Threat Database Hacktool PUP.HackKMS.F

PUP.HackKMS.F

The detection of PUP.HackKMS.F on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.HackKMS.F?

PUP.HackKMS.F is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as harmful as other types of malware, such as viruses or Trojans, it can still cause problems with your system and compromise your personal data. PUPs are often installed unintentionally, and they can be difficult to remove without the right tools and knowledge.

How PUP.HackKMS.F Operates

PUP.HackKMS.F, like other PUPs, can operate in various ways, including modifying system settings, displaying unwanted advertisements, and collecting user data. It may also attempt to connect to remote servers to download additional malware or update its own components. In some cases, PUPs can be used to distribute other types of malware, making them a significant threat to your system's security.

Symptoms of Infection

If your system is infected with PUP.HackKMS.F, you may experience a range of symptoms, including slow system performance, unwanted pop-ups and advertisements, and changes to your browser settings. You may also notice that your system is crashing or freezing frequently, or that your personal data is being collected and transmitted without your consent. In some cases, PUPs can also cause issues with your system's stability and security, making it vulnerable to other types of malware.

  • Unwanted changes to your system settings
  • Display of unwanted advertisements and pop-ups
  • Collection and transmission of personal data
  • Slow system performance and crashes
  • Changes to your browser settings and homepage

How to Remove PUP.HackKMS.F

  1. Boot your system in Safe Mode with Networking to prevent PUP.HackKMS.F from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove PUP.HackKMS.F and any other malware that may be present.
  3. Uninstall any suspicious programs that may be related to PUP.HackKMS.F, and be cautious when installing new software to avoid unintentionally installing PUPs.
  4. Reset your browser settings, including Chrome, Firefox, and Edge, to their default values to remove any changes made by PUP.HackKMS.F.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that PUP.HackKMS.F has been completely removed.

Conclusion

Removing PUP.HackKMS.F from your system requires careful attention to detail and the use of reputable removal tools. By following the steps outlined above, you can help to ensure that your system is free from this potentially unwanted program and prevent future infections. It is also essential to be cautious when installing new software and to keep your operating system and security software up to date to protect against the latest threats.

Analysis Report

General information

Family Name: PUP.HackKMS.F
Signature status: No Signature

Known Samples

MD5: 8e1a461b615ced87e4256dcf7aa72fae
SHA1: 9ed14e98fe946b678c8754ecc3118eb1ec6c6adf
SHA256: BA4B36725A5A50D0B04FA52B63C72A717BCEDC2C1B9D9B536F33AED54DCE237A
File Size: 3.04 MB, 3043840 bytes
MD5: 37c8132d3968578793cf95e2764c434a
SHA1: 55ec7e5651db6ea4dfcd265a466d1cd12e08da3d
SHA256: FAEE6714AE77B06A454B280E94ABAB8AE1F4D36A981040617FBA3B5AF7936AC5
File Size: 9.60 MB, 9603868 bytes
MD5: 8867a8b370e982308e4dd4522c9d873e
SHA1: 24fbbb79774ff7f6cfe6a74a18bdee64fe29a81e
SHA256: FE6B01D72FAB1FCFF74AA488B8A4E29AECB2D4128A598584FEB4664F5D35E0C4
File Size: 7.57 MB, 7572992 bytes
MD5: 0c127bc8fa6496aa0aa6064362cc639e
SHA1: 8bf10a323a7dbed486afa1d96c354e824ce307a0
SHA256: 82E35F7FF1F22234F86A6B739AC27A83444EFE07C60CFBB54BE39DC63B63EDF4
File Size: 7.77 MB, 7772672 bytes
MD5: 55b0fe6bdcf167a2ccf79f617326e5fb
SHA1: d83edb614c6e237a1bd4991393d9a45b4e330c4f
SHA256: 535B984AD759CECC619AFD5125C2941B3C216CE941846AA9CA794D5A558B9B27
File Size: 3.05 MB, 3048448 bytes
Show More
MD5: ca800495e75d561288f4ae95e33fcb2d
SHA1: e44fc7c9ce7e220dafa65c9f25ecc4799b374f23
SHA256: E1352A7F676288BDFF766F513C6FE08B0A242F4B0F3A3C81106FEE6A5CC63813
File Size: 3.81 MB, 3809280 bytes
MD5: 141bd0171bec447d65a6e4f760496e42
SHA1: 06ac0ea4a6a0bb2f70da8ea69d2f6c5d572dedd3
SHA256: CA603EA07DC1F8FDC47C70AB2FCB9D970CE915E6DC3A1261D625F551626A5671
File Size: 6.16 MB, 6163968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Synaptics
File Description
  • AAct x86
  • Synaptics Pointing Device Driver
File Version 1.0.0.4
Product Name Synaptics Pointing Device Driver
Product Version 1.0.0.0

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 2,323
Potentially Malicious Blocks: 323
Whitelisted Blocks: 1,881
Unknown Blocks: 119

Visual Map

? 0 0 x ? ? x ? x x 0 x ? x x ? 0 x 0 x ? ? ? ? ? x ? ? ? ? ? x x x ? ? x x ? x ? ? x ? x ? ? x ? x x 0 x ? x ? x x x x ? x x x 0 x ? x ? ? x x x x x x x x x x 0 x x 0 x x x 0 x x x x x x x x x x x 0 ? x x x ? ? ? ? ? 0 x x 0 x x 0 x x x 0 ? ? x x x x x x 0 ? 0 x ? ? x x x ? x ? x x 0 x x 0 x ? x ? x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 x 0 x ? x 0 ? x x x x x x x x 0 x ? 0 x x x 0 x ? x x x x x 0 x 0 ? x ? x 0 x x 0 ? x ? x x 0 ? 0 ? x 0 x x x x ? x 0 ? 0 ? ? x 0 ? ? x x x x x x ? ? x ? x ? x x x x x 0 x x 0 0 x x ? x x x ? ? x ? ? ? ? ? x 0 ? x x 0 x 0 x x 0 0 x x x x 0 x 0 0 0 0 0 0 1 0 1 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x ? 0 0 0 x 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x x x x x x x x x 0 x 0 x 0 0 x 0 x x x x x 0 0 x x x x 0 x 0 0 x x x 0 x 0 x 0 x x x 0 x x 0 x x 0 x x 0 x x 0 x 0 x x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 x x x 0 x x 0 x 0 x x x 0 0 0 0 0 x 0 x x x x 0 0 x x x x x x x 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HackKMS.D

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable Synchronize,Write Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\__tmp_rar_sfx_access_check_2927656 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsauto x64.exe Generic Write,Read Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsauto x64.exe Synchronize,Write Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsauto.exe Generic Write,Read Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsauto.exe Synchronize,Write Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsautolite.ini Generic Write,Read Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsautolite.ini Synchronize,Write Attributes
Show More
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\readme_en.txt Generic Write,Read Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\readme_en.txt Synchronize,Write Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\sacc.bat Generic Write,Read Attributes
c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\sacc.bat Synchronize,Write Attributes
c:\programdata\synaptics Synchronize,Write Attributes
c:\programdata\synaptics\rcxbf6d.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\synaptics.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\synaptics\synaptics.exe Synchronize,Write Attributes
c:\programdata\synaptics\synaptics.exe Synchronize,Write Data
c:\users\user\appdata\local\temp\gmzhumt.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\winsl Synchronize,Write Attributes
c:\users\user\appdata\roaming\winsl\l4\10\2026 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_e44fc7c9ce7e220dafa65c9f25ecc4799b374f23_0003809280 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_e44fc7c9ce7e220dafa65c9f25ecc4799b374f23_0003809280 Synchronize,Write Attributes
c:\users\user\downloads\24fbbb79774ff7f6cfe6a74a18bdee64fe29a81e_0007572992 Synchronize,Write Attributes
c:\users\user\downloads\aact.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\kmsautolite.ini Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows script host\settings::enabled  RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 䐜୩竌ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 䐜୩竌ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㴝煹窽ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 /k 8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��2 xy* �/��Y�d�kP~��� ��ރ�p��^�o���zee)Vs} kP~ ��1���7 ���ﺃee����1��fe��h RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 0k 8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 딱뀅負ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe '� ���� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 揨쏁ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ꧮ揭쏁ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀT���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/�� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::synaptics pointing device driver C:\ProgramData\Synaptics\Synaptics.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p��^�o�ee=Vs}kP~��1.��7 ���ﺃee��� ��1��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9� RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Winsock2
  • WSAStartup
  • WSAttemptAutodialName
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Terminate
  • TerminateProcess
Keyboard Access
  • GetKeyState
Service Control
  • OpenSCManager
Network Winhttp
  • WinHttpOpen
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile
Network Winsock
  • bind
  • closesocket
  • gethostbyname
  • getsockname
  • socket

Shell Command Execution

"C:\WINDOWS\Sysnative\cmd.exe" /c WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionPath="c:\users\user\downloads\9ed14e98fe946b678c8754ecc3118eb1ec6c6adf_0003043840"
C:\WINDOWS\System32\Wbem\WMIC.exe WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionPath="c:\users\user\downloads\9ed14e98fe946b678c8754ecc3118eb1ec6c6adf_0003043840"
WriteConsole: Access is denied
(NULL) C:\Program Files (x86)\_KMSAuto Lite v1.8.8.0 Portable\SACC.BaT
C:\WINDOWS\system32\reg.exe reg Query "HKLM\Hardware\Description\System\CentralProcessor\0"
Show More
C:\WINDOWS\system32\find.exe find /i "x86"
C:\WINDOWS\system32\explorer.exe explorer "KMSAuto x64.exe"
"C:\WINDOWS\Sysnative\cmd.exe" /c copy C:\WINDOWS\system32\Tasks\KMSAuto "C:\Users\Kfstbngz\AppData\Local\Temp\KMSAuto.tmp" /Y
"C:\WINDOWS\Sysnative\cmd.exe" /c WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionPath="c:\users\user\downloads\d83edb614c6e237a1bd4991393d9a45b4e330c4f_0003048448"
C:\WINDOWS\System32\Wbem\WMIC.exe WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionPath="c:\users\user\downloads\d83edb614c6e237a1bd4991393d9a45b4e330c4f_0003048448"
runas c:\users\user\downloads\._cache_e44fc7c9ce7e220dafa65c9f25ecc4799b374f23_0003809280
runas C:\ProgramData\Synaptics\Synaptics.exe InjUpdate

Related Posts

Trending

Most Viewed

Loading...