Threat Database Trojans Trojan.Reconyc.FI

Trojan.Reconyc.FI

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,779
Threat Level: 80 % (High)
Infected Computers: 51
First Seen: December 12, 2025
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Reconyc.FI on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the integrity of your computer, allowing unauthorized access to your personal data and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Reconyc.FI?

Trojan.Reconyc.FI is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan" refers to the malware's ability to deceive users into installing it, often by masquerading as a harmless or useful application. Once installed, Trojan.Reconyc.FI can cause significant harm to your system and data.

How Trojan.Reconyc.FI Operates

Like other Trojans, Trojan.Reconyc.FI operates by exploiting vulnerabilities in your system's security or by tricking users into installing it. It can spread through various means, including infected software downloads, suspicious email attachments, or compromised websites. Once inside your system, the malware can establish a backdoor, allowing remote access to your computer. This can lead to a range of malicious activities, including data theft, keystroke logging, and the installation of additional malware.

Symptoms of Infection

Identifying the symptoms of a Trojan.Reconyc.FI infection can be challenging, as it often runs in the background without visible signs. However, some common indicators of a potential infection include slow system performance, unexpected pop-ups or ads, and unfamiliar programs or icons on your desktop. You may also notice that your browser homepage has changed or that you are being redirected to suspicious websites. If you suspect that your system is infected, it is crucial to take immediate action to remove the malware.

How to Remove Trojan.Reconyc.FI

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will enable you to download and install removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. This will help identify and remove all instances of the malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time of the infection. Be cautious when removing programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This will help remove any malicious extensions or settings that the malware may have installed.
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed. It is also a good idea to scan your system regularly to prevent future infections.

Conclusion

Removing Trojan.Reconyc.FI from your system requires careful attention to detail and a thorough understanding of the malware's characteristics. By following the steps outlined above and maintaining good cybersecurity practices, you can help protect your system and data from future threats. Remember to always be cautious when downloading software or clicking on links, and keep your operating system and security software up to date to prevent vulnerabilities from being exploited. If you are unsure about any aspect of the removal process, consider seeking the advice of a cybersecurity professional to ensure that your system is completely secure.

Analysis Report

General information

Family Name: Trojan.Reconyc.FI
Signature status: No Signature

Known Samples

MD5: e835db905a3b34740a00dc7f6b6e818d
SHA1: 575eb2a61e3c890d940befc7bae19bd509a44529
SHA256: 8CB15DE40809B7F0F80BFD46C2039C0A43437CC271ADBDB7466D9B27FC91D3B7
File Size: 3.11 MB, 3114064 bytes
MD5: 5da2f3517b2ba2d3051173ce73bdcae2
SHA1: 580c80f820ea6e86ff3acf32dd0907aa7a38a14e
SHA256: 38761F51AC8F0C7521FB9246FEB8A2DF354A9FF155A79335AEB0FDAA746BEC59
File Size: 3.09 MB, 3090136 bytes
MD5: 596c7b8f434772c04b5ff03b45dab8bd
SHA1: 2314d697fa2f6f48e8abadadcbddb4f1e55096ff
SHA256: 70E82387D256C7B1EBC8B63608849A58FFC589090AC34B2D7E03D2C0646FE9F8
File Size: 2.75 MB, 2750680 bytes
MD5: a42f7085426422ae2fcc4429570c1c6d
SHA1: 2401d7ecf3af2ecc83555a5c8a1bf2bb97f1840e
SHA256: 3F49813CB38EFCA4DD2B99643E34B873CE359AD389F8AEFBE49297CD9BEC5A8B
File Size: 2.89 MB, 2890968 bytes
MD5: b599749364795aafda710478a0bf44ca
SHA1: 9b85be250ec59b8a33cc9890f536edb139a013a7
SHA256: A61480ACF047378B2AE5B7DDB6C47ABD0456B34AAD01A745965302F74B429BF2
File Size: 9.09 MB, 9089600 bytes
Show More
MD5: 95fd4597925cc6571f1f93ba38bebaa7
SHA1: add956a3d5e87ff0a3bca2b60acdbeeafe9b41ff
SHA256: 890807DCE8DA336EF444F6054FBEE5885389C125ED59F52C1F49059AC746005B
File Size: 4.53 MB, 4532400 bytes
MD5: 53b3ac7a6dc818ad9ee9135c8b94f9ad
SHA1: 2af60076c3b710de95630154bf12236e767f6323
SHA256: 592A08A60B261501457B5C9B4769646900C1EF57054FFBBBD6B4CA0BAB55F344
File Size: 4.52 MB, 4519600 bytes
MD5: 476be98204efbbd7f34ef80e313bf7c6
SHA1: 1ee914425535fe1f9db93757e2dc4b74c633003f
SHA256: E7F643E2B4047E96A7DA74AA23EB2A82CC0D2EACFF27B16E4E72B3C9B7BE5107
File Size: 5.84 MB, 5844144 bytes
MD5: 0bf07078318ed07eb79a64cbe5e635c3
SHA1: e12950350d0d7de41d0c3c5e959d473c22e84055
SHA256: 80888C28E5D0E9B7FAB45B5B7970BA2648FD581107EF0FFF79F906212732CBD4
File Size: 8.92 MB, 8922944 bytes
MD5: 0c5191e81933b98ae584402a57082c6d
SHA1: 1fbc2e2f8f46eec1d2c083ba0e5cea30a3d75c97
SHA256: 3D83DC7FA4EF0B916D8CE30FCEE6969F3A51DF2E38A09BF9BEC93EE4D0E19DFB
File Size: 2.68 MB, 2677247 bytes
MD5: f5617974e5d6655102c3d47076efd3aa
SHA1: 757ae2fd8a9029830da2a9c237f404b29fe8a56a
SHA256: 49604C66C0F237E8A0A8C464CC448C8A7BCE59F5D6DE2A57653D08614B2CADA4
File Size: 7.92 MB, 7924736 bytes
MD5: 1f8b2dbb64a4bf6a93acb48b73f989d0
SHA1: ed480c9d3d0f97407ba6db21f72b1308eef3e74c
SHA256: C4BB5B4E33D0707A7F264417D96F5B2FF583667FC02D06444E0CE5B2E5BF2CBD
File Size: 8.68 MB, 8682496 bytes
MD5: 4b1de0172d97f4ea3c31ddb7af365908
SHA1: 4c0c1f5a1d2edbccb905adcd7ca9aadd457f6613
SHA256: 4843AB41538EA715D7B506E18968AA5339116AF0F35501AF9BF6E1945C4B1D6A
File Size: 2.54 MB, 2542080 bytes
MD5: f1df073b340d9f5475c71c318d2826c6
SHA1: 22c111a00d9104033bbdc6b4014af019a62a2d84
SHA256: 3718BD7D0CE766862ECB2EBD8F58FDE9E21EFB14E7B6E08ABF12DBCDED445CB1
File Size: 2.31 MB, 2308608 bytes
MD5: dc47466c854a7e76163ede4d5dea2464
SHA1: 4687b002353348c8e0c8a4c47a92b6bc357a9d41
SHA256: F222FE65B5D163A889DFBE9A0742F4759069E4C4A70849C69A82927E67F2CB7F
File Size: 2.79 MB, 2791487 bytes
MD5: 940327a75206101091bca24301b6ea0d
SHA1: ee492ab145b626dac816f844fd9c7c26f3944d5a
SHA256: 9ABE65AA916493764127601680A00D4F325B2F4BEFF7B0E4AE8F4603CCA35C32
File Size: 2.64 MB, 2642944 bytes
MD5: 19efa4da083749b747cdf16365fb08bb
SHA1: 52fce9fda4dcdc6ba822d7dbd9e5ca0ea1cd2b83
SHA256: 9800097744BBCDF81744DA1F3FFF9EC39E6A60D8BA2E2C70301DFCD172679980
File Size: 2.33 MB, 2330288 bytes
MD5: 41e171c3a92286786e62a99d05ccf209
SHA1: c35ac3594b127a5ea8db21e931dc2918f49d5cb7
SHA256: 6B9F67826C5FE1437B93C7CA9A8F5EC9D103E0E109706797A5F1465C7C1542C0
File Size: 3.24 MB, 3236359 bytes
MD5: 4696cc42b18ff0c7d4cab61a14499533
SHA1: acd94b415ac701037a862685bcf22b88ba6ce6f1
SHA256: DD995314388BFD1541FB219CDD66F4D66C9BDDC5D89B00EA581A96D112F0542F
File Size: 8.51 MB, 8506960 bytes
MD5: f5829f9057d29c08e44e72e1913ed9ff
SHA1: 45186b1bbf78ccdbbde45ab320065934949ac210
SHA256: F2EB7305C9BBA4BDE44284B424F582A1FCE7EF20112AF5224FE2128232EF7211
File Size: 2.59 MB, 2586624 bytes
MD5: 048ee806decb3274d169214bb499d55a
SHA1: 4177167fa843f167c212ec487ebba76eeac431d6
SHA256: A07DA51317EB3D14701339806B5F8C591D32BC238868C78290F3EC9B3FC31263
File Size: 2.32 MB, 2318336 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • aerospace
  • Evernote Corporation
  • everythingcomplications
  • irrigation
  • ourselvesconfidentiality
  • perspectivesproducers
  • politicians
  • sculptureintroduce
File Description Evernote
File Version
  • 10.159.4.20251022090921
  • 5.0.0.0
  • 1.0.0.0
Internal Name
  • aerospace
  • classicallitigation
  • executivejurisdiction
  • irrigation
  • knowledgecombination
  • numericalexaminationsaccepting
  • politicians
Legal Copyright
  • aerospace
  • astronomyreflected
  • Copyright © 2025 Evernote Corporation
  • difficultyscheduled
  • irrigation
  • politicians
  • preferencesupporting
  • proprietaryextraordinary
Original Filename
  • aerospace.exe
  • hardcover.exe
  • irrigation.exe
  • languages.exe
  • politicians.exe
  • recognized.exe
  • responses.exe
Product Name
  • administrativereliabilitycenturiescommonwealth
  • aerospace
  • demonstratescollectibles
  • Evernote
  • immigrationdepending
  • irrigation
  • politicians
  • restructuringanniversary
Product Version
  • 10.159.4
  • 1.0.0.0

Digital Signatures

Signer Root Status
*.dodo.com *.dodo.com Self Signed
*.texasdiagnosticradiology.com *.texasdiagnosticradiology.com Self Signed
*.us.pg.com *.us.pg.com Self Signed
Evernote Corporation Entrust Code Signing Root Certification Authority - CSBR1 Hash Mismatch
Evernote Corporation Entrust Code Signing Root Certification Authority - CSBR1 Hash Mismatch
Show More
glitch.com glitch.com Self Signed
www.hindustantimes.com www.hindustantimes.com Self Signed

File Traits

  • 2+ executable sections
  • big overlay
  • dll
  • golang
  • HighEntropy
  • No Version Info
  • x64

Block Information

Total Blocks: 2,751
Potentially Malicious Blocks: 469
Whitelisted Blocks: 2,276
Unknown Blocks: 6

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.BSA
  • Agent.JFJ
  • Agent.KFTA
  • Agent.KOFA
  • Agent.KTSD
Show More
  • Agent.KTSE
  • Agent.LPX
  • CobaltStrike.ZA
  • Coinminer.LO
  • Dropper.FF
  • Dropper.FFA
  • Dropper.JD
  • Filecoder.EYA
  • Filecoder.JFA
  • Gamehack.OFG
  • Kryptik.ERA
  • Kryptik.FRS
  • Kryptik.FRSA
  • Kryptik.FRSC
  • Kryptik.FSK
  • Kryptik.GFSC
  • Kryptik.IOB
  • Kryptik.IOC
  • Lumma.AU
  • Mikey.U
  • Quasar.BC
  • Quasar.LD
  • Quasar.SA
  • Quasar.SB
  • Reconyc.FH
  • Reconyc.FI
  • Reconyc.Q
  • ReverseShell.XF
  • Rozena.DDA
  • Rozena.ED
  • ShellcodeRunner.AYB
  • SmokeLoader.C
  • SmokeLoader.D
  • SmokeLoader.E
  • Trojan.Downloader.Gen.JS
  • Trojan.ReverseShell.Gen.AO
  • Trojan.ReverseShell.Gen.B
  • Trojan.ShellcodeRunner.Gen.AQ
  • Trojan.ShellcodeRunner.Gen.AR
  • Trojan.ShellcodeRunner.Gen.DP
  • Trojan.ShellcodeRunner.Gen.FC
  • Trojan.ShellcodeRunner.Gen.FZ
  • Trojan.ShellcodeRunner.Gen.KT
  • Trojan.ShellcodeRunner.Gen.ND

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Ol+� �v xy������!wz%:�(�1`1�1HO>3�@V�H[uJ��X�i��k`k�qrnJu�~�P��{�������b:����6��h �a �n��F��m�Ù�ͪ�t����$�8���`��o B1_`�V���P�����Q]���~��@K� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
Show More
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
User Data Access
  • GetComputerName
  • GetUserName
Network Wininet
  • HttpOpenRequest
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetReadFile
  • InternetSetOption
Network Winhttp
  • WinHttpOpen

Trending

Most Viewed

Loading...