Threat Database Trojans Trojan.Banker.AX

Trojan.Banker.AX

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,072
Threat Level: 80 % (High)
Infected Computers: 4,777
First Seen: October 28, 2021
Last Seen: June 18, 2026
OS(es) Affected: Windows

The detection of Trojan.Banker.AX on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and potentially steal sensitive information, making it essential to understand its nature and how to remove it effectively.

What Is Trojan.Banker.AX?

Trojan.Banker.AX is!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! identified as a Trojan-type threat. Trojans are malicious programs that disguise themselves as legitimate software to gain unauthorized access to a computer system. They can be used for various malicious purposes, including stealing personal data, installing additional malware, or providing unauthorized access to the infected system. The ".Banker" part of the name suggests it might be focused on banking or financial information theft, but without specific details, it's crucial to approach the situation with a broad understanding of malware removal best practices.

How Trojan.Banker.AX Operates

Generally, Trojans like Trojan.Banker.AX operate by deceiving users into installing them on their systems. This can happen through various means, such as opening malicious email attachments, downloading infected software, or visiting compromised websites. Once installed, the Trojan can carry out its intended malicious activities, which might include monitoring and logging keystrokes, stealing login credentials, or even allowing remote access to the infected computer. The exact operation method of Trojan.Banker.AX is not specified, but understanding how Trojans typically work can help in taking preventive measures.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but may include unusual system behavior, such as unexpected pop-ups, slow system performance, or unfamiliar programs running in the background. Users might also notice that their personal files have been altered or that they are experiencing difficulties with their internet connection. In some cases, the infection might not exhibit any noticeable symptoms at all, making regular system checks and the use of antivirus software crucial for detection.

How to Remove Trojan.Banker.AX

  1. Enter Safe Mode with Networking to restrict the malware's ability to spread or communicate with its command and control servers. This mode allows you to use the internet to download removal tools if necessary.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove all traces of the malware. Ensure your antivirus software is updated to the latest version for the best detection and removal capabilities.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are sure are not needed or are known to be malicious.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the Trojan. This can often be done through the browser's settings or options menu.
  5. After completing the above steps, reboot your computer and perform another full system scan to ensure that the malware has been completely removed. Repeat the scan a few times if necessary, until no threats are detected.

Conclusion

Removing Trojan.Banker.AX from your system requires careful and systematic steps to ensure all components of the malware are eliminated. It's also crucial to adopt preventive measures to avoid future infections, including keeping your operating system and software up to date, using strong antivirus protection, and being cautious when downloading and installing new programs or opening email attachments. By understanding how Trojans operate and taking the right removal steps, you can protect your personal data and maintain the security of your computer system.

Analysis Report

General information

Family Name: Trojan.Banker.AX
Signature status: No Signature

Known Samples

MD5: 245d34e26afbb76ca47c53c45ede0a08
SHA1: 9b9810451252ce064d7f57019b92774e5718063c
File Size: 1.84 MB, 1843200 bytes
MD5: a8a8c3f0392fefdca8573fffe8ff93bf
SHA1: e2e7d040729707aa85f1cfbf6375002bde173e50
SHA256: 7787CD710AFB80789F7C1BD923301B6DE346109EBCEBD56C1C46E1888CBDCBAE
File Size: 847.36 KB, 847360 bytes
MD5: 8dccdaf744c42a8b81861a4c47f1168b
SHA1: 538fee23f7b34517d52db9bfabc49674aa1a2f59
SHA256: 0829438F8C4583F4E006D4561571E24435A5BEF1E7B588ED98B453900A9C8EC2
File Size: 2.12 MB, 2120192 bytes
MD5: cf74281bb7ad54e9e47abee95caa3049
SHA1: c9a40ae9d86a8c600fbaca95c99e7de2a30c9808
SHA256: 42EF7D0DC47CCF612368901CCE9DB990C7E90697483637FE9AE281796FCDA4F3
File Size: 1.27 MB, 1270170 bytes
MD5: 20ad0c0b8502b284b26b8ee184639a6b
SHA1: cacaaf8c8a6eb6730e7a72f39b2ba68104bcdb33
SHA256: 55A79F4C661FA894F2C268B7EF1EF7ED5208D48DED54FFC0B774C7BEB3E9FCC2
File Size: 1.15 MB, 1153536 bytes
Show More
MD5: daf2eaff8cf627f19157d3f0fbf189d4
SHA1: 2a2733836a69a2c3af1a42bcd94390a06fd549de
SHA256: 39FD0A53EC0306E6530E873296ADEDA1ACB7AAE6186225B6C0AE9FE92DE50306
File Size: 1.04 MB, 1039872 bytes
MD5: 7b7c06a1f417a903987749a49652c983
SHA1: 38b93f274bcb41ab43e6170bf6fb92896e396297
SHA256: 1A126804F121E0F72C71CFDBCE0686B4AB346315561CE76D04EDF85D3538E3E0
File Size: 1.95 MB, 1952829 bytes
MD5: e13ba401f27767740e482788ec492c81
SHA1: 9509c6645e5a7aa5950cfa120a301d7a7fcca6b8
SHA256: 4EB9086B845EAA442C170FA51E392EC79F7CF3CAC2B88F103D613109D519C6DF
File Size: 771.58 KB, 771584 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Synaptics
File Description Synaptics Pointing Device Driver
File Version
  • 1.00
  • 1.0.0.4
Internal Name TJprojMain
Original Filename TJprojMain.exe
Product Name
  • Project1
  • Synaptics Pointing Device Driver
Product Version
  • 1.00
  • 1.0.0.0

File Traits

  • dll
  • x86

Block Information

Total Blocks: 3,108
Potentially Malicious Blocks: 150
Whitelisted Blocks: 2,958
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Banker.MA
  • Darkkomet.DE
  • Darkkomet.LH
  • Ekstak.AN
  • FakeAlert.X
Show More
  • Kasperagent.A
  • Kryptik.LFT
  • PWS.Onlinegames.AS
  • QQPass.AK
  • Trojan.Downloader.Gen.HP
  • Trojan.Downloader.Gen.MD
  • Woreflint.A

Files Modified

File Attributes
c:\programdata\synaptics Synchronize,Write Attributes
c:\programdata\synaptics\rcx539a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\rcxbba4.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\rcxfa56.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\synaptics.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\synaptics\synaptics.exe Synchronize,Write Attributes
c:\programdata\synaptics\synaptics.exe Synchronize,Write Data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_2a2733836a69a2c3af1a42bcd94390a06fd549de_0001039872 Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\downloads\._cache_2a2733836a69a2c3af1a42bcd94390a06fd549de_0001039872 Synchronize,Write Attributes
c:\users\user\downloads\._cache_9b9810451252ce064d7f57019b92774e5718063c_0001843200.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_9b9810451252ce064d7f57019b92774e5718063c_0001843200.exe Synchronize,Write Attributes
c:\users\user\downloads\._cache_e2e7d040729707aa85f1cfbf6375002bde173e50_0000847360 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_e2e7d040729707aa85f1cfbf6375002bde173e50_0000847360 Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 eS�r�p��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�������B�O�����x�%���8�5����Bx��� ���\�!IN�sb �!>!wz#@�#��#�O$kF$��$¨%:�%f RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::synaptics pointing device driver C:\ProgramData\Synaptics\Synaptics.exe RegNtPreCreateKey
HKCU\software\pc soft\windev\24.0\appli\._cache_9b9810451252ce064d7f57019b92774e5718063c_0001843200::last_framework 240024g RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��� xy0kP~�ރ0���o��^0۴�B}�T Vs}�kP~5�)����1���B���d0B `F e�>��1v��h�n�}0e��0e�� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 D^�r�E��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�������B�����x�%���8�5����Bx�������\�!IN�sb!>#@�#��#�O$kF$��%f�%�'�'i'�!(�) RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 愵ȁ偫~Ꚑơљ龡^듛ï紘Çʇ獖}B偫~B엦1좟Êdᵂċ ᵆċe岘엦1´¶}ꙥžꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀT���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p��^�o�ee=Vs}kP~��1.��7 ���ﺃee��� ��1��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9� RegNtPreCreateKey

Windows API Usage

Category API
Service Control
  • OpenSCManager
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

runas c:\users\user\downloads\._cache_9b9810451252ce064d7f57019b92774e5718063c_0001843200.exe
runas C:\ProgramData\Synaptics\Synaptics.exe InjUpdate
runas c:\users\user\downloads\._cache_e2e7d040729707aa85f1cfbf6375002bde173e50_0000847360
runas c:\users\user\downloads\._cache_2a2733836a69a2c3af1a42bcd94390a06fd549de_0001039872

Related Posts

Trending

Most Viewed

Loading...