PUP.XYNTService.A

Analysis Report

General information

Family Name: PUP.XYNTService.A
Signature status: Self Signed

Known Samples

MD5: f21bd735e4876faa30916a0bb07ef7bc
SHA1: b9275716107d78f3460370219b849bc0ee4a361c
SHA256: 12E3BAD4E03D86B354E98F22885ABA69CC22D69F4E365BC3034357CA2632C3C9
File Size: 1.73 MB, 1726544 bytes
MD5: cf5fac0f21bfaf7aa8b235ed62e1971d
SHA1: 9608885539b7e1e4d012670c217c62c58a07754c
SHA256: 5988A6A579A847FE54CB3B2C0675ECC424043301A7A1FBE87D12880763E10489
File Size: 3.51 MB, 3513400 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
File Description Process Them Setup
Legal Copyright Copyright © 2002-2010 Kadmy, Inc.
Product Name Process Them

Digital Signatures

Signer Root Status
SmarterTools, Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
Kadmy Inc. Kadmy Inc Self Signed

File Traits

  • No Version Info
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsna871.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsna871.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsna871.tmp\system.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey

Trending

Most Viewed

Loading...