Threat Database Trojans Trojan.Dropper.Dinwod.A

Trojan.Dropper.Dinwod.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 2,754
Threat Level: 80 % (High)
Infected Computers: 644
First Seen: April 18, 2018
Last Seen: August 3, 2026
OS(es) Affected: Windows

The detection of Trojan.Dropper.Dinwod.A on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, a step-by-step guide on how to remove it from your computer.

What Is Trojan.Dropper.Dinwod.A?

Trojan.Dropper.Dinwod.A is identified as a Trojan-type threat, which means it is designed to deceive users into installing it on their systems by disguising itself as legitimate software. Once installed, it can lead to a variety of malicious activities, including but not limited to, data theft, unauthorized access to the system, and the installation of additional malware. The name itself does not directly point to a specific malware family but indicates its capability to drop or install other malicious components on the infected system.

How Trojan.Dropper.Dinwod.A Operates

Trojan.Dropper.Dinwod.A operates by exploiting vulnerabilities in the system or by tricking the user into executing the malicious file. Upon execution, it may connect to remote servers to download and install additional malware, which can lead to severe consequences such as compromising personal data, hijacking the system for botnet activities, or even encrypting files for ransom. The dropper aspect of this malware signifies its ability to deliver a payload, which could be any type of malicious software designed to carry out specific malicious tasks.

Symptoms of Infection

Symptoms of a Trojan.Dropper.Dinwod.A infection can vary widely depending on the payload it delivers. Common indicators include unusual system behavior, such as slow performance, frequent crashes, or the appearance of unwanted programs and toolbars in your web browser. You might also notice that your antivirus software is disabled or that certain system settings have been altered without your permission. Sometimes, the infection might not exhibit obvious symptoms, making it difficult to detect without proper scanning tools.

How to Remove Trojan.Dropper.Dinwod.A

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This can usually be done by pressing a specific key (such as F8) during system startup and selecting the appropriate option from the boot menu.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing the malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only uninstall programs you are certain are not necessary for your system's operation.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings that the malware might have altered. This can usually be done from within the browser's settings or options menu.
  5. After completing the above steps, reboot your system and perform another scan to ensure that the malware has been successfully removed. Repeat the scanning process until no threats are detected.

Conclusion

Removing Trojan.Dropper.Dinwod.A requires careful and systematic steps to ensure that all components of the malware are eliminated from the system. It's crucial to stay vigilant and keep your antivirus software updated to protect against future infections. Regularly backing up important data and being cautious when opening email attachments or downloading software from the internet can also help prevent malware infections. If you are not comfortable with the removal process or if the problem persists after attempting to remove the malware, consider seeking help from a professional.

Analysis Report

General information

Family Name: Trojan.Dropper.Dinwod.A
Signature status: Self Signed

Known Samples

MD5: 8c9bcf774eb868981e922af76205013d
SHA1: d1784c333debf553bbbb4359a1c3aaceafde6251
SHA256: 195B02D994ED45D6E20655E3705BA134A9523AB26655BED194C27247DBA3EBF1
File Size: 6.20 MB, 6197760 bytes
MD5: 93b2c8bfce4d9ea37cfe550189da226d
SHA1: a46c1c073612de6622f0c6a3181299f9a979f467
SHA256: 6C3769CE6A896CC0C4AC3AA033D1EBFD4DDDFC0359CA7FB40FC1A0CAF508F7AA
File Size: 1.65 MB, 1650176 bytes
MD5: 00f3f1bc54581dccde0f59ec2edf712e
SHA1: e5f2d2ff6d43a07a1558f8eccacb98826c081c8a
SHA256: 71166C599A418AD339A3677734ED8B9D54DBE15409EA8A9D0CE3E9BFF5FE12BF
File Size: 4.02 MB, 4021760 bytes
MD5: 7fd3e4d6113611594a5959ad0689d56a
SHA1: 77aedeb31f547f024c3a9fba9b76d906ddba3537
SHA256: C4C5648DE56667596AC4CA55F602BF60133EF805E9E8B00F609C3F8043A5B9FF
File Size: 568.32 KB, 568320 bytes
MD5: c78aaaa0e7c82aa7f429aa57834b8eaa
SHA1: 3300093f0458027edbd017126222408da9984dd9
SHA256: 80512D37E68FA4E9186956ED46207CCF6B21B0E59F90BB00CF67669100A71373
File Size: 3.58 MB, 3584000 bytes
Show More
MD5: bd8a20ff9fc139a7cdee647faf995421
SHA1: 03558e18add1795b4e7f5e069e05c661b8e4abbb
SHA256: 294E74EFA59A3208667C2D75B7D140A9B10C752145A6DB0B46A88BA6AF515F42
File Size: 5.01 MB, 5009408 bytes
MD5: 43f8d94ed6e91e96f3fe37920efeaccf
SHA1: 58acce2660f0f2cc2985d94c35b6dfe216611a73
SHA256: 9489EE7030CF25892CC3839F7885D258574D35FDE26D02060A99F8E63392195A
File Size: 434.18 KB, 434176 bytes
MD5: 713e4ea4c62f7d818b4748e402c7549c
SHA1: 73aab38080e5ff41e5fb06cc465ab3876cfe2f55
SHA256: 2167F45244FB4C49E74224722607BAAC8595CA998E26787CCD17CDDD90DA5095
File Size: 5.29 MB, 5292032 bytes
MD5: cb115e7ba22ade4e78d7999f23a28980
SHA1: a7cd27360c7fc895c784ae1e4dc4f6338047faab
SHA256: C51270374774A86B4F2077BC09AAE2842AF373D6AFBB27DABB89070BF318D3DB
File Size: 1.03 MB, 1032192 bytes
MD5: b1c59d2686990ee55ac151b12cddd313
SHA1: 5cc22da9216dd0ebce10f49f80064694adc7cea6
SHA256: 381D561DA171B0E0C12230FC73484C457752B138FE905CAD1F7FF7358D1A17C5
File Size: 53.72 KB, 53720 bytes
MD5: 433702cba06f8e73ca5bfdf9a0b31c37
SHA1: da002d2f4a37dd5fd844c230894115751db952ba
SHA256: C5D8F7F16D4E7F299E3CC83CE09FE74A90DDA3AC1B81F05C89B0A62F671218AD
File Size: 3.39 MB, 3385344 bytes
MD5: 88ba1c61c3c5e6d360ecf58401e0e927
SHA1: 7cc3f2025baf10ed118969f9578f849054bcbe6d
SHA256: 3176A22C2562BF2D088D5593CCAF5E6DAD17C1FDD72C4A2E5D2EF73252DB1F51
File Size: 6.99 MB, 6989728 bytes
MD5: 14132af42c5d3b2f93ef3b48307e34a8
SHA1: b292526d932ea66f957dba9bb0c06a44fedbd694
SHA256: FA3C62E60159B47CAC7E45D8C6AADFD224CD9BE3521F7D45739FA2FF78FD6F3F
File Size: 350.21 KB, 350208 bytes
MD5: 50e991a45f81a75255c26a1348225ba7
SHA1: 3a4f3ceb2c2d05cf8f1e641ccac3b3a6752610f2
SHA256: 5000A95AB96B05DD38E579DE5A24DD45E18B5D4EF539FD3B2CF424A892998ADC
File Size: 8.39 MB, 8388608 bytes
MD5: f9a60744e5960d35cdc6b71b8ba9776e
SHA1: 11cd6264e05289e7b169343ce8d08663bb9ded95
SHA256: C134E156739FB18D9BB54207F407B2AB078D061F9CAEDD3BDA68AC3EF0BAD64F
File Size: 4.94 MB, 4943872 bytes
MD5: fcf743b9e404ad16defc41a8f2a4a40e
SHA1: 055926a15358dd48ab0d60e2c2a4d33c53271df1
SHA256: 1E0003455A17E6E126E9E963E48F95CDE14538E9B5115355F814E8DCEAA6E3D8
File Size: 3.36 MB, 3359232 bytes
MD5: b16c927fffc2726c59d03ce281b3acc4
SHA1: f496a4553fba90d77bccf68b700955fab833a952
SHA256: AA095691F52B1EB57B3BDEF5F5D56A3F6E2C4D3CB0C92CF4297A05828B94B052
File Size: 909.31 KB, 909312 bytes
MD5: f722c9f4c2aeb40b31b922b2ad1b3cb6
SHA1: f56212b5e8c189b86e02e7064e3ea1a24c2d31ed
SHA256: 3C401BF822584F26C6C76E428F475523953D34FD634B33BC3D095855F528AEFE
File Size: 5.53 MB, 5528576 bytes
MD5: c87f4a488bd8a07e16c98b6eecdf0250
SHA1: 8e05b337cc778907e4c87bb388b66f71c91e6be9
SHA256: 1A2E9CF153D296A379C9AB0B34BBB7423FBCB67096CCC4A1E69BFB870A6AE3F7
File Size: 1.87 MB, 1872351 bytes
MD5: 9649552a4ed12e218e27c9d70ffec9b0
SHA1: 6d3ebbffc08261869ed513018dbd1b122980c7b1
SHA256: 54DA85CDC6EDC0A1971AB5F37E823CFE376759D9EC77B6434F5B496553DBC01A
File Size: 4.03 MB, 4025360 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Comments
  • 1.0.0
  • Copyright (C) 2014 - 2016 Yamato Ryou Inc.
  • LaTaleLauncher
  • PCB抄板软件 HXPCB 是深圳专心科技自主开发的一款它集现有的EAD软件的优点,去除不常用命令。功能强大,简单易用。
  • QQ:8057867
  • Windows/Office激活工具V3
  • Windows应用程序
  • Windows超级管理器
  • zysys
  • 北京深思洛克数据保护中心
Show More
  • 本程序使用易语言编写(http://www.eyuyan.com)
  • 简易浏览器
  • 米哈库洛代理转向
  • 阿嘉 www.443w.com
Company Name
  • Alec
  • Octopus Studio
  • QQ:8057867
  • TomyJan
  • Yamato Ryou Inc.
  • 安静739132042
  • 清扬小新
  • 科利特尔Colithel
  • 阿嘉 www.443w.com
File Description
  • 1.0.0
  • LaTaleLauncher
  • PCB设计
  • QQ:8057867
  • SETUP 基础类驱动应用程序
  • trafficxia_jicheng
  • Windows/Office激活工具V3
  • Windows应用程序
  • Windows超级管理器
  • zysys
Show More
  • 下载VX视频号的小工具
  • 易语言程序
  • 程序包验证
  • 简单自解压程序
  • 简易浏览器
  • 米哈库洛代理转向
  • 系统资源程序
File Version
  • 9.5.1.0
  • 5.3.0.0
  • 3.2.0.0
  • 2.2.0.0
  • 1.99.20.7
  • 1.1.0.0
  • 1.0.0.48
  • 1.0.0.0
Legal Copyright
  • Alec 版权所有
  • Copyright(C) 2013-2025 版权所有
  • Copyright (C) 2014 - 2016 Yamato Ryou Inc.
  • Copyright (C) TomyJan All Rights Reserved.
  • Octopus Studio
  • QQ:8057867
  • 作者版权所有 请尊重并使用正版
  • 安静739132042
  • 清扬小新 版权所有
  • 版权所有(C) 阿嘉 免责条款: 本软件版权人申明不对本软件产品的安装、使用提供任何明示的和隐含的保证。不对软件使用中所遇到的任何理论上的或实际上的损失承担责任。 更多信息请访问:http://www.443w.com 联系作者: cctvw0m1@126.com QQ: 1006018660
Show More
  • 科利特尔团队 刘镔汉作品
  • 简易浏览器
Product Name
  • HXPCB
  • LaTaleLauncher
  • NBA 2K12 Fantasy Genius
  • RVC变声器
  • SenseIV动态库
  • trafficxia
  • Windows/Office激活工具V3
  • Windows应用程序
  • Windows超级管理器
  • zysys
Show More
  • 小白点视频号工具
  • 旅客版托盘图标修复
  • 植物大战僵尸CL版专用修改器
  • 程序包验证
  • 简单自解压程序
  • 简易浏览器
  • 米哈库洛代理转向
  • 系统资源程序
Product Version
  • 9.5.1.0
  • 5.3.0.0
  • 3.2.0.0
  • 2.2.0.0
  • 1.99.20.7
  • 1.1.0.0
  • 1.0.0.48
  • 1.0.0.0

Digital Signatures

Signer Root Status
Keroro Software LLC DigiCert Global G3 Code Signing ECC SHA384 2021 CA1 Self Signed
TomyWeb TomyWeb Self Signed
Yamato Ryou (代码或文件签名) Yamato Ryou (代码或文件签名) Self Signed

File Traits

  • .adata
  • .aspack
  • .UPX
  • 2+ executable sections
  • ASPack v2.12
  • big overlay
  • HighEntropy
  • Installer Version
  • MPRESS
  • MPRESS Win32
Show More
  • Native MPRESS x86
  • No Version Info
  • packed
  • PEC2
  • PECompact v2.20
  • WinZip SFX
  • WriteProcessMemory
  • x86
  • ZIP (In Overlay)
  • ZIPinO

Block Information

Total Blocks: 2,450
Potentially Malicious Blocks: 706
Whitelisted Blocks: 1,580
Unknown Blocks: 164

Visual Map

? x 0 x x x ? ? x ? x x 0 ? 0 0 x x x 0 ? ? x x x x x ? 0 ? x x ? ? x 0 x 0 x ? x 0 x 0 x 0 x 0 x x x x x ? x x x x x x x x x x x x 0 x ? x x 0 0 ? ? x ? ? ? 0 x 0 ? ? ? 0 0 ? ? x x x x x ? x x ? ? ? ? ? ? x ? ? x ? x x x x x x x x ? x ? ? ? ? 0 x x x ? ? x x x ? ? 0 ? ? 0 ? ? ? ? ? x ? x x x x x x x x x x x x x x x 0 0 x x 0 x x x x x 0 x x 0 x x x x x x 0 x x x x x x x 0 ? ? x x x 0 ? x x x x ? x x x ? x x x x x ? 0 x ? x ? x x x x ? x ? ? ? x x x x 0 ? ? ? x ? ? x x x x x x x ? ? 0 ? 0 x x x x ? x 0 ? x x ? ? 0 x x x x x x x x x x x x x ? ? x ? x x ? x ? x x x x x x x x x x x x x x x x x x x ? ? x x x x x x x x x x x x x ? x x x x x x x x x ? x x x x x x x x x x x x x x x x x x ? x x x ? x x x x x x x x x x ? x x x ? ? x x x x x ? x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x ? x x x x 0 ? x x x x x x x x ? x x x x x x x x 0 x ? ? ? ? x x x x x x x x ? x x x x x x x x ? x x x x x x x x x x ? x ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? x x ? ? x ? ? x x x x x x x x x x x x x x x x ? x ? x x x x x x x x x x ? ? ? x ? ? ? ? ? ? ? ? ? x x x x x x x x x x x x x 0 x 0 x x 0 0 0 x x x x x x 0 x x 0 x x x x x x x x x x x 0 0 x x 0 x x x x x 0 0 x 0 0 0 x 0 x 0 x 0 x 0 0 x x x x x x x x x x x 0 x x x x x x x x 0 x x 0 x x x 0 x x x x 0 x x x x 0 x x x x x x x x x x x x x 0 x x x x x 0 x x x x x 0 0 x 0 0 x 0 x x 0 0 x x x 0 0 0 0 x 0 0 x x x x x x 0 0 x 0 0 x 0 x x x x 0 x x x x x x 0 x 0 x x x x x x x x x x x x x 0 x x x x x x 0 0 x x 0 x x 0 0 0 0 x x x x 0 0 0 x 0 x x x x x x x x x x x x x x x x x x x 0 x 0 0 x x 0 x 0 x 0 0 0 x x x x x x 0 0 x x x x x x 0 0 0 x 0 0 x x x x x x x 0 x x 0 x x x x 0 x x 0 x x x x 0 x x 0 x 0 x 0 0 0 x 0 x x x 0 0 0 x x x x x x x x x x x x x x x x 0 0 0 x x 0 x x 0 x x 0 0 x x 0 0 0 x 0 0 x x 0 0 x x 0 0 x 0 0 0 x x 0 0 0 x x 0 x 0 0 x x x 0 x 0 0 x x 0 x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x x x 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 1 0 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 0 1 0 0 2 3 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bitcoinminer.FD
  • CoinMiner.BB
  • Emotet.AAJ
  • Emotet.AAL
  • FlyStudio.CA
Show More
  • Kryptik.FHE
  • Tofsee.BP
  • Trojan.Downloader.Gen.CG
  • Trojan.Downloader.Gen.DO
  • Trojan.Downloader.Gen.EY
  • Trojan.Downloader.Gen.HL
  • Upatre.WIA

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\e_n60005\eapi.fne Generic Write,Read Attributes
c:\users\user\appdata\local\temp\e_n60005\ethread.fne Generic Write,Read Attributes
c:\users\user\appdata\local\temp\e_n60005\iext.fnr Generic Write,Read Attributes
c:\users\user\appdata\local\temp\e_n60005\internet.fne Generic Write,Read Attributes
c:\users\user\appdata\local\temp\e_n60005\krnln.fnr Generic Write,Read Attributes
c:\users\user\appdata\local\temp\e_n60005\ogrelib.fnr Generic Write,Read Attributes
c:\users\user\appdata\local\temp\e_n60005\regex.fnr Generic Write,Read Attributes
c:\users\user\appdata\local\temp\e_n60005\shell.fne Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\e_n60005\spec.fne Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\systemcertificates\root\certificates\be36a4562fb2ee05dbb3d32323adf445084ed656::blob \Ѐ볝蚽㾜ࠛ컯퇄춈ᔻᰘ兘槹镹⍋ .Thawte Timestamping CA  ਰࠆثԁ܅ࠃ㚾嚤눯׮돛⏓괣䗴丈囖晿煺硩騠ᑑ莝⃚ꗨ뺘芄ﺎ炮ᔑ㔁뉶 ʥ RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • SetWindowsHookEx
Process Manipulation Evasion
  • ReadProcessMemory