Threat Database Trojans Trojan.MSIL.Bladabindi.A

Trojan.MSIL.Bladabindi.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,201
Threat Level: 80 % (High)
Infected Computers: 2,345
First Seen: January 3, 2013
Last Seen: April 30, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Bladabindi.A on your system indicates a potential security threat. Trojans are a type of malware that can cause significant harm to your computer and compromise your personal data. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Trojan.MSIL.Bladabindi.A?

Trojan.MSIL.Bladabindi.A is a type of Trojan horse malware that can infect your system without your knowledge or consent. The name itself does not provide specific information about the malware family, but it is clear that it is a malicious program designed to cause harm. Trojans can be used to steal sensitive information, install additional malware, or provide unauthorized access to your system.

How Trojan.MSIL.Bladabindi.A Operates

Trojans like Trojan.MSIL.Bladabindi.A typically operate by exploiting vulnerabilities in your system or deceiving you into installing them. They can be disguised as legitimate software or attached to seemingly harmless files. Once installed, the Trojan can connect to a command and control server to receive instructions from its creators, allowing them to control your system remotely. This can lead to a range of malicious activities, including data theft, ransomware attacks, or the installation of additional malware.

Symptoms of Infection

Identifying a Trojan infection can be challenging, as these malware programs are designed to operate stealthily. However, there are several symptoms that may indicate the presence of Trojan.MSIL.Bladabindi.A or similar malware on your system. These include unexpected changes to your system settings, unusual network activity, slow system performance, and the appearance of unfamiliar programs or files. If you suspect that your system has been infected, it is crucial to take immediate action to remove the threat.

How to Remove Trojan.MSIL.Bladabindi.A

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. This can help identify and remove the Trojan and any associated malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or settings that the Trojan may have installed.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed. It is also a good idea to scan your system regularly to detect and remove any future threats.

Conclusion

The removal of Trojan.MSIL.Bladabindi.A requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above and maintaining good security practices, such as keeping your software up to date and avoiding suspicious downloads, you can help protect your system from future infections. Remember, prevention is key, and staying informed about the latest malware threats is essential for maintaining the security and integrity of your computer system.

Analysis Report

General information

Family Name: Trojan.MSIL.Bladabindi.A
Signature status: No Signature

Known Samples

MD5: 22c5be8c1c5be0029fd1979d4032e177
SHA1: 476a6ee5ed5b6174570173ab21b21be836abe0b6
SHA256: 4ED736782515078D2C602AE701F7B329033E5E84CFD70EB38C088100611F5332
File Size: 129.54 KB, 129536 bytes
MD5: 43908399edcbc99d38ca54e0eb8de95b
SHA1: 2275457fb935e499e19b5ee6576dc1ab04a4fc0d
SHA256: A8048D5CC6DCC5B08840F0BFCD8F8C34CE109E12AA57273C5B8C623039B1635A
File Size: 35.33 KB, 35328 bytes
MD5: 279d3ce8fc2319246ecb018e7a3a577d
SHA1: 0c2b1e53b8ee0705dd82550cdf4962de0ca00dfe
SHA256: 3B425C9DE22651630BC96BD8D0D796FCF31F9B3764B99D11347EDFFC9CA04E30
File Size: 24.06 KB, 24064 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • .NET
  • HighEntropy
  • NewLateBinding
  • No Version Info
  • ntdll
  • x86

Block Information

Total Blocks: 28
Potentially Malicious Blocks: 25
Whitelisted Blocks: 3
Unknown Blocks: 0

Visual Map

x x x x x x 0 0 x x x x x x x x x x x x x x x 0 x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Bladabindi.A
  • MSIL.FakeMS.OA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\windows explore.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\csc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\204b410be8c12856e39ff90b80a8b98b.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\204b410be8c12856e39ff90b80a8b98b.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\caff161a211c2a1f5ea5faf3e9c3e6ab.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\caff161a211c2a1f5ea5faf3e9c3e6ab.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\windows update.exe Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU::di ! RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��$ xy kP~�ރ ������^ ۴�}��Vs}5kP~5��1������d B F e�'��1���h�n�} e�� e�� RegNtPreCreateKey
Show More
HKCU::di ! RegNtPreCreateKey
HKCU\environment::see_mask_nozonechecks 1 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::204b410be8c12856e39ff90b80a8b98b "C:\Users\Qyvezehb\windows update.exe" .. RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xy�ރ ��^��zeePVs}"kP~"��1>��ee�����1��fe��ise��r��se��ue��ve��{e�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ೉跰啧ǜ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::caff161a211c2a1f5ea5faf3e9c3e6ab "C:\Users\Lnwawvdl\AppData\Local\Temp\Windows Explore.exe" .. RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 u= xy�ރ��^eeEVs} kP~ ��1 ��ee�� ��1 ��fe��i(e��rP�ve�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 肍⸊挄ǜ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::01223f26fbc84302a1081c8cd77e1769 "C:\Users\Qlyswydq\AppData\Roaming\csc.exe" .. RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiDrawStream
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetEntry
  • win32u.dll!NtGdiGetFontData
  • win32u.dll!NtGdiGetGlyphIndicesW
  • win32u.dll!NtGdiGetOutlineTextMetricsInternalW
  • win32u.dll!NtGdiGetRandomRgn
  • win32u.dll!NtGdiGetRealizationInfo
  • win32u.dll!NtGdiGetTextFaceW
  • win32u.dll!NtGdiGetTextMetricsW
  • win32u.dll!NtGdiGetWidthTable
  • win32u.dll!NtGdiHfontCreate
  • win32u.dll!NtGdiIntersectClipRect
  • win32u.dll!NtGdiQueryFontAssocInfo
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap

65 additional items are not displayed above.

Network Winsock2
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Service Control
  • OpenSCManager
  • OpenService
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Terminate
  • TerminateProcess
Keyboard Access
  • GetAsyncKeyState
  • GetKeyState
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock
  • closesocket
  • setsockopt

Shell Command Execution

(NULL) C:\Users\Qyvezehb\windows update.exe
netsh firewall add allowedprogram "C:\Users\Qyvezehb\windows update.exe" "windows update.exe" ENABLE
(NULL) C:\Users\Lnwawvdl\AppData\Local\Temp\Windows Explore.exe
netsh firewall add allowedprogram "C:\Users\Lnwawvdl\AppData\Local\Temp\Windows Explore.exe" "Windows Explore.exe" ENABLE
(NULL) C:\Users\Qlyswydq\AppData\Roaming\csc.exe
Show More
netsh firewall add allowedprogram "C:\Users\Qlyswydq\AppData\Roaming\csc.exe" "csc.exe" ENABLE

Related Posts

Trending

Most Viewed

Loading...