PUP.AnyplaceControl

Threat Scorecard

Popularity Rank: 16,353
Threat Level: 10 % (Normal)
Infected Computers: 700
First Seen: July 24, 2009
Last Seen: November 27, 2025
OS(es) Affected: Windows

File System Details

PUP.AnyplaceControl may create the following file(s):
# File Name MD5 Detections
1. apc_host.exe 5e934ba6c81269d8efddc584d1c20324 6
More files

Analysis Report

General information

Family Name: PUP.AnyplaceControl
Signature status: No Signature

Known Samples

MD5: 9c5690c22d5d3802944ab856bba0024a
SHA1: 4a67e49a00e50c9de3f7c67e1fa397d40f5e9a24
SHA256: 4BD844390E0583B8EA5562E886A51F4E6405A2B34CC5C4C9A206BB3E34DFA631
File Size: 4.89 MB, 4888504 bytes
MD5: aea388585ddd56bba73a4fc04797deef
SHA1: 0a74360565db17a58fbac382a24b95b243ca444c
SHA256: F9FA3A2D3478067017EBCFC50773277CF6ED3BE05547BD4B771D3A223058BFAC
File Size: 4.36 MB, 4361548 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments No Comments
Company Name Anyplace Control Software
File Description Anyplace Control www.anyplace-control.com
File Version 7.0.4.0
Legal Copyright © 2002-2013 Anyplace Control Software
Original Filename apc_Admin.exe
Product Name Anyplace Control
Product Version 7.0

Digital Signatures

Signer Root Status
Honcharuk Yuriy UTN-USERFirst-Object Root Not Trusted

File Traits

  • big overlay
  • HighEntropy
  • Installer Manifest
  • packed
  • x86

Block Information

Total Blocks: 212
Potentially Malicious Blocks: 0
Whitelisted Blocks: 210
Unknown Blocks: 2

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Autorun.KA
  • KillMBR.XE

Files Modified

File Attributes
\device\namedpipe\apc_adminapp_unload Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\$_temp_$.$$$ Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{35f45d48-100c-4603-aa40-d10516b07704}:: AudioMixer RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{35f45d48-100c-4603-aa40-d10516b07704}\localserver32:: c:\Users\user\downloads\4a67e49a00e50c9de3f7c67e1fa397d40f5e9a24_0004888504 RegNtPreCreateKey
HKLM\software\classes\4a67e49a00e50c9de3f7c67e1fa397d40f5e9a24_0004888504.audiomixer:: AudioMixer RegNtPreCreateKey
HKLM\software\classes\4a67e49a00e50c9de3f7c67e1fa397d40f5e9a24_0004888504.audiomixer\clsid:: {35F45D48-100C-4603-AA40-D10516B07704} RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{35f45d48-100c-4603-aa40-d10516b07704}\progid:: 4a67e49a00e50c9de3f7c67e1fa397d40f5e9a24_0004888504.AudioMixer RegNtPreCreateKey

Trending

Most Viewed

Loading...