PUP.AnyProtect

Threat Scorecard

Popularity Rank: 3,436
Threat Level: 10 % (Normal)
Infected Computers: 131,906
First Seen: June 16, 2014
Last Seen: October 31, 2025
OS(es) Affected: Windows

Aliases

11 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Avast Win32:Adware-gen [Adw]
McAfee RDN/Generic.bfr!hk
AVG Generic_s.CQ
Ikarus Trojan.SuspectCRC
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious-PKR.G
Avast Win32:PUP-gen [PUP]
K7AntiVirus Riskware ( 0040f10b1 )
McAfee RDN/Generic PUP.x!chb
Sophos Install Core
Avast Win32:Malware-gen
AVG AnyProtect.B

SpyHunter Detects & Remove PUP.AnyProtect

File System Details

PUP.AnyProtect may create the following file(s):
# File Name MD5 Detections
1. nsa9067.tmp a7ed81a0bb0f50c456cfd6048b9a5389 3,038
2. AnyProtectTray.exe f63ba4a53f8628a16c38cf2a76a1ea94 247
3. nsq3887.tmp b073c872ece67182a115badde4861271 160
4. OpenAccess.exe 9cdfce446ae9aa6443d998c2548509ce 153
5. AnyProtectTrayIcon.exe d7992d85efe19eab2ab9e61bd820176e 117
6. A0656770.exe 5263e072ae97d41871f5541b7c26157b 109
7. A0119903.exe 84677fe83570177edf0b8dc91e45b9e6 94
8. A0001186.exe 943dcefba692d8c103c741cd97889c86 88
9. uninstall.exe f6a94044da72f13a7a1dd5d9ab8f75f3 18
10. A0005493.exe 9f1f9be5ebd71dac2371b2064f8aa6a9 9
More files

Registry Details

PUP.AnyProtect may create the following registry entry or registry entries:
File name without path
AnyProtect.lnk
Regexp file mask
%LOCALAPPDATA%\AnyProtectScannerSetup.exe
%USERPROFILE%\Local Settings\Application Data\AnyProtectScannerSetup.exe
%windir%\System32\Tasks\APSnotifierPP[RANDOM CHARACTERS]
%windir%\Tasks\APSnotifierPP[RANDOM CHARACTERS]
Software\AnyProtect
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3

Directories

PUP.AnyProtect may create the following directory or directories:

%APPDATA%\AnyProtectEx
%APPDATA%\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
%APPDATA%\Microsoft\Windows\Start Menu\Programs\AnyProtectEx
%PROGRAMFILES%\AnyProtectEx

Analysis Report

General information

Family Name: PUP.AnyProtect
Signature status: Root Not Trusted

Known Samples

MD5: ad884ce6379174bd18db959a814224f8
SHA1: b86bbaaab71ffb01a0c42a86a46a7003d84bc327
File Size: 144.57 KB, 144568 bytes
MD5: d58d7eb4adda351c4e6bd7c7ca530705
SHA1: c05688ca37eadf1520fbfaba6091d87d1e19c252
File Size: 588.67 KB, 588672 bytes
MD5: 7f50ccf43ebc64a0ffbbd8f4d9a687c4
SHA1: 0b97d88128b4f14d74b810906eb64742262a8d47
File Size: 588.14 KB, 588144 bytes
MD5: acd4b4a63288c494e44362edbcf42105
SHA1: 9e89dad08a71858b45552f565f0c1a01e8fefa18
File Size: 588.67 KB, 588672 bytes
MD5: ba13a7275af961acb85111848f1ad39c
SHA1: 769bd78ead1b5eca06ebd95fcb8ff0b9950416b9
SHA256: AFD856479515A093DB0952D6A15A500594292EC8A3010C171A391EAEF9699C2D
File Size: 709.26 KB, 709256 bytes
Show More
MD5: 24ed18e0db328b67d8fac5bd7051eb36
SHA1: 656b837072ac3e27e41450851fa7c7f09c7590a2
SHA256: 89E701C05209AF21B44CD068CAA3D07954C7E814ACB1F1A37068B4BAEBD1A0B6
File Size: 1.00 MB, 1001488 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • ClickMeIn Generic Installer
  • This installation was built with Inno Setup.
Company Name
  • ClickMeIn Limited
  • InstallCore ©
File Description
  • ClickMeIn Generic Setup
  • InstallCore© Installer
File Version
  • 1.0.0.0
  • 1, 0, 0, 9
Internal Name Installer Powered by installcore.com - SDK v2.1
Legal Copyright
  • Copyright 2013
  • Copyright © InstallCore
Legal Trademarks ClickMeIn and its brands are a trademark of ClickMeIn Limited
Product Name
  • ClickMeIn Generic
  • InstallCore© Installer
Product Version
  • 1.0.0.0
  • 1, 0, 0, 9

Digital Signatures

Signer Root Status
AnyProtect UTN-USERFirst-Object Root Not Trusted
ClickMeIn Limited VeriSign Class 3 Public Primary Certification Authority - G5 Root Not Trusted

Block Information

Total Blocks: 3,109
Potentially Malicious Blocks: 0
Whitelisted Blocks: 3,103
Unknown Blocks: 6

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\1vtp0c0l0i0c0k0m0e0i0ntp1v Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\1vtp0c0l0i0c0k0m0e0i0ntp1v_test Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\00138eb6.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\0033948e.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\css\ie6_main.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\css\ie6_main.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\css\ie6_main.css Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\browse.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\browse.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\browse.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\button.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\button.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\button.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\checkbox.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\checkbox.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\checkbox.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\images\button-bg.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\images\button-bg.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\images\button-bg.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\images\progress-bg.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\images\progress-bg.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\images\progress-bg.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\progress-bar.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\progress-bar.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\css\sdk-ui\progress-bar.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\css\style.css Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\css\style.css Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\css\style.css Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\defaultoffer\ad_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\defaultoffer\ad_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\defaultoffer\ad_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\defaultoffer\ad_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\images\back_butt.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\images\back_butt.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\images\back_butt.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\images\bg_logo.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\images\bg_logo.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\images\bg_logo.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\images\blank.gif Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\images\blank.gif Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\images\blank.gif Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\images\hand.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\images\hand.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\images\hand.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\images\inst_prog.gif Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\images\inst_prog.gif Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\images\inst_prog.gif Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\images\nxt_butt.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\images\nxt_butt.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\images\nxt_butt.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\images\progress-bg.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\images\progress-bg.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\images\progress-bg.jpg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\images\x.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\images\x.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\images\x.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\license\license_en.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\license\license_en.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\license\license_en.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\locale\en.locale Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\locale\en.locale Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\locale\en.locale Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\locale\es.locale Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\locale\es.locale Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\locale\es.locale Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\locale\fr.locale Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\locale\fr.locale Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\locale\fr.locale Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\locale\it.locale Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\locale\it.locale Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\locale\it.locale Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\bb\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\offers\bb\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\bb\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\bb\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\offers\bb\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\bb\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\dp\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\offers\dp\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\dp\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\dp\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\offers\dp\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\dp\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\fm\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\offers\fm\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\fm\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\fm\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\offers\fm\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\fm\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\sn\offer_code.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\offers\sn\offer_code.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\sn\offer_code.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\sn\offer_html.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\offers\sn\offer_html.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\offers\sn\offer_html.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ish1281734\sdk\exceptlist.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ish1281734\sdk\exceptlist.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ish1281734\sdk\exceptlist.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsp58ef.tmp Synchronize,Write Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Network Info Queried
  • GetAdaptersInfo
Network Wininet
  • HttpOpenRequest
  • InternetConnect
  • InternetOpen
Network Winhttp
  • WinHttpOpen

Trending

Most Viewed

Loading...