Threat Database Trojans Trojan.Renamer.CA

Trojan.Renamer.CA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,693
Threat Level: 80 % (High)
Infected Computers: 4
First Seen: January 19, 2011
Last Seen: September 12, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Renamer.CA
Signature status: No Signature

Known Samples

MD5: 3970a66efc8390a66e01b055ab986252
SHA1: a2a3f447a8a28f02e75032f4bd5b70a609d838aa
SHA256: ACE6B647C42A05A411961CCB963E8683767B7F31195504582A83509476E2C30B
File Size: 835.58 KB, 835584 bytes
MD5: d5e0cb483d66315224e206eae9f6df57
SHA1: 108088c4e4cad0919edb26c91fd68e74d2b12ca6
SHA256: F3496901190EB98F2C6DC16E88016E6D663439FB6C3363139A317DB1622521E5
File Size: 835.58 KB, 835584 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • No Version Info
  • VirtualQueryEx
  • x86

Block Information

Total Blocks: 2,659
Potentially Malicious Blocks: 21
Whitelisted Blocks: 2,638
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Qhost.MA

Files Modified

File Attributes
c:\autorun.inf Synchronize,Write Attributes
c:\autorun.inf Synchronize,Write Data
c:\hold.inf Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\paint Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\paint Synchronize,Write Attributes
c:\program files\common files\microsoft shared\ink\en-us\inputpersonalization.exe.mui Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\en-us\mip.exe.mui Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\en-us\shapecollector.exe.mui Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\en-us\tabtip.exe.mui Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\en-us\vinputpersonalization.exe.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\program files\common files\microsoft shared\ink\en-us\vinputpersonalization.exe.mui Synchronize,Write Attributes
c:\program files\common files\microsoft shared\ink\en-us\vinputpersonalization.exe.mui Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\en-us\vmip.exe.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\en-us\vmip.exe.mui Synchronize,Write Attributes
c:\program files\common files\microsoft shared\ink\en-us\vmip.exe.mui Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\en-us\vshapecollector.exe.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\en-us\vshapecollector.exe.mui Synchronize,Write Attributes
c:\program files\common files\microsoft shared\ink\en-us\vshapecollector.exe.mui Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\en-us\vtabtip.exe.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\en-us\vtabtip.exe.mui Synchronize,Write Attributes
c:\program files\common files\microsoft shared\ink\en-us\vtabtip.exe.mui Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\inputpersonalization.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\mip.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\mip.exe Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\rcx51a6.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\rcx5243.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\rcx52e1.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\rcx64d5.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\shapecollector.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\shapecollector.exe Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\tabtip.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\tabtip.exe Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\vinputpersonalization.exe Synchronize,Write Attributes
c:\program files\common files\microsoft shared\ink\vinputpersonalization.exe Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\vinputpersonalization.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\vmip.exe Synchronize,Write Attributes
c:\program files\common files\microsoft shared\ink\vmip.exe Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\vmip.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\vshapecollector.exe Synchronize,Write Attributes
c:\program files\common files\microsoft shared\ink\vshapecollector.exe Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\vshapecollector.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\ink\vtabtip.exe Synchronize,Write Attributes
c:\program files\common files\microsoft shared\ink\vtabtip.exe Synchronize,Write Data
c:\program files\common files\microsoft shared\ink\vtabtip.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\msinfo\en-us\msinfo32.exe.mui Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\msinfo\en-us\vmsinfo32.exe.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\msinfo\en-us\vmsinfo32.exe.mui Synchronize,Write Attributes
c:\program files\common files\microsoft shared\msinfo\en-us\vmsinfo32.exe.mui Synchronize,Write Data
c:\program files\common files\microsoft shared\msinfo\msinfo32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\msinfo\msinfo32.exe Synchronize,Write Data
c:\program files\common files\microsoft shared\msinfo\rcx55c0.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\common files\microsoft shared\msinfo\vmsinfo32.exe Synchronize,Write Attributes
c:\program files\common files\microsoft shared\msinfo\vmsinfo32.exe Synchronize,Write Data
c:\program files\common files\microsoft shared\msinfo\vmsinfo32.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\cuassistant\culauncher.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\cuassistant\vculauncher.exe Synchronize,Write Attributes
c:\program files\cuassistant\vculauncher.exe Synchronize,Write Data
c:\program files\cuassistant\vculauncher.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\en-us\ieinstal.exe.mui Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\en-us\iexplore.exe.mui Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\en-us\vieinstal.exe.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\en-us\vieinstal.exe.mui Synchronize,Write Attributes
c:\program files\internet explorer\en-us\vieinstal.exe.mui Synchronize,Write Data
c:\program files\internet explorer\en-us\viexplore.exe.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\en-us\viexplore.exe.mui Synchronize,Write Attributes
c:\program files\internet explorer\en-us\viexplore.exe.mui Synchronize,Write Data
c:\program files\internet explorer\extexport.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\iediagcmd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\iediagcmd.exe Synchronize,Write Data
c:\program files\internet explorer\ieinstal.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\ieinstal.exe Synchronize,Write Data
c:\program files\internet explorer\ielowutil.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\ielowutil.exe Synchronize,Write Data
c:\program files\internet explorer\iexplore.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\iexplore.exe Synchronize,Write Data
c:\program files\internet explorer\rcx5861.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\rcx590e.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\rcx59ab.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\rcx5a39.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\vextexport.exe Synchronize,Write Attributes
c:\program files\internet explorer\vextexport.exe Synchronize,Write Data
c:\program files\internet explorer\vextexport.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\viediagcmd.exe Synchronize,Write Attributes
c:\program files\internet explorer\viediagcmd.exe Synchronize,Write Data
c:\program files\internet explorer\viediagcmd.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\vieinstal.exe Synchronize,Write Attributes
c:\program files\internet explorer\vieinstal.exe Synchronize,Write Data
c:\program files\internet explorer\vieinstal.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\vielowutil.exe Synchronize,Write Attributes
c:\program files\internet explorer\vielowutil.exe Synchronize,Write Data
c:\program files\internet explorer\vielowutil.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\internet explorer\viexplore.exe Synchronize,Write Attributes
c:\program files\internet explorer\viexplore.exe Synchronize,Write Data
c:\program files\internet explorer\viexplore.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\microsoft update health tools\expediteupdater.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\microsoft update health tools\uhssvc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\microsoft update health tools\vexpediteupdater.exe Synchronize,Write Attributes
c:\program files\microsoft update health tools\vexpediteupdater.exe Synchronize,Write Data
c:\program files\microsoft update health tools\vexpediteupdater.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\microsoft update health tools\vuhssvc.exe Synchronize,Write Attributes
c:\program files\microsoft update health tools\vuhssvc.exe Synchronize,Write Data
c:\program files\microsoft update health tools\vuhssvc.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\rempl\sedlauncher.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\rempl\vsedlauncher.exe Synchronize,Write Attributes
c:\program files\rempl\vsedlauncher.exe Synchronize,Write Data
c:\program files\rempl\vsedlauncher.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows defender\configsecuritypolicy.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows defender\mpcmdrun.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows defender\mpcmdrun.exe Synchronize,Write Data
c:\program files\windows defender\msmpeng.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows defender\nissrv.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows defender\rcx5eae.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows defender\vconfigsecuritypolicy.exe Synchronize,Write Attributes
c:\program files\windows defender\vconfigsecuritypolicy.exe Synchronize,Write Data
c:\program files\windows defender\vconfigsecuritypolicy.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows defender\vmpcmdrun.exe Synchronize,Write Attributes
c:\program files\windows defender\vmpcmdrun.exe Synchronize,Write Data
c:\program files\windows defender\vmpcmdrun.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows defender\vmsmpeng.exe Synchronize,Write Attributes
c:\program files\windows defender\vmsmpeng.exe Synchronize,Write Data
c:\program files\windows defender\vmsmpeng.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\windows defender\vnissrv.exe Synchronize,Write Attributes
c:\program files\windows defender\vnissrv.exe Synchronize,Write Data
c:\users\user\appdata\roaming\paint.exe Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\run::paint.exe C:\Users\Emmhksqt\AppData\Roaming\Paint.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::paint.exe C:\Users\Uvwgpmtf\AppData\Roaming\Paint.exe RegNtPreCreateKey

Trending

Most Viewed

Loading...