PUP.PC SpeedCat

Threat Scorecard

Popularity Rank: 3,287
Threat Level: 10 % (Normal)
Infected Computers: 6,195
First Seen: March 27, 2019
Last Seen: February 6, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove PUP.PC SpeedCat

File System Details

PUP.PC SpeedCat may create the following file(s):
# File Name MD5 Detections
1. PCSpeedCat.exe 522c10d2699b5891d0949b529308b011 2,850
2. ee89b6b9864dd81c50d975156e28fa011439dd5526391130c8df4072f7791380.exe b7fe9750c2ca2d32c87b5d05cefde68f 328
3. speedcat.setup_240911.exe ebcc19250b9d70266e0ce6f5fd3b94f9 326
4. trz114A.tmp 303847905860063499b4eb108459f1ad 322
5. speedcat.setup_121118.exe f728174b4ad0d53460db267fd5b4f5a7 4
6. ff6f18824c070ce0f943b9602c764244fc72a9ad8d6b045a77ca1d1c963d4a13.exe c63887b5ef633b94897a14decda664ff 2
7. speedcat.setup.exe a96f347c779146314a5280afc0eec146 1
8. speedcat.setup 1.2.2018.exe 06c86b5869453c4b13940e1ca20673af 0
9. speedcat.setup_190110.exe f2137c3bbd1d441d77a16c41fad1dd13 0
10. speedcat.setup [2].exe 9fa2d1587db1b03d1a4dd2acdd985d21 0

Analysis Report

General information

Family Name: PUP.PC SpeedCat
Signature status: Modified signature

Known Samples

MD5: aed1356d86848aeec7011cfaa5208c4f
SHA1: 5bd5b687f982ac125ed64b4d6e4be35e77ed18df
File Size: 2.73 MB, 2728560 bytes
MD5: a835092c575ecca4273a3e6f29708970
SHA1: 7ebaefdbae03bdc141e905cfb11d19fa4330c43f
File Size: 2.73 MB, 2728552 bytes
MD5: 64cf54e759fdcfcdb3ba056d2b53cc25
SHA1: 5ba82829ff209660516c932563bddd76c58c00cd
File Size: 2.73 MB, 2734712 bytes
MD5: 8007332153b07035bf7bd0a37281587b
SHA1: a1fbda7d0224bfc4512ed8d71c09793a4d07de71
SHA256: 8653BE3E1193694EB538AF1C9F57B5456426A935AD256EF04C37CD17FA769F3D
File Size: 2.73 MB, 2729328 bytes
MD5: 3f4375831be5b74affb8a1c70e6af848
SHA1: 2c961ffd0e9ea66d1c534f40b2649d62cb11750b
SHA256: 2A51A158FA9A703D674E3C4857918F480532F82292B68BE254C47123027D7160
File Size: 2.73 MB, 2728536 bytes
Show More
MD5: f69f31ec9e15fa1e54d6757502a72c45
SHA1: 44397d4bc3c8db6f8983e77775189b125b71658d
SHA256: B8AEEC7488DA6E98F7795EB05CCBD0728B9C9318BAF0D8321FB1DA47F7869998
File Size: 2.73 MB, 2734712 bytes
MD5: fddb431657492f944877ee4dc189cac7
SHA1: d0ce8c360ff2f50b2d3b548f99fc3cefc41c4280
SHA256: CFAA3F64496CEA699C5CDC11E5F4572EA38D15DF4D2E66DDF0ADB53C9FA10717
File Size: 2.73 MB, 2728544 bytes
MD5: 7862ec83757a85d5a820780e74a5a0a6
SHA1: 7df792a8faed19569082980195e65d6fb1dc3e28
SHA256: F72B496FFD68F47BDF9BD245F091EB05858EEC8131407886CD4E4CE3275CDCFB
File Size: 2.73 MB, 2729280 bytes
MD5: 2e32044bf35115eb80a5970b1e531dcc
SHA1: b95e9b6da7b3420de4ea43e03dd73d24c2f9f523
SHA256: 08B2C520A6AA63297DF260ED660A2BE4FCBE16DE5A4290878E6A66508384D2F1
File Size: 2.73 MB, 2728872 bytes
MD5: 7828c24e16235297d51d5d0b6b421fc4
SHA1: 8e71665bbde7f7552c7e103d5478e6f1ab201140
SHA256: B67922E3C263B02D124FCB383773A02269626330B9BBB7A0A2588FFFD314A0FE
File Size: 2.73 MB, 2728560 bytes
MD5: 8a64d087944ae6791bd505be77a50952
SHA1: 575a5160e95970fe199425e2cdefd93575eb69a5
SHA256: 90030E77E24D5B66FD1DE30DEEDBC876E3C0ABE9898F76F9EB72065ADDB886B6
File Size: 2.73 MB, 2729336 bytes
MD5: d0f1cf6d847f62f4feef54a6d20ce527
SHA1: 714206f205ac75ad8c3c7d2266f82f82d19e8a70
SHA256: A60E43AD4A667236275094799A9928DFE011C7BF91FDD3BB371A92E3CAF51B28
File Size: 2.73 MB, 2734752 bytes
MD5: 6472c763351110644ad39d6a128a0a1f
SHA1: 1ce222bf496dab78a19f13b68401ca64ffe6fd3b
SHA256: A14FA8AA38609C83AB93E00AD6723F1C343ABACC5FBC3A50F47C125E78716748
File Size: 2.73 MB, 2734728 bytes
MD5: e28d7b804aa40faeb08e04aefe416b02
SHA1: a2e45014ca88a973dc12ac27bde70ebdbad10be7
SHA256: 7519FD016804CF238C774DFDEF15333B94BDB8D0567F8911DBC05E5C0FFFC99C
File Size: 2.73 MB, 2729328 bytes
MD5: 5b3b7062ca8f774eea502dc87c990be4
SHA1: adbc9a4cab7689531ba5dfe21361406f02f87189
SHA256: 2B38224B9C9780E49EFFB30C1EE1AB24FB5C84DEE863DC352D5865D54B62CDDB
File Size: 2.73 MB, 2729320 bytes
MD5: 6dc4a9dd75fd6a783ec3e96658dc470a
SHA1: 164414e5efc03319ae3a05883332c3addb5633a7
SHA256: BF428F8C95FF64F32BF347A1D041B68367D312B69C0DC9CB4F441FA3827EED3B
File Size: 2.73 MB, 2729336 bytes
MD5: 14d697b97e789e7417aeb296e429ae45
SHA1: fb895183fba9e1a334ec458aeb3db462841034c5
SHA256: 904197A5596695287CACBA6E608D81BE7A8C0A52A0D25CC0BC96FDABE1E1E983
File Size: 2.82 MB, 2818568 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
File Description
  • Installer
  • IT Stub Installer -SETUPIT-V2
File Version 11.2.1
Product Name
  • IT-Setup
  • Setup
Product Version 11.2.1

File Traits

  • 2+ executable sections
  • Inno
  • InnoSetup Installer
  • Installer Manifest
  • Installer Version
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\pc speedcat-logs\log_it.log Generic Write,Read Attributes
c:\users\user\appdata\local\speedcat-logs\log_it.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-0q7i4.tmp\164414e5efc03319ae3a05883332c3addb5633a7_0002729336.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3gq2j.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3gq2j.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3gq2j.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3gq2j.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3gq2j.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3gq2j.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3gq2j.tmp\parsfrms.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\is-3gq2j.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3gq2j.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3gq2j.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3gq2j.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-3rntc.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3rntc.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3rntc.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3rntc.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3rntc.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3rntc.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3rntc.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3rntc.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3rntc.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-3rntc.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3rntc.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-59200.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-59200.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-59200.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-59200.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-59200.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-59200.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-59200.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-59200.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-59200.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-59200.tmp\temporary\acat-setupit-nd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-59200.tmp\temporary\acat-setupit-nd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-69nm4.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-69nm4.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-69nm4.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-69nm4.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-69nm4.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-69nm4.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-69nm4.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-69nm4.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-69nm4.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-69nm4.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-69nm4.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-75e45.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-75e45.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-75e45.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-75e45.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-75e45.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-75e45.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-75e45.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-75e45.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-75e45.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-75e45.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-75e45.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-7gp9c.tmp\5bd5b687f982ac125ed64b4d6e4be35e77ed18df_0002728560.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7kr47.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-7kr47.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-7kr47.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7kr47.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7kr47.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7kr47.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7kr47.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7kr47.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7kr47.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7kr47.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-7kr47.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-7qcvv.tmp\2c961ffd0e9ea66d1c534f40b2649d62cb11750b_0002728536.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-8f1nd.tmp\d0ce8c360ff2f50b2d3b548f99fc3cefc41c4280_0002728544.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-af7t0.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-af7t0.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-af7t0.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-af7t0.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-af7t0.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-af7t0.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-af7t0.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-af7t0.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-af7t0.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-af7t0.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-af7t0.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-akkhc.tmp\714206f205ac75ad8c3c7d2266f82f82d19e8a70_0002734752.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-aq22m.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-aq22m.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-aq22m.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-aq22m.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-aq22m.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-aq22m.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-aq22m.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-aq22m.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-aq22m.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-aq22m.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-aq22m.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-bbm7b.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bbm7b.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bbm7b.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bbm7b.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bbm7b.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bbm7b.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bbm7b.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bbm7b.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bbm7b.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bbm7b.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bbm7b.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-bsi59.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bsi59.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bsi59.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bsi59.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bsi59.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bsi59.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bsi59.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bsi59.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bsi59.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bsi59.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bsi59.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-c7ta3.tmp\a2e45014ca88a973dc12ac27bde70ebdbad10be7_0002729328.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-d7hiu.tmp\fb895183fba9e1a334ec458aeb3db462841034c5_0002818568.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-dqu16.tmp\575a5160e95970fe199425e2cdefd93575eb69a5_0002729336.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ebdju.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-ebdju.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-ebdju.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ebdju.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ebdju.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ebdju.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ebdju.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ebdju.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ebdju.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ebdju.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-ebdju.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-g0eaj.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-g0eaj.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-g0eaj.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-g0eaj.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-g0eaj.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-g0eaj.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-g0eaj.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-g0eaj.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-g0eaj.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-g0eaj.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-g0eaj.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-g37jc.tmp\adbc9a4cab7689531ba5dfe21361406f02f87189_0002729320.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jo059.tmp\b95e9b6da7b3420de4ea43e03dd73d24c2f9f523_0002728872.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jp3g1.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-jp3g1.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-jp3g1.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jp3g1.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jp3g1.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jp3g1.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jp3g1.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jp3g1.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jp3g1.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jp3g1.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-jp3g1.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-mnopn.tmp\5ba82829ff209660516c932563bddd76c58c00cd_0002734712.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-n2pug.tmp\1ce222bf496dab78a19f13b68401ca64ffe6fd3b_0002734728.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-nqc2i.tmp\44397d4bc3c8db6f8983e77775189b125b71658d_0002734712.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pk5f3.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-pk5f3.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-pk5f3.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pk5f3.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pk5f3.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pk5f3.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pk5f3.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pk5f3.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pk5f3.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-pk5f3.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-pk5f3.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-qhas9.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-qhas9.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-qhas9.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-qhas9.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-qhas9.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-qhas9.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-qhas9.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-qhas9.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-qhas9.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-qhas9.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-qhas9.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-r1nip.tmp\8e71665bbde7f7552c7e103d5478e6f1ab201140_0002728560.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-rh3ag.tmp\a1fbda7d0224bfc4512ed8d71c09793a4d07de71_0002729328.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vceuj.tmp\7df792a8faed19569082980195e65d6fb1dc3e28_0002729280.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqboo.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-vqboo.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-vqboo.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqboo.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqboo.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqboo.tmp\parsdwn.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqboo.tmp\parsfrms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqboo.tmp\parsin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqboo.tmp\presplashni.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqboo.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-vqboo.tmp\temporary\setupit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\is-vqsm7.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-vqsm7.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-vqsm7.tmp\idp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqsm7.tmp\itspllite.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqsm7.tmp\parscon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-vqsm7.tmp\parsdwn.dll Generic Write,Read Attributes

6 additional files are not displayed above.

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState
Network Wininet
  • InternetOpen
  • InternetOpenUrl
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

"C:\Users\Dnqbrtjs\AppData\Local\Temp\is-7GP9C.tmp\5bd5b687f982ac125ed64b4d6e4be35e77ed18df_0002728560.tmp" /SL5="$1025A,2137460,214528,c:\users\user\downloads\5bd5b687f982ac125ed64b4d6e4be35e77ed18df_0002728560.exe"
"C:\Users\Ucsktujf\AppData\Local\Temp\is-VUN3A.tmp\7ebaefdbae03bdc141e905cfb11d19fa4330c43f_0002728552.tmp" /SL5="$40274,2137460,214528,c:\users\user\downloads\7ebaefdbae03bdc141e905cfb11d19fa4330c43f_0002728552.exe"
"C:\Users\Vwetjnhe\AppData\Local\Temp\is-MNOPN.tmp\5ba82829ff209660516c932563bddd76c58c00cd_0002734712.tmp" /SL5="$E0068,2147093,214528,c:\users\user\downloads\5ba82829ff209660516c932563bddd76c58c00cd_0002734712"
"C:\Users\Dystrtru\AppData\Local\Temp\is-RH3AG.tmp\a1fbda7d0224bfc4512ed8d71c09793a4d07de71_0002729328.tmp" /SL5="$60068,2137460,214528,c:\users\user\downloads\a1fbda7d0224bfc4512ed8d71c09793a4d07de71_0002729328"
"C:\Users\Vqspywcg\AppData\Local\Temp\is-7QCVV.tmp\2c961ffd0e9ea66d1c534f40b2649d62cb11750b_0002728536.tmp" /SL5="$9020C,2137460,214528,c:\users\user\downloads\2c961ffd0e9ea66d1c534f40b2649d62cb11750b_0002728536"
Show More
"C:\Users\Pqcangng\AppData\Local\Temp\is-NQC2I.tmp\44397d4bc3c8db6f8983e77775189b125b71658d_0002734712.tmp" /SL5="$20138,2147093,214528,c:\users\user\downloads\44397d4bc3c8db6f8983e77775189b125b71658d_0002734712"
"C:\Users\Chleqxdy\AppData\Local\Temp\is-8F1ND.tmp\d0ce8c360ff2f50b2d3b548f99fc3cefc41c4280_0002728544.tmp" /SL5="$30144,2137460,214528,c:\users\user\downloads\d0ce8c360ff2f50b2d3b548f99fc3cefc41c4280_0002728544"
"C:\Users\Nkoxnpyo\AppData\Local\Temp\is-VCEUJ.tmp\7df792a8faed19569082980195e65d6fb1dc3e28_0002729280.tmp" /SL5="$50056,2137460,214528,c:\users\user\downloads\7df792a8faed19569082980195e65d6fb1dc3e28_0002729280"
"C:\Users\Wdnhxrso\AppData\Local\Temp\is-JO059.tmp\b95e9b6da7b3420de4ea43e03dd73d24c2f9f523_0002728872.tmp" /SL5="$400AC,2137460,214528,c:\users\user\downloads\b95e9b6da7b3420de4ea43e03dd73d24c2f9f523_0002728872"
"C:\Users\Mfcirnxi\AppData\Local\Temp\is-R1NIP.tmp\8e71665bbde7f7552c7e103d5478e6f1ab201140_0002728560.tmp" /SL5="$F0258,2137460,214528,c:\users\user\downloads\8e71665bbde7f7552c7e103d5478e6f1ab201140_0002728560"
"C:\Users\Dfxiaghz\AppData\Local\Temp\is-DQU16.tmp\575a5160e95970fe199425e2cdefd93575eb69a5_0002729336.tmp" /SL5="$6038E,2137460,214528,c:\users\user\downloads\575a5160e95970fe199425e2cdefd93575eb69a5_0002729336"
"C:\Users\Apwchuuq\AppData\Local\Temp\is-AKKHC.tmp\714206f205ac75ad8c3c7d2266f82f82d19e8a70_0002734752.tmp" /SL5="$9034A,2147093,214528,c:\users\user\downloads\714206f205ac75ad8c3c7d2266f82f82d19e8a70_0002734752"
"C:\Users\Hxraznun\AppData\Local\Temp\is-N2PUG.tmp\1ce222bf496dab78a19f13b68401ca64ffe6fd3b_0002734728.tmp" /SL5="$302A6,2147093,214528,c:\users\user\downloads\1ce222bf496dab78a19f13b68401ca64ffe6fd3b_0002734728"
"C:\Users\Yzliaxwq\AppData\Local\Temp\is-C7TA3.tmp\a2e45014ca88a973dc12ac27bde70ebdbad10be7_0002729328.tmp" /SL5="$402A4,2137460,214528,c:\users\user\downloads\a2e45014ca88a973dc12ac27bde70ebdbad10be7_0002729328"
"C:\Users\Codrtiny\AppData\Local\Temp\is-G37JC.tmp\adbc9a4cab7689531ba5dfe21361406f02f87189_0002729320.tmp" /SL5="$70180,2137460,214528,c:\users\user\downloads\adbc9a4cab7689531ba5dfe21361406f02f87189_0002729320"
"C:\Users\Mnnsfqih\AppData\Local\Temp\is-0Q7I4.tmp\164414e5efc03319ae3a05883332c3addb5633a7_0002729336.tmp" /SL5="$6037E,2137460,214528,c:\users\user\downloads\164414e5efc03319ae3a05883332c3addb5633a7_0002729336"
"C:\Users\Dotuklih\AppData\Local\Temp\is-D7HIU.tmp\fb895183fba9e1a334ec458aeb3db462841034c5_0002818568.tmp" /SL5="$3036C,2231333,214528,c:\users\user\downloads\fb895183fba9e1a334ec458aeb3db462841034c5_0002818568"

Trending

Most Viewed

Loading...