PUP.Kazaa

Analysis Report

General information

Family Name: PUP.Kazaa
Signature status: No Signature

Known Samples

MD5: 35ea17f7a4afd32912e823cf6674aa20
SHA1: a3ed17bab7a69d9e43e0c4df2db54e3f4362f233
SHA256: CCAA2D09E68E56D56419A46E9D29B2A4AC5C8D069149C283C89EC004F657901F
File Size: 6.69 MB, 6690604 bytes
MD5: c5c7792c8e3f350fa4ff88f89d28a43b
SHA1: 8923918946935f7b44ef46985f2431ec63bc7011
SHA256: 2E3DEF91AE687C4FE89DB6ECD994F32ADA60E3E17FD9FEAC2FBB7E3761973548
File Size: 1.69 MB, 1692672 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • KaZaA
  • Sharman Networks Ltd
File Description
  • Kazaa Installer
  • KaZaA Media Desktop
File Version
  • 7, 01, 100, 1248
  • 1, 6, 1, 0
Internal Name
  • ISPNickel
  • kazaa
Legal Copyright
  • Copyright (C) 1990-2004
  • Copyright (C) 1997-2002
Original Filename
  • KaZaA.EXE
  • Setup.exe
Product Name
  • Kazaa
  • KaZaA Media Desktop
Product Version
  • 7, 01
  • 1, 6, 1, 0

File Traits

  • 00 section
  • big overlay
  • HighEntropy
  • Installer Manifest
  • Installer Version
  • x86

Block Information

Total Blocks: 3
Potentially Malicious Blocks: 3
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bagle.A

Files Modified

File Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\cto5dcc.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\cto5dcc.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\ctor.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\dot5d6d.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\dot5d6d.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\dotnetinstaller.exe Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\igdi.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\ike5cfe.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\ike5cfe.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\ikernel.dll Synchronize,Write Data
Show More
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\isc5e4a.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\isc5e4a.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\iscript.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\isp57e8.tmp\setup.dll Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\isp57e8.tmp\setup.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\isp57e8.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\isp5ae8.tmp\igdi.dll Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\isp5ae8.tmp\igdi.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\isp5ae8.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\ius5eb8.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\ius5eb8.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\iuser.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\setup.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\ikernel.rgs Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\ikernel.rgs Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\isp5f46.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\isp5f46.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\isprobe.tlb Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\program files (x86)\common files\installshield\professional\runtime\obj6002.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\obj6002.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\objectps.dll Synchronize,Write Data
c:\users\user\appdata\local\temp\62c1.rra Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\_isdelet.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\_se5b86.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5312.tmp\disk1\data1.cab Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5312.tmp\disk1\data1.hdr Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5312.tmp\disk1\engine32.cab Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5312.tmp\disk1\layout.bin Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5312.tmp\disk1\setup.boot Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5312.tmp\disk1\setup.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5312.tmp\disk1\setup.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5312.tmp\disk1\setup.inx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\igd5b08.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\isp5620.tmp\setup.dll Synchronize,Write Data
c:\users\user\appdata\local\temp\isp5620.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\isp5ac8.tmp\_setup.dll Synchronize,Write Data
c:\users\user\appdata\local\temp\isp5ac8.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ispackfiles.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\set5650.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\set5837.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\8bfa059e4515cb4649be94d75dfb0d29_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\a547fdbcd391cf6b8dd10c45ed56b668_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\a547fdbcd391cf6b8dd10c45ed56b668_bfeb5820-9643-42ad-a79f-071dff4d8e64_deleted_ Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\a547fdbcd391cf6b8dd10c45ed56b668_bfeb5820-9643-42ad-a79f-071dff4d8e64_deleted__deleted_ Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\a547fdbcd391cf6b8dd10c45ed56b668_bfeb5820-9643-42ad-a79f-071dff4d8e64_deleted__deleted__deleted_ Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\a547fdbcd391cf6b8dd10c45ed56b668_bfeb5820-9643-42ad-a79f-071dff4d8e64_deleted__deleted__deleted__deleted_ Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{f4817e4b-04b6-11d3-8862-00c04f72f303}\inprocserver32:: C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f4817e4b-04b6-11d3-8862-00c04f72f303}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f4817e4b-04b6-11d3-8862-00c04f72f303}:: PSFactoryBuffer RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f4817e4b-04b6-11d3-8862-00c04f72f303}\proxystubclsid32:: {F4817E4B-04B6-11D3-8862-00C04F72F303} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f4817e4b-04b6-11d3-8862-00c04f72f303}:: ISetupServiceProvider RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f4817e4b-04b6-11d3-8862-00c04f72f303}\nummethods:: 6 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9b697780-dbbc-11d2-80c7-00104b1f6cea}\proxystubclsid32:: {F4817E4B-04B6-11D3-8862-00C04F72F303} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9b697780-dbbc-11d2-80c7-00104b1f6cea}:: ISetupObjectClass RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9b697780-dbbc-11d2-80c7-00104b1f6cea}\nummethods:: 5 RegNtPreCreateKey
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0:: InstallShield Professional Setup Kernel 7.0 RegNtPreCreateKey
Show More
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0\flags:: 0 RegNtPreCreateKey
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0\0\win32:: C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\IsProBE.tlb RegNtPreCreateKey
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0\helpdir:: C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}:: ISetupTransferEvents RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}:: ISetupTransferEvents RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}:: ISetupFeature RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}:: ISetupFeature RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}:: ISetupBasicFeature RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}:: ISetupBasicFeature RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLog RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLog RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLogs RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLogs RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpSequence RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpSequence RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}:: ISetupLogDB RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}:: ISetupLogDB RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpTypes RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpTypes RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpType RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpType RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}:: ISetupBasicFeatureStateEvents RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}:: ISetupBasicFeatureStateEvents RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}:: ISetupFeatures RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}:: ISetupFeatures RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}:: ISetupTransferEvents2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}:: ISetupTransferEvents2 RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}:: ISetupLogDB2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}:: ISetupLogDB2 RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}:: ISetupOpSequence2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}:: ISetupOpSequence2 RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ebf-b5f0-11d2-80b9-00104b1f6cea}:: ISetupMedia RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ebf-b5f0-11d2-80b9-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ebf-b5f0-11d2-80b9-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ebf-b5f0-11d2-80b9-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{91814ebf-b5f0-11d2-80b9-00104b1f6cea}:: ISetupMedia RegNtPreCreateKey
HKLM\software\classes\interface\{91814ebf-b5f0-11d2-80b9-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{91814ebf-b5f0-11d2-80b9-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{91814ebf-b5f0-11d2-80b9-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{44d61997-b7d4-11d2-80ba-00104b1f6cea}:: ISetupCABFiles RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{44d61997-b7d4-11d2-80ba-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{44d61997-b7d4-11d2-80ba-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{44d61997-b7d4-11d2-80ba-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{44d61997-b7d4-11d2-80ba-00104b1f6cea}:: ISetupCABFiles RegNtPreCreateKey
HKLM\software\classes\interface\{44d61997-b7d4-11d2-80ba-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{44d61997-b7d4-11d2-80ba-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{44d61997-b7d4-11d2-80ba-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec1-b5f0-11d2-80b9-00104b1f6cea}:: ISetupCABFile RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec1-b5f0-11d2-80b9-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec1-b5f0-11d2-80b9-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec1-b5f0-11d2-80b9-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec1-b5f0-11d2-80b9-00104b1f6cea}:: ISetupCABFile RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec1-b5f0-11d2-80b9-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec1-b5f0-11d2-80b9-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec1-b5f0-11d2-80b9-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec5-b5f0-11d2-80b9-00104b1f6cea}:: ISetupComponents RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec5-b5f0-11d2-80b9-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec5-b5f0-11d2-80b9-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec5-b5f0-11d2-80b9-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec5-b5f0-11d2-80b9-00104b1f6cea}:: ISetupComponents RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec5-b5f0-11d2-80b9-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec5-b5f0-11d2-80b9-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec5-b5f0-11d2-80b9-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec3-b5f0-11d2-80b9-00104b1f6cea}:: ISetupComponent RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec3-b5f0-11d2-80b9-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec3-b5f0-11d2-80b9-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{91814ec3-b5f0-11d2-80b9-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec3-b5f0-11d2-80b9-00104b1f6cea}:: ISetupComponent RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec3-b5f0-11d2-80b9-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec3-b5f0-11d2-80b9-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{91814ec3-b5f0-11d2-80b9-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2061-cb55-11d2-8094-00104b1f9838}:: ISetupObjects RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2061-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2061-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2061-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2061-cb55-11d2-8094-00104b1f9838}:: ISetupObjects RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2061-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2061-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2061-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2060-cb55-11d2-8094-00104b1f9838}:: ISetupObject RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2060-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2060-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2060-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2060-cb55-11d2-8094-00104b1f9838}:: ISetupObject RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2060-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2060-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2060-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ded5feec-225a-11d3-88aa-00c04f72f303}:: ISetupFilesCost RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ded5feec-225a-11d3-88aa-00c04f72f303}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ded5feec-225a-11d3-88aa-00c04f72f303}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ded5feec-225a-11d3-88aa-00c04f72f303}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{ded5feec-225a-11d3-88aa-00c04f72f303}:: ISetupFilesCost RegNtPreCreateKey
HKLM\software\classes\interface\{ded5feec-225a-11d3-88aa-00c04f72f303}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{ded5feec-225a-11d3-88aa-00c04f72f303}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{ded5feec-225a-11d3-88aa-00c04f72f303}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2069-cb55-11d2-8094-00104b1f9838}:: ISetupDriver RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2069-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2069-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2069-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2069-cb55-11d2-8094-00104b1f9838}:: ISetupDriver RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2069-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2069-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2069-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{d4ff39bb-1a05-11d3-8896-00c04f72f303}:: ISetupTypes RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{d4ff39bb-1a05-11d3-8896-00c04f72f303}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{d4ff39bb-1a05-11d3-8896-00c04f72f303}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey

491 additional registry modifications are not displayed above.

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Shell Command Execution

c:\users\user\downloads\a3ed17bab7a69d9e43e0c4df2db54e3f4362f233_0006690604 -deleter

Trending

Most Viewed

Loading...