PUP.Registry Winner

Threat Scorecard

Popularity Rank: 4,232
Threat Level: 10 % (Normal)
Infected Computers: 3,405
First Seen: March 27, 2019
Last Seen: January 20, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove PUP.Registry Winner

File System Details

PUP.Registry Winner may create the following file(s):
# File Name MD5 Detections
1. 7.1.10.12_RegistryWinner_Setup.exe c9e8c6fd661e8aef00d9aecdd0a98f49 96
2. 7.1.12.18_RegistryWinner_Setup.exe 982cd8613985dcf336229dd611ecae9a 18

Analysis Report

General information

Family Name: PUP.Registry Winner
Signature status: Root Not Trusted

Known Samples

MD5: 3fe37d6961ee95d8957a453f03bd27b7
SHA1: 7c7d9ea770bf50ca750df25f3bfd7187d8e74886
SHA256: D863A81D30DB3816E69EFB1997BC09298542F5CE8E37EF1E5C94FAE4052342BC
File Size: 739.28 KB, 739285 bytes
MD5: c5ee2b84e836ab49a47a4b9694dc889d
SHA1: ed2298cf2b2d16b753b1eeac2c130efa5c9ac9e5
SHA256: F75C6B2C8BB0C4A58AFA4591CFA979AAF3B25CD10EC5FDC8C24FA1C61DD34965
File Size: 5.92 MB, 5918448 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name EveryonePiano.com
File Description
  • EveryonePiano Setup
  • Setup/Uninstall
File Version
  • 51.52.0.0
  • 1.6.12.1
Legal Copyright Copyright (C) 2008-2017 EveryonePiano.com
Product Name EveryonePiano
Product Version 1.6.12.1

Digital Signatures

Signer Root Status
ALIKET SOFTWARE CO., LTD. thawte Primary Root CA Root Not Trusted

File Traits

  • HighEntropy
  • Inno
  • Installer Manifest
  • Installer Version
  • x86

Block Information

Similar Families

  • Dropper.Delf.C
  • Dropper.Delf.CF
  • Injector.AJA
  • Injector.KPD
  • Morto.B
Show More
  • Softcnapp.N

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-m604l.tmp\ed2298cf2b2d16b753b1eeac2c130efa5c9ac9e5_0005918448.tmp Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Tkyhheqg\AppData\Local\Temp\is-M604L.tmp\ed2298cf2b2d16b753b1eeac2c130efa5c9ac9e5_0005918448.tmp" /SL5="$601E6,5536618,66048,c:\users\user\downloads\ed2298cf2b2d16b753b1eeac2c130efa5c9ac9e5_0005918448"

Trending

Most Viewed

Loading...