CHARM.exe is part of CHARM and developed by AmeriTechnology Group, Inc. according to the CHARM.exe version information.
CHARM.exe's description is "Computer Health And Remote Monitoring software exclusively for AMTGI clients."
CHARM.exe is digitally signed by AmeriTechnology Group, Inc..
CHARM.exe is usually located in the 'c:\downloads\' folder.
Some of the anti-virus scanners at VirusTotal detected CHARM.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
The following is the available information on CHARM.exe:
Property | Value |
---|---|
Product name | CHARM |
Company name | AmeriTechnology Group, Inc. |
File description | Computer Health And Remote Monitoring software exclusively for AMTGI clients. |
Internal name | CHARM |
Original filename | CHARM.exe |
Comments | Client auditing, management and asset control software for AMTGI clients. |
Legal copyright | 2005-2018 |
Product version | 1.09.0781 |
File version | 1.09.0781 |
Here's a screenshot of the file properties when displayed by Windows Explorer:
Product name | CHARM |
Company name | AmeriTechnology Group, Inc. |
File description | Computer Health And Remote Monitorin.. |
Internal name | CHARM |
Original filename | CHARM.exe |
Comments | Client auditing, management and asse.. |
Legal copyright | 2005-2018 |
Product version | 1.09.0781 |
File version | 1.09.0781 |
CHARM.exe has a valid digital signature.
Property | Value |
---|---|
Signer name | AmeriTechnology Group, Inc. |
Certificate issuer name | Go Daddy Secure Certificate Authority - G2 |
Certificate serial number | 38074e531bc5ed42 |
25 of the 67 anti-virus programs at VirusTotal detected the CHARM.exe file. That's a 37% detection rate.
Scanner | Detection Name |
---|---|
AhnLab-V3 | Trojan/Win32.Injector.C2789003 |
Antiy-AVL | RiskWare[Monitor]/Win32.AMTGiMon |
Avast | Win32:Malware-gen |
AVG | Win32:Malware-gen |
Avira | TR/Dropper.Gen |
CAT-QuickHeal | Trojan.IGENERIC |
Comodo | Malware@#1tjczb9wupp5e |
Cylance | Unsafe |
Cyren | W32/Trojan.DNBF-1201 |
ESET-NOD32 | a variant of Win32/Monitor.AMTGiMon.B potentially unsafe |
F-Secure | Trojan.TR/Dropper.Gen |
Fortinet | Riskware/AMTGiMon |
GData | Win32.Trojan.Agent.GHEMOC |
K7AntiVirus | Unwanted-Program ( 0053fca61 ) |
K7GW | Unwanted-Program ( 0053fca61 ) |
MAX | malware (ai score=100) |
McAfee | RDN/Generic Dropper |
McAfee-GW-Edition | RDN/Generic Dropper |
Microsoft | PUA:Win32/Presenoker |
Rising | Dropper.Generic!8.35E (TFE:5:Ayo8HXzkj0P) |
SentinelOne | static engine - malicious |
Sophos | Mal/Generic-S |
TrendMicro | TROJ_GEN.R002C0PKG18 |
TrendMicro-HouseCall | TROJ_GEN.R002C0PKG18 |
Yandex | Riskware.AMTGiMon! |
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{ "file_created": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\Microsoft_CUCKPC.txt", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~DF585E38BBF11D94C5.TMP" ], "dll_loaded": [ "kernel32", "DNSAPI.dll", "kernel32.dll", "UxTheme.dll", "dwmapi.dll", "cryptsp.dll", "advapi32", "winhttp.dll", "CLBCatQ.DLL", "OLEAUT32.DLL", "SspiCli.dll", "comctl32", "SHLWAPI.dll", "CRYPTSP.dll", "credssp.dll", "VERSION.DLL", "OLEAUT32.dll", "C:\\Windows\\system32\\kernel32.dll", "RPCRT4.dll", "C:\\Windows\\System32\\wship6.dll", "SXS.DLL", "C:\\Windows\\system32\\mswsock.dll", "ADVAPI32.dll", "C:\\Windows\\System32\\wshtcpip.dll", "WS2_32.dll" ], "file_opened": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\Microsoft_CUCKPC.txt", "C:\\Windows\\System32\\en-US\\winhttp.dll.mui", "C:\\Windows\\SysWOW64\\wshom.ocx", "C:\\Windows\\SysWOW64\\stdole2.tlb", "C:\\Windows\\System32\\wbem\\wbemdisp.tlb" ], "regkey_opened": [ "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LsaExtensionConfig\\SspiCli", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\TreatAs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WINMGMTS\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msxml2.ServerXMLHTTP\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\Progid", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InprocHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InprocHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\0\\win32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocHandler32", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\0\\win32", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\System", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\SecurityProviders\\SaslProfiles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\\0", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\SecurityProviders", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\Progid", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\MS Sans Serif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\Tracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\Progid", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip6", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InprocHandler32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Help", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International", "HKEY_CURRENT_USER\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Scripting.FileSystemObject\\CLSID", "HKEY_CURRENT_USER\\winmgmts", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\409", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InprocHandler32", "HKEY_CURRENT_USER\\Scripting.FileSystemObject", "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Setup Migration\\Providers", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\\0\\win32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\VBA\\Monitors", "HKEY_CURRENT_USER\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\9", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\TreatAs", "HKEY_CURRENT_USER\\WScript.Network", "HKEY_CURRENT_USER\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\0", "HKEY_CURRENT_USER\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\HTML Help", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Winsock", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Scripting", "HKEY_CURRENT_USER\\MSXML2.ServerXMLHTTP", "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Parameters", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\9", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WScript.Network\\CLSID", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\409", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT\\UserEra", "HKEY_CURRENT_USER\\scripting.filesystemobject", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\SspiCache", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip6\\Parameters\\Winsock", "HKEY_CURRENT_USER\\TypeLib", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocServer32", "HKEY_CURRENT_USER\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\TreatAs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\0" ], "resolves_host": [ "charm.bizfxr.com" ], "file_written": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\Microsoft_CUCKPC.txt" ], "file_deleted": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\~DF585E38BBF11D94C5.TMP" ], "file_exists": [ "C:\\Windows\\System32\\C_936.NLS", "C:\\Users\\cuck\\AppData\\Local\\Temp\\Microsoft_CUCKPC.txt", "C:\\Windows\\System32\\C_932.NLS", "C:\\Windows\\System32\\.HLP", "C:\\Windows\\System32\\C_949.NLS", "C:\\Windows\\Help\\.HLP", "C:\\Windows\\System32\\C_950.NLS" ], "file_failed": [ "C:\\Windows\\WINHELP.INI" ], "wmi_query": [ "select Description from Win32_OperatingSystem", "Select * from Win32_OperatingSystem" ], "guid": [ "{016fe2ec-b2c8-45f8-b23b-39e53a75396b}", "{093ff999-1ea0-4079-9525-9614c3504b74}", "{172bddf8-ceea-11d1-8b05-00600806d9b6}", "{0000011a-0000-0000-c000-000000000046}", "{00000000-0000-0000-c000-000000000046}", "{4590f811-1d3a-11d0-891f-00aa004b2e24}", "{afba6b42-5692-48ea-8141-dc517dcf0ef1}", "{44aca674-e8fc-11d0-a07c-00c04fb68820}", "{275c23e2-3747-11d0-9fea-00aa003f8646}", "{cf4cc405-e2c5-4ddd-b3ce-5e7582d8c9fa}", "{d5f569d0-593b-101a-b569-08002b2dbf7a}", "{674b6698-ee92-11d0-ad71-00c04fd8fdff}", "{3bc15af2-736c-477e-9e51-238af8667dcc}", "{275c23e1-3747-11d0-9fea-00aa003f8646}", "{0d43fe01-f093-11cf-8940-00a0c9054228}", "{7c857801-7381-11cf-884d-00aa004b2e24}", "{8bc3f05e-d86b-11d0-a075-00c04fb68820}", "{2087c2f4-2cef-4953-a8ab-66779b670495}", "{f309ad18-d86a-11d0-a075-00c04fb68820}", "{dc12a687-737f-11cf-884d-00aa004b2e24}" ], "file_read": [ "C:\\Windows\\SysWOW64\\wshom.ocx", "C:\\Windows\\SysWOW64\\stdole2.tlb", "C:\\Windows\\System32\\wbem\\wbemdisp.tlb" ], "regkey_read": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\TokenSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\ProgID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WINMGMTS\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InProcServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\RegisteredOrganization", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AcceptLanguage", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureRoutine", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\Com+Enabled", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\SecurityProviders", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocServer32\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\ProgID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\Tracing\\Enabled", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InProcServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\949", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\932", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msxml2.ServerXMLHTTP\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WScript.Network\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureDll", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\Scripting\\Default Namespace", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\HTML Help\\.HLP", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\\0\\win32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InProcServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\0\\win32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Comment", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\DisableBranchCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InProcServer32\\InprocServer32", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\RpcId", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InProcServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MaxSockaddrLength", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\0\\win32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\ProgID\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Capabilities", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\950", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Scripting.FileSystemObject\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ShareCredsWithWinHttp", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\HelperDllName", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip6\\WinSock 2.0 Provider ID", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MinSockaddrLength", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\936", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\WinHttpSettings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InProcServer32\\InprocServer32", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Type", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\UseDelayedAcceptance" ] }
[ { "yara": [], "sha1": "c99f88b1f1170d6d5a4c78ced28c89dbc2d887cc", "name": "5431795a463d2eac_microsoft_cuckpc.txt", "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\Microsoft_CUCKPC.txt", "type": "ASCII text, with CRLF line terminators", "sha256": "5431795a463d2eacfc523c8bdff513db94a85fdcc15cefca6b1b33db1740567c", "urls": [], "crc32": "8E490CD9", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9424\/files\/5431795a463d2eac_microsoft_cuckpc.txt", "ssdeep": null, "size": 144, "sha512": "6068991233c380bbac92bd0a08938da844b8b98b06d859aac2b4686d61113e40d25399cf2e4f6f60f8e184e072dea4cba7fd88af09a969d63f9d7042607d4338", "pids": [ 2420 ], "md5": "208bbe0bfd9172beb00b2e9adb88dedb" }, { "yara": [], "sha1": "ce30977ae7b3f60bf189217caf4abf029b17ca4c", "name": "58c8e98f18c44df4_~DF585E38BBF11D94C5.TMP", "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\~DF585E38BBF11D94C5.TMP", "type": "Composite Document File V2 Document, Cannot read section info", "sha256": "58c8e98f18c44df4eff28bcf69f16ea2f8b3815fd1fb88e4d0a12bfc9cef442c", "urls": [], "crc32": "3BD519DA", "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9424\/files\/58c8e98f18c44df4_~DF585E38BBF11D94C5.TMP", "ssdeep": null, "size": 9216, "sha512": "529fb3365560bebf0bb46bb513195ec1689c506ba7f51dd35c8c99dfdc25efabcedd01627f1ea67b07a7736e9cff304c3a01b52b47a0231462bb516891ac94e4", "pids": [], "md5": "d8626e37db04ceb0a4904e07eadaabb2" } ]
[ { "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\042f6b30ca7a2666868197b002a92cce0b11908b24766c77a2111d014195c09c.bin", "process_name": "042f6b30ca7a2666868197b002a92cce0b11908b24766c77a2111d014195c09c.bin", "pid": 2420, "summary": { "file_created": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\Microsoft_CUCKPC.txt", "C:\\Users\\cuck\\AppData\\Local\\Temp\\~DF585E38BBF11D94C5.TMP" ], "dll_loaded": [ "kernel32", "DNSAPI.dll", "kernel32.dll", "UxTheme.dll", "dwmapi.dll", "cryptsp.dll", "advapi32", "winhttp.dll", "CLBCatQ.DLL", "OLEAUT32.DLL", "SspiCli.dll", "comctl32", "SHLWAPI.dll", "CRYPTSP.dll", "credssp.dll", "VERSION.DLL", "OLEAUT32.dll", "C:\\Windows\\system32\\kernel32.dll", "RPCRT4.dll", "C:\\Windows\\System32\\wship6.dll", "SXS.DLL", "C:\\Windows\\system32\\mswsock.dll", "ADVAPI32.dll", "C:\\Windows\\System32\\wshtcpip.dll", "WS2_32.dll" ], "file_opened": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\Microsoft_CUCKPC.txt", "C:\\Windows\\System32\\en-US\\winhttp.dll.mui", "C:\\Windows\\SysWOW64\\wshom.ocx", "C:\\Windows\\SysWOW64\\stdole2.tlb", "C:\\Windows\\System32\\wbem\\wbemdisp.tlb" ], "regkey_opened": [ "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LsaExtensionConfig\\SspiCli", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\TreatAs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WINMGMTS\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msxml2.ServerXMLHTTP\\CLSID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\Progid", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InprocHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InprocHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\0\\win32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocHandler32", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\0\\win32", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\System", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\SecurityProviders\\SaslProfiles", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\\0", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\SecurityProviders", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\Progid", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback\\MS Sans Serif", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\Tracing", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\Progid", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip6", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InprocHandler32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Help", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International", "HKEY_CURRENT_USER\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Scripting.FileSystemObject\\CLSID", "HKEY_CURRENT_USER\\winmgmts", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\409", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InprocHandler32", "HKEY_CURRENT_USER\\Scripting.FileSystemObject", "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Setup Migration\\Providers", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\\0\\win32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\VBA\\Monitors", "HKEY_CURRENT_USER\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\9", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\TreatAs", "HKEY_CURRENT_USER\\WScript.Network", "HKEY_CURRENT_USER\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\0", "HKEY_CURRENT_USER\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\HTML Help", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Winsock", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Scripting", "HKEY_CURRENT_USER\\MSXML2.ServerXMLHTTP", "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Winsock\\Parameters", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocHandler", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\9", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WScript.Network\\CLSID", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\409", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLEAUT\\UserEra", "HKEY_CURRENT_USER\\scripting.filesystemobject", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\SspiCache", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip6\\Parameters\\Winsock", "HKEY_CURRENT_USER\\TypeLib", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocServer32", "HKEY_CURRENT_USER\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.0", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\TreatAs", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\0" ], "resolves_host": [ "charm.bizfxr.com" ], "file_written": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\Microsoft_CUCKPC.txt" ], "file_deleted": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\~DF585E38BBF11D94C5.TMP" ], "file_exists": [ "C:\\Windows\\System32\\C_936.NLS", "C:\\Users\\cuck\\AppData\\Local\\Temp\\Microsoft_CUCKPC.txt", "C:\\Windows\\System32\\C_932.NLS", "C:\\Windows\\System32\\.HLP", "C:\\Windows\\System32\\C_949.NLS", "C:\\Windows\\Help\\.HLP", "C:\\Windows\\System32\\C_950.NLS" ], "file_failed": [ "C:\\Windows\\WINHELP.INI" ], "wmi_query": [ "select Description from Win32_OperatingSystem", "Select * from Win32_OperatingSystem" ], "guid": [ "{016fe2ec-b2c8-45f8-b23b-39e53a75396b}", "{093ff999-1ea0-4079-9525-9614c3504b74}", "{172bddf8-ceea-11d1-8b05-00600806d9b6}", "{0000011a-0000-0000-c000-000000000046}", "{00000000-0000-0000-c000-000000000046}", "{4590f811-1d3a-11d0-891f-00aa004b2e24}", "{afba6b42-5692-48ea-8141-dc517dcf0ef1}", "{44aca674-e8fc-11d0-a07c-00c04fb68820}", "{275c23e2-3747-11d0-9fea-00aa003f8646}", "{cf4cc405-e2c5-4ddd-b3ce-5e7582d8c9fa}", "{d5f569d0-593b-101a-b569-08002b2dbf7a}", "{674b6698-ee92-11d0-ad71-00c04fd8fdff}", "{3bc15af2-736c-477e-9e51-238af8667dcc}", "{275c23e1-3747-11d0-9fea-00aa003f8646}", "{0d43fe01-f093-11cf-8940-00a0c9054228}", "{7c857801-7381-11cf-884d-00aa004b2e24}", "{8bc3f05e-d86b-11d0-a075-00c04fb68820}", "{2087c2f4-2cef-4953-a8ab-66779b670495}", "{f309ad18-d86a-11d0-a075-00c04fb68820}", "{dc12a687-737f-11cf-884d-00aa004b2e24}" ], "file_read": [ "C:\\Windows\\SysWOW64\\wshom.ocx", "C:\\Windows\\SysWOW64\\stdole2.tlb", "C:\\Windows\\System32\\wbem\\wbemdisp.tlb" ], "regkey_read": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MaxSockaddrLength", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\TokenSize", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\ProgID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WINMGMTS\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InProcServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\RegisteredOrganization", "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AcceptLanguage", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureRoutine", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\Com+Enabled", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\SecurityProviders", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\MinSockaddrLength", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip\\WinSock 2.0 Provider ID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocServer32\\InprocServer32", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\ProgID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\Tracing\\Enabled", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InProcServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\949", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\932", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msxml2.ServerXMLHTTP\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WScript.Network\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\LsaExtensionConfig\\SspiCli\\CheckSignatureDll", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\Mapping", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Parameters\\Transports", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\Scripting\\Default Namespace", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\HTML Help\\.HLP", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\\0\\win32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Version", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InProcServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{565783C6-CB41-11D1-8B02-00600806D9B6}\\1.2\\0\\win32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Comment", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Name", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\UseDelayedAcceptance", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WinHttp\\DisableBranchCache", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InProcServer32\\InprocServer32", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\RpcId", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{093FF999-1EA0-4079-9525-9614C3504B74}\\InProcServer32\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MaxSockaddrLength", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\\1.0\\0\\win32\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\ProgID\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Capabilities", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\950", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Scripting.FileSystemObject\\CLSID\\(Default)", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ShareCredsWithWinHttp", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\HelperDllName", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\HelperDllName", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winsock\\Setup Migration\\Providers\\Tcpip6\\WinSock 2.0 Provider ID", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\MinSockaddrLength", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\InprocServer32\\ThreadingModel", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{0D43FE01-F093-11CF-8940-00A0C9054228}\\(Default)", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\936", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Winsock\\Mapping", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\WinHttpSettings", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}\\InProcServer32\\InprocServer32", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\SspiCache\\credssp.dll\\Type", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TCPIP6\\Parameters\\Winsock\\UseDelayedAcceptance" ] }, "first_seen": 1599634390.6875, "ppid": 1268 }, { "process_path": "C:\\Windows\\System32\\lsass.exe", "process_name": "lsass.exe", "pid": 476, "summary": {}, "first_seen": 1599634390.34375, "ppid": 376 } ]
[ { "markcount": 3, "families": [], "description": "Queries for the computername", "severity": 1, "marks": [ { "call": { "category": "misc", "status": 1, "stacktrace": [], "api": "GetComputerNameW", "return_value": 1, "arguments": { "computer_name": "CUCKPC" }, "time": 1599634390.8755, "tid": 2460, "flags": {} }, "pid": 2420, "type": "call", "cid": 311 }, { "call": { "category": "misc", "status": 1, "stacktrace": [], "api": "GetComputerNameW", "return_value": 1, "arguments": { "computer_name": "CUCKPC" }, "time": 1599634390.9375, "tid": 2460, "flags": {} }, "pid": 2420, "type": "call", "cid": 552 }, { "call": { "category": "misc", "status": 1, "stacktrace": [], "api": "GetComputerNameW", "return_value": 1, "arguments": { "computer_name": "CUCKPC" }, "time": 1599634390.9685, "tid": 2460, "flags": {} }, "pid": 2420, "type": "call", "cid": 779 } ], "references": [], "name": "antivm_queries_computername" }, { "markcount": 3, "families": [], "description": "One or more processes crashed", "severity": 1, "marks": [ { "call": { "category": "__notification__", "status": 1, "stacktrace": [], "raw": [ "stacktrace" ], "api": "__exception__", "return_value": 0, "arguments": { "stacktrace": "E\nb\nG\ne\nt\nH\na\nn\nd\nl\ne\nO\nf\nE\nx\ne\nc\nu\nt\ni\nn\ng\nP\nr\no\nj\ne\nc\nt\n+\n0\nx\n2\n2\nb\n3\n \nr\nt\nc\nP\na\nc\nk\nD\na\nt\ne\n-\n0\nx\nb\na\n9\n \nm\ns\nv\nb\nv\nm\n6\n0\n+\n0\nx\nd\n0\nd\nc\nf\n \n@\n \n0\nx\n7\n2\na\n1\n0\nd\nc\nf\n\n\nr\nt\nc\nD\no\nE\nv\ne\nn\nt\ns\n+\n0\nx\n1\n3\n1\n \n_\n_\nv\nb\na\nE\nr\nr\no\nr\n-\n0\nx\n6\n2\n6\n \nm\ns\nv\nb\nv\nm\n6\n0\n+\n0\nx\nc\ne\n2\n2\n8\n \n@\n \n0\nx\n7\n2\na\n0\ne\n2\n2\n8", "registers": { "esp": 1634108, "edi": 1634384, "eax": 1634108, "ebp": 1634188, "edx": 0, "ebx": 6726024, "esi": 1634384, "ecx": 2 }, "exception": { "instruction_r": "c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b", "symbol": "RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727", "instruction": "leave", "module": "KERNELBASE.dll", "exception_code": "0xc000008f", "offset": 46887, "address": "0x75dbb727" } }, "time": 1599634391.0155, "tid": 2460, "flags": {} }, "pid": 2420, "type": "call", "cid": 1060 }, { "call": { "category": "__notification__", "status": 1, "stacktrace": [], "raw": [ "stacktrace" ], "api": "__exception__", "return_value": 0, "arguments": { "stacktrace": "E\nb\nG\ne\nt\nH\na\nn\nd\nl\ne\nO\nf\nE\nx\ne\nc\nu\nt\ni\nn\ng\nP\nr\no\nj\ne\nc\nt\n+\n0\nx\n2\n2\nb\n3\n \nr\nt\nc\nP\na\nc\nk\nD\na\nt\ne\n-\n0\nx\nb\na\n9\n \nm\ns\nv\nb\nv\nm\n6\n0\n+\n0\nx\nd\n0\nd\nc\nf\n \n@\n \n0\nx\n7\n2\na\n1\n0\nd\nc\nf\n\n\nr\nt\nc\nD\no\nE\nv\ne\nn\nt\ns\n+\n0\nx\n1\n3\n1\n \n_\n_\nv\nb\na\nE\nr\nr\no\nr\n-\n0\nx\n6\n2\n6\n \nm\ns\nv\nb\nv\nm\n6\n0\n+\n0\nx\nc\ne\n2\n2\n8\n \n@\n \n0\nx\n7\n2\na\n0\ne\n2\n2\n8", "registers": { "esp": 1634044, "edi": 1634320, "eax": 1634044, "ebp": 1634124, "edx": 0, "ebx": 6726024, "esi": 1634320, "ecx": 2 }, "exception": { "instruction_r": "c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b", "symbol": "RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727", "instruction": "leave", "module": "KERNELBASE.dll", "exception_code": "0xc000008f", "offset": 46887, "address": "0x75dbb727" } }, "time": 1599634391.0155, "tid": 2460, "flags": {} }, "pid": 2420, "type": "call", "cid": 1062 }, { "call": { "category": "__notification__", "status": 1, "stacktrace": [], "raw": [ "stacktrace" ], "api": "__exception__", "return_value": 0, "arguments": { "stacktrace": "E\nb\nG\ne\nt\nH\na\nn\nd\nl\ne\nO\nf\nE\nx\ne\nc\nu\nt\ni\nn\ng\nP\nr\no\nj\ne\nc\nt\n+\n0\nx\n2\n2\nb\n3\n \nr\nt\nc\nP\na\nc\nk\nD\na\nt\ne\n-\n0\nx\nb\na\n9\n \nm\ns\nv\nb\nv\nm\n6\n0\n+\n0\nx\nd\n0\nd\nc\nf\n \n@\n \n0\nx\n7\n2\na\n1\n0\nd\nc\nf\n\n\nr\nt\nc\nD\no\nE\nv\ne\nn\nt\ns\n+\n0\nx\n1\n3\n1\n \n_\n_\nv\nb\na\nE\nr\nr\no\nr\n-\n0\nx\n6\n2\n6\n \nm\ns\nv\nb\nv\nm\n6\n0\n+\n0\nx\nc\ne\n2\n2\n8\n \n@\n \n0\nx\n7\n2\na\n0\ne\n2\n2\n8", "registers": { "esp": 1634628, "edi": 6726024, "eax": 1634628, "ebp": 1634708, "edx": 0, "ebx": 6726024, "esi": 6726024, "ecx": 2 }, "exception": { "instruction_r": "c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b", "symbol": "RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727", "instruction": "leave", "module": "KERNELBASE.dll", "exception_code": "0xc000008f", "offset": 46887, "address": "0x75dbb727" } }, "time": 1599634391.0465, "tid": 2460, "flags": {} }, "pid": 2420, "type": "call", "cid": 1273 } ], "references": [], "name": "raises_exception" }, { "markcount": 2, "families": [], "description": "Executes one or more WMI queries", "severity": 2, "marks": [ { "category": "wmi", "ioc": "select Description from Win32_OperatingSystem", "type": "ioc", "description": null }, { "category": "wmi", "ioc": "Select * from Win32_OperatingSystem", "type": "ioc", "description": null } ], "references": [], "name": "has_wmi" }, { "markcount": 1, "families": [], "description": "Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)", "severity": 2, "marks": [ { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2420, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 1, "length": 24576, "protection": 32, "process_handle": "0xffffffff", "base_address": "0x02490000" }, "time": 1599634390.7815, "tid": 2460, "flags": { "protection": "PAGE_EXECUTE_READ" } }, "pid": 2420, "type": "call", "cid": 17 } ], "references": [], "name": "protection_rx" } ]
The Yara rules did not detect anything in the file.
{ "tls": [], "udp": [ { "src": "192.168.56.101", "dst": "192.168.56.255", "offset": 546, "time": 3.0780880451202393, "dport": 137, "sport": 137 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 2234, "time": 3.04066801071167, "dport": 5355, "sport": 51001 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 2562, "time": 1.0250270366668701, "dport": 5355, "sport": 53595 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 2890, "time": 3.0528790950775146, "dport": 5355, "sport": 53848 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 3218, "time": 1.535140037536621, "dport": 5355, "sport": 54255 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 3546, "time": -0.10139679908752441, "dport": 5355, "sport": 55314 }, { "src": "192.168.56.101", "dst": "239.255.255.250", "offset": 3874, "time": 1.5317401885986328, "dport": 1900, "sport": 1900 }, { "src": "192.168.56.101", "dst": "239.255.255.250", "offset": 8350, "time": 1.0391170978546143, "dport": 3702, "sport": 49152 }, { "src": "192.168.56.101", "dst": "239.255.255.250", "offset": 12542, "time": 3.1245269775390625, "dport": 1900, "sport": 53598 } ], "dns_servers": [], "http": [], "icmp": [], "smtp": [], "tcp": [], "smtp_ex": [], "mitm": [], "hosts": [], "pcap_sha256": "104b0d436f63a35235ca044aeb28ef0044454ec90c1b608e50858e1848b66ee3", "dns": [], "http_ex": [], "domains": [], "dead_hosts": [], "sorted_pcap_sha256": "8ba2f26d90e126fbe44bdfdf03264993ae7988708808b932061b3b6d8115b640", "irc": [], "https_ex": [] }
The instructions below shows how to remove CHARM.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the CHARM.exe file for removal, restart your computer and scan it again to verify that CHARM.exe has been successfully removed. Here are the removal instructions in more detail:
Property | Value |
---|---|
MD5 | 7066da470773e2ffcc708e6c5634d764 |
SHA256 | 042f6b30ca7a2666868197b002a92cce0b11908b24766c77a2111d014195c09c |
These are some of the error messages that can appear related to charm.exe:
charm.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
charm.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.
Computer Health And Remote Monitoring software exclusively for AMTGI clients. has stopped working.
End Program - charm.exe. This program is not responding.
charm.exe is not a valid Win32 application.
charm.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.
To help other users, please let us know what you will do with CHARM.exe:
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.