PUP.HWIDChanger.X

PUP.HWIDChanger.X is the detection name used for a type of potentially unwanted program (PUP) that falls into the broader family of hardware ID (HWID) spoofing or changing tools. These utilities are typically marketed as a way to alter or mask a computer's unique hardware identifiers, often to help users bypass bans imposed by online games, software licensing systems, or other services that track hardware fingerprints. While the stated purpose may sound harmless or even useful to some users, programs flagged under this detection name are considered unwanted because of the way they are distributed, the system changes they make, and the security risks they introduce.

What PUP.HWIDChanger.X Does

Programs identified as PUP.HWIDChanger.X generally attempt to modify low-level system identifiers associated with a computer's hardware, such as values tied to network adapters, storage drives, or other components that applications use to recognize a specific machine. In order to do this, such tools often require elevated administrative privileges and may make changes to system settings or the Windows registry that go beyond what a typical user program needs. This kind of deep system access is a hallmark of potentially unwanted programs in this category, since it can destabilize the operating system, interfere with legitimate software, or create conflicts with security tools.

Many HWID changer tools also ask users to disable antivirus or other protective software before installation, claiming this is necessary for the program to function correctly. This is a common and concerning trait of PUPs, as disabling security protections leaves the system exposed to other, potentially more dangerous threats.

How It Usually Gets on Computers

Like most potentially unwanted programs, HWID changer tools are typically distributed through unofficial channels rather than trusted software stores. Common distribution methods include downloads from forums dedicated to bypassing game bans or software restrictions, file-sharing sites, and bundling with cracked or pirated software. Users often seek out these tools intentionally, but may not fully realize the bundled extras, adware components, or security risks that can come packaged alongside them.

Risks for the User

Because PUP.HWIDChanger.X requires deep system-level changes and often asks users to lower their security defenses, it can expose a computer to several risks. These may include system instability, unexpected crashes, or conflicts with legitimate drivers and software. There is also a risk of secondary infections, since tools obtained from unofficial sources are frequently bundled with adware, browser hijackers, or more serious malware. Additionally, using such tools to circumvent bans or licensing restrictions may violate the terms of service of the platform involved, which can carry its own consequences.

Signs of Infection

Users may notice unusual system behavior after installing a program like this, including unexpected changes to system settings, prompts to disable security software, or the appearance of unfamiliar entries in startup programs. Slower system performance, unexpected pop-ups, or the presence of additional unwanted toolbars or applications can also indicate that a HWID changer tool brought along unwanted extras.

How to Stay Protected

To avoid potentially unwanted programs like PUP.HWIDChanger.X, it is best to avoid downloading software from unofficial forums, cracked software repositories, or sites promising to bypass bans and restrictions. Keeping security software active and updated, avoiding requests to disable protection, and carefully reviewing installation prompts for bundled extras are all effective ways to reduce risk. Regularly scanning the system and reviewing installed programs can also help identify and remove unwanted software before it causes further issues.

Analysis Report

General information

Family Name: PUP.HWIDChanger.X
Signature status: No Signature

Known Samples

MD5: 21adff0121ec88e41b66b6f7d60a74db
SHA1: d79ec8fe336f98826b7ceb6e6e5bc0771c451552
SHA256: 010CE3183A0DE0AD656952889E9F4313F8F96FCC9D4A87A5C718F3D10651764D
File Size: 180.22 KB, 180224 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • fptable
  • No Version Info
  • x64

Block Information

Total Blocks: 569
Potentially Malicious Blocks: 20
Whitelisted Blocks: 540
Unknown Blocks: 9

Visual Map

0 0 ? ? ? ? ? x ? x x ? 1 x x x x x 0 ? x x x x x 0 ? x x x x x 0 x 0 x 2 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.Injector.Gen.JZV
  • Trojan.Kryptik.Gen.KTZ

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
\device\namedpipe\srvsvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c: Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\microsoft\windows\wer Synchronize,Write Attributes
c:\programdata\ntuser.pol Synchronize,Write Attributes
c:\system volume information\tracking.log Synchronize,Write Attributes
c:\users\default\ntuser.dat Synchronize,Write Attributes
c:\users\public\libraries Synchronize,Write Attributes
c:\users\user\appdata\local\d3dscache Synchronize,Write Attributes
c:\users\user\appdata\local\microsoft\feeds Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\microsoft\feeds cache Synchronize,Write Attributes
c:\users\user\appdata\local\microsoft\windows\inetcache Synchronize,Write Attributes
c:\users\user\appdata\local\microsoft\windows\inetcookies Synchronize,Write Attributes
c:\users\user\appdata\local\microsoft\windows\webcache Synchronize,Write Attributes
c:\users\user\appdata\local\microsoft\xboxlive\authstatecache.dat Synchronize,Write Attributes
c:\windows\inf\setupapi.dev.log Synchronize,Write Attributes
c:\windows\inf\setupapi.setup.log Synchronize,Write Attributes
c:\windows\prefetch\agapplaunch.db Synchronize,Write Attributes
c:\windows\prefetch\agcx_s1_s-1-5-21-3119368278-1123331430-659265220-1001.snp.db Synchronize,Write Attributes
c:\windows\prefetch\agcx_sc4.db Synchronize,Write Attributes
c:\windows\prefetch\agglfaulthistory.db Synchronize,Write Attributes
c:\windows\prefetch\agglfgapphistory.db Synchronize,Write Attributes
c:\windows\prefetch\agglglobalhistory.db Synchronize,Write Attributes
c:\windows\prefetch\aggluad_p_s-1-5-21-3119368278-1123331430-659265220-1001.db Synchronize,Write Attributes
c:\windows\prefetch\aggluad_s-1-5-21-3119368278-1123331430-659265220-1001.db Synchronize,Write Attributes
c:\windows\prefetch\agrobust.db Synchronize,Write Attributes
c:\windows\prefetch\applicationframehost.exe-cceef759.pf Synchronize,Write Attributes
c:\windows\prefetch\atbroker.exe-2e15a492.pf Synchronize,Write Attributes
c:\windows\prefetch\backgroundtaskhost.exe-353e93dd.pf Synchronize,Write Attributes
c:\windows\prefetch\backgroundtaskhost.exe-d61f7b44.pf Synchronize,Write Attributes
c:\windows\prefetch\backgroundtransferhost.exe-0849bbbc.pf Synchronize,Write Attributes
c:\windows\prefetch\backgroundtransferhost.exe-11ae310d.pf Synchronize,Write Attributes
c:\windows\prefetch\backgroundtransferhost.exe-4abde2db.pf Synchronize,Write Attributes
c:\windows\prefetch\backgroundtransferhost.exe-4fd26b36.pf Synchronize,Write Attributes
c:\windows\prefetch\backgroundtransferhost.exe-7f685c33.pf Synchronize,Write Attributes
c:\windows\prefetch\backgroundtransferhost.exe-bf0ae715.pf Synchronize,Write Attributes
c:\windows\prefetch\backgroundtransferhost.exe-fae7d0ad.pf Synchronize,Write Attributes
c:\windows\prefetch\cadrespri.7db Synchronize,Write Attributes
c:\windows\prefetch\cleanmgr.exe-e3c5e89d.pf Synchronize,Write Attributes
c:\windows\prefetch\cmd.exe-4a81b364.pf Synchronize,Write Attributes
c:\windows\prefetch\compattelrunner.exe-db97728f.pf Synchronize,Write Attributes
c:\windows\prefetch\conhost.exe-1f3e9d7e.pf Synchronize,Write Attributes
c:\windows\prefetch\consent.exe-531bd9ea.pf Synchronize,Write Attributes
c:\windows\prefetch\csrss.exe-3fe41f7e.pf Synchronize,Write Attributes
c:\windows\prefetch\ctfmon.exe-9450846b.pf Synchronize,Write Attributes
c:\windows\prefetch\defrag.exe-588f90ad.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-041f1888.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-0ad6ac16.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-2e884d3e.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-41467c2f.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-5a984e5f.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-823ca4da.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-88f23425.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-9037274d.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-b9b46003.pf Synchronize,Write Attributes
c:\windows\prefetch\dllhost.exe-ea533aaf.pf Synchronize,Write Attributes
c:\windows\prefetch\dwm.exe-6ffd3da8.pf Synchronize,Write Attributes
c:\windows\prefetch\dynrespri.7db Synchronize,Write Attributes
c:\windows\prefetch\easeofaccessdialog.exe-2b345401.pf Synchronize,Write Attributes
c:\windows\prefetch\explorer.exe-a80e4f97.pf Synchronize,Write Attributes
c:\windows\prefetch\fontdrvhost.exe-31e45f6d.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-0464a06b.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-1cad104d.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-440f564f.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-81633501.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-8e91ee43.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-9e08df9d.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-9ed2879f.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-a4611e03.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-ca1600f5.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-d0b55d8b.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-dd84965f.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-fb17a891.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebar.exe-fb93a8a1.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebarftserver.exe-436c0bb2.pf Synchronize,Write Attributes
c:\windows\prefetch\gamebarftserver.exe-44b54636.pf Synchronize,Write Attributes
c:\windows\prefetch\gethelp.exe-243ba475.pf Synchronize,Write Attributes
c:\windows\prefetch\layout.ini Synchronize,Write Attributes
c:\windows\prefetch\lockapp.exe-59620d5a.pf Synchronize,Write Attributes
c:\windows\prefetch\lockapp.exe-baddc799.pf Synchronize,Write Attributes
c:\windows\prefetch\logonui.exe-09140401.pf Synchronize,Write Attributes
c:\windows\prefetch\makecab.exe-0f1704a4.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoft.photos.exe-a6cf5fcb.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_143.0.3650.-64e2136d.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_143.0.3650.-68a2aa4a.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_147.0.3912.-3007787d.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_147.0.3912.-b92690db.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_147.0.3912.-e31f5cd3.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_147.0.3912.-e4761e2d.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_147.0.3912.-f8e2dff7.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_148.0.3967.-4596b43c.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_148.0.3967.-848124ee.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_154.0.4258.-19e3ad99.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedge_x64_154.0.4258.-522a17ca.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdate.exe-161141e4.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdate.exe-223adf78.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdate.exe-23ea12c9.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdate.exe-4f9082d9.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdate.exe-c4317749.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdate.exe-ec67f03a.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdatesetup_x86_-370d86c6.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdatesetup_x86_-41269959.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdatesetup_x86_-63832945.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdatesetup_x86_-6a0ad7f2.pf Synchronize,Write Attributes
c:\windows\prefetch\microsoftedgeupdatesetup_x86_-9442561a.pf Synchronize,Write Attributes
c:\windows\prefetch\mmc.exe-381384ef.pf Synchronize,Write Attributes
c:\windows\prefetch\mmc.exe-667e9ca3.pf Synchronize,Write Attributes
c:\windows\prefetch\mmc.exe-7fbb0956.pf Synchronize,Write Attributes
c:\windows\prefetch\mmc.exe-cab79805.pf Synchronize,Write Attributes
c:\windows\prefetch\mobsync.exe-c5e2284f.pf Synchronize,Write Attributes
c:\windows\prefetch\mousocoreworker.exe-681a8fee.pf Synchronize,Write Attributes
c:\windows\prefetch\mscorsvw.exe-57d17daf.pf Synchronize,Write Attributes
c:\windows\prefetch\mscorsvw.exe-c3c515bd.pf Synchronize,Write Attributes
c:\windows\prefetch\msedge.exe-78f14b85.pf Synchronize,Write Attributes
c:\windows\prefetch\msiexec.exe-a2d55cb6.pf Synchronize,Write Attributes
c:\windows\prefetch\msinfo32.exe-95097b65.pf Synchronize,Write Attributes
c:\windows\prefetch\musnotificationux.exe-48ffd505.pf Synchronize,Write Attributes
c:\windows\prefetch\net.exe-df44f913.pf Synchronize,Write Attributes
c:\windows\prefetch\netplwiz.exe-52789dd1.pf Synchronize,Write Attributes
c:\windows\prefetch\ngen.exe-ae594a6b.pf Synchronize,Write Attributes
c:\windows\prefetch\ngen.exe-ec3f9239.pf Synchronize,Write Attributes
c:\windows\prefetch\ngentask.exe-4f8bd802.pf Synchronize,Write Attributes
c:\windows\prefetch\ngentask.exe-bb7f7010.pf Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\hardwareconfig::lastconfig {f1eaebb5-4d2f-7711-a017-94b444b44f11} RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::id RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::lastuse ⭀謱ُǛ RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::systembiosversion Xen - 0Revision: 1.221 RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::enclosuretype  RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::systemmanufacturer Xen RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::systemproductname HVM domU RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::biosvendor Xen RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::biosversion 4.13 RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::biosreleasedate 11/17/2023 RegNtPreCreateKey
Show More
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::systemversion 4.13 RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}::bootdriverflags RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\computerids::{db2321af-1d6a-5ce8-954f-9680c4914ba3} Xen&&HVM domU&Xen&4.13&04&0d RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\computerids::{a190f5c1-b5c7-5746-8ace-b8917e90d585} Xen&HVM domU&Xen&4.13&04&0d RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\computerids::{67f9d617-c18a-54ea-83d9-9dbb8af9e472} Xen&&HVM domU RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\computerids::{ef48adbc-f2b4-51a9-b03e-3a858764392d} Xen&HVM domU RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\computerids::{524d2732-13bc-5f73-bbdc-6a2b8ec2946e} Xen&1 RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\computerids::{c9d88512-cf58-5151-af5f-39414a55822a} Xen RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\productids::{db2321af-1d6a-5ce8-954f-9680c4914ba3}_amd64 (NULL) RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\productids::{a190f5c1-b5c7-5746-8ace-b8917e90d585}_amd64 (NULL) RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\productids::{67f9d617-c18a-54ea-83d9-9dbb8af9e472}_amd64 (NULL) RegNtPreCreateKey
HKLM\system\hardwareconfig\{f1eaebb5-4d2f-7711-a017-94b444b44f11}\productids::{ef48adbc-f2b4-51a9-b03e-3a858764392d}_amd64 (NULL) RegNtPreCreateKey
HKLM\system\controlset001\services\tpm\wmi::windowsaikhash 挐շ똬柉␼㟢ֿえ辑鼄늵뜳뻅䊓衜 RegNtPreCreateKey
HKLM\system\controlset001\services\tpm\wmi::windowsaikhash ⃋潴廆ꍮ䔆䔃霻쩽ᔔꄧ䑕ᔂ焪璹燗 RegNtPreCreateKey
HKLM\hardware\description\system\multifunctionadapter\0\diskcontroller\0\diskperipheral\0::identifier c372cd05-1e3bd0ad-4 RegNtPreCreateKey
HKLM\system\controlset001\services\tpm\oduid::randomseed ⑲끫⸊砛䉥隮⯆嘏ꨜ處⃋첢躯㵊뽞⨸ RegNtPreCreateKey
HKLM\software\microsoft\cryptography::machineguid 0549aede-a9df-074d-f045-cab98918f505 RegNtPreCreateKey
HKLM\system\controlset001\control\idconfigdb\hardware profiles\0001::hwprofileguid {f3c58997-4f9e-28ab-3a5e-593dbe1a9915} RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\windowsupdate::susclientid d9c42da0-711b-3e7a-e1fb-0fbbeeb5a834 RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\windowsupdate::susclientidvalidation ���0<LZ4 RegNtPreCreateKey
HKLM\system\controlset001\services\tcpip6\parameters::dhcpv6duid 㜗ײַ䙝秊邉΄툤 RegNtPreCreateKey
HKLM\system\controlset001\services\tcpip6\parameters::dhcpv6duid �Y���?�bT� RegNtPreCreateKey
HKLM\system\controlset001\control\systeminformation::computerhardwareid {de34e177-cd0d-5975-5f14-9deea8f524c4} RegNtPreCreateKey
HKLM\system\controlset001\control\systeminformation::computerhardwareids {3373d2df-c5b1-4add-3bbf-027c52315ddc}{25bce4e4-4a5e-7ccc-1ad7-bbf8fca5b118}{e82b8184-0c71-4b74-bbc8-3580350bbb81}{153b57bc-d RegNtPreCreateKey
HKLM\software\microsoft\internet explorer\migration::ie installed date 糉婻 RegNtPreCreateKey
HKLM\software\microsoft\sqmclient::machineid {0ab847f7-8913-5000-7335-a41050c57003} RegNtPreCreateKey
HKLM\software\microsoft\sqmclient::winsqmfirstsessionstarttime 㪦⎠ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion::installtime ࣢擼 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion::installdate ⟁⨦ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion::digitalproductid �}�C߀/�X�B���(��c,�M]Rrħ�)���_Y�Ɩ�w�9�W��\uT`x)_���U��,�N!$V�} �{_����>ػG7 ����X�����W�s>��#�σ$��doV��g��f��}na!D"h�w�e�#4��� ����'9 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion::digitalproductid4 r�c*��^�=Rv��׻r� wn���p�K�����u5�<D��m��m�<���a�����J70����$g=�zoF�h��-��<�?��&�����z�21��C�$/ +�,Z��,��~��e�Qʟ�桠~D���c� �����6o�)�5v٫������ ��u��h�o�!M��G�e@��eRKS�<3�s�%��>/qۼ�E���Jz�J�`UV$��]�4f���U(���� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion::buildguid bd8d5db1-cb4b-52dc-2e5d-48e21ca4b8ab RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion::productid a421a-01d89-17048-def1a RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion::buildlab 95be3.v9_rclbas3.9edb5a-78c3 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion::buildlabex 84818.7.bmbe7er9.vd_r8ldas2.475f34-ece1 RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0000::networkinterfaceinstalltimestamp 但綽 RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001::networkinterfaceinstalltimestamp 楀Ꭿ RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0002::networkinterfaceinstalltimestamp ᡱ崱 RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0003::networkinterfaceinstalltimestamp 㡏Ή RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0004::networkinterfaceinstalltimestamp 䈍䐛 RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0005::networkinterfaceinstalltimestamp 檐ā RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0006::networkinterfaceinstalltimestamp ㄰协 RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0007::networkinterfaceinstalltimestamp 浟ᒗ RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0008::networkinterfaceinstalltimestamp ᪫䅦 RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0009::networkinterfaceinstalltimestamp 嶼擔 RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0010::networkinterfaceinstalltimestamp 刲絗 RegNtPreCreateKey
HKLM\system\controlset001\control\class\{4d36e972-e325-11ce-bfc1-08002be10318}\0011::networkinterfaceinstalltimestamp 炗ൿ RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\diagnostics\diagtrack\sevilleeventlogmanager::lasteventlogwrittentime ᒾ彈 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\softwareprotectionplatform\activation::productactivationtime か眔 RegNtPreCreateKey
HKCU\software\microsoft\onedrive\accounts::lastupdate 到宣 RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\onesettings\wsd\setupplatform\queryparameters::deviceid {fa2fea5f-cdf1-545c-b0a2-ab93d01009f0} RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\onesettings\wsd\updateagent\queryparameters::deviceid {0a3d9aff-f593-2ed9-3789-ac78924f9215} RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\vfuprovider::lastupdate ௼֬ RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\wosc\client\persistent\clientstate\wosc::lastrefreshattempted ⶝滺 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\windows\win32kwpp\parameters::wpprecorder_traceguid {a1f83b17-0592-afb5-ea3e-e349e2b8fcd0} RegNtPreCreateKey
HKLM\system\controlset001\services\kbdclass\parameters::wpprecorder_traceguid {7ffeb358-1aa5-21b2-cf13-ece92437e35a} RegNtPreCreateKey
HKLM\system\controlset001\services\kbdclass\parameters::wpprecorder_traceguid {ae19e183-74b8-fb35-abfe-fdd99135c2eb} RegNtPreCreateKey
HKLM\system\controlset001\services\kbdclass\parameters::wpprecorder_traceguid {9bfbbff5-0aed-c851-249d-2ceaccdc1983} RegNtPreCreateKey
HKLM\system\controlset001\services\mouhid\parameters::wpprecorder_traceguid {b7fec10b-0d23-addd-4efd-fd19eac5a8a9} RegNtPreCreateKey
HKLM\system\waas\waasmedic\state::featuretimestampoflatestrun 晽 RegNtPreCreateKey
HKLM\system\waas\waasmedic\state::qualitytimestampoflatestrun 嬚 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcDisconnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteKey
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Other Suspicious
  • AdjustTokenPrivileges