generic Write,Read Attributes
c:\windows\syswow64\lbbmfn32.dll Generic Write,Read Attributes
c:\windows\syswow64\lbmjed32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lbmjed32.exe Generic Write,Read Attributes
c:\windows\syswow64\lcfpdl32.dll Generic Write,Read Attributes
c:\windows\syswow64\lcheec32.dll Generic Write,Read Attributes
c:\windows\syswow64\ldcphl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ldcphl32.exe Generic Write,Read Attributes
c:\windows\syswow64\ldimbm32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\ldimbm32.exe Generic Write,Read Attributes
c:\windows\syswow64\leiilpef.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\leiilpef.exe Generic Write,Read Attributes
c:\windows\syswow64\lfanoo32.dll Generic Write,Read Attributes
c:\windows\syswow64\lfibcbcp.dll Generic Write,Read Attributes
c:\windows\syswow64\lhlock32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\lhlock32.exe Generic Write,Read Attributes
c:\windows\syswow64\llennjjp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\llennjjp.exe Generic Write,Read Attributes
c:\windows\syswow64\llhkcj32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\llhkcj32.exe Generic Write,Read Attributes
c:\windows\syswow64\lljkma32.dll Generic Write,Read Attributes
c:\windows\syswow64\llqeck32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\llqeck32.exe Generic Write,Read Attributes
c:\windows\syswow64\lmfedkgo.dll Generic Write,Read Attributes
c:\windows\syswow64\loandfkf.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

94 additional files are not displayed above.

Registry Modifications

Key::Value Dados API Name
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Jkgeqmhi.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Iljkadlh.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dqdcde32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lmfedkgo.dll RegNtPreCreateKey
Show More
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Folepl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Edephp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mcedha32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Nldjleeo.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Bkgpkqii.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mjcbee32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dmkmbj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Iikigjpk.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Fmlnogng.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lfanoo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ddofki32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mnlgke32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Cmaohmcd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ihcdepja.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Kiobka32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Adfkaq32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Acmfppob.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Klqhan32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Iopdll32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Onpqpmhg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dqfpiopd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lbbmfn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Hnndceaj.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Idjnde32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Jmegek32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Aqmepf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Hjckgf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Oclgpjni.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Bmlikg32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Fefegcjb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dmmjgdde.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Mpdilaah.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lfibcbcp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Omcoan32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Cnhchkhj.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ddffkkgo.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ihfgmj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Ckgepfqn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Hfejhp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Hijdfa32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Kffkemjh.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Pgcmmo32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Pgfgojae.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Oijipc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dkgpihcm.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Dohekp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Biibpjmp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lpbmee32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ikljgjfq.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FAA099-1BAE-816E-D711-115290CEE717} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Amaenlae.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Qejjjman.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Eaamijbm.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Mimfao32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Kodkpd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Kqqljn32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dhppmh32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Bcoilahd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lljkma32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Fhpqfpjl.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dibgqp32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Qpamnqbe.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Cbnnmh32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Onpqpmhg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Cjnligob.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ehneekon.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Banknc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Idjnde32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Geocha32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dfiaoefc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Andjdd32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ikgnka32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Plbmep32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Gaikhc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ecehhopd.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Klglgf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ngocigbp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Pjjjnpeg.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Akkame32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Heknkj32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Ignhifpb.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Gciamf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lcfpdl32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Gmgbdb32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lcheec32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Oijipc32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Dkjonnfn.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Heckfcee.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Biibpjmp.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Lpbmee32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79faa099-1bae-816e-d711-115290cee717}\inprocserver32:: C:\WINDOWS\SysWow64\Omkofl32.dll RegNtPreCreateKey

9 additional registry modifications are not displayed above.

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

C:\WINDOWS\system32\Negndljc.exe

Tendendo

Mais visto

Carregando...