Code: Select all
Filename: xyplorer_13.20_install.exe
Threat name: SONAR.SuspBeh!gen3
Full Path: Not Available
High
This file risk is high.
SONAR Protection monitors for suspicious program activity on your computer.
____________________________
Source: External Media
____________________________
File Actions
File: c:\users\<username>\appdata\local\temp\wz9c1f\ xyplorer_13.20_install.exe No Action Required
File: c:\program files (x86)\xyplorer\ xyplorer.chm Removed
File: c:\program files (x86)\xyplorer\ readmexy.txt Removed
File: c:\program files (x86)\xyplorer\ licensexy.txt Removed
File: c:\program files (x86)\xyplorer\ tipoftheday.htm Removed
File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer.lnk Removed
File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer help.lnk Removed
File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer homepage.url Removed
File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer uninstall.lnk Removed
File: c:\users\<username>\appdata\roaming\mpc-hc\ default.mpcpl Removed
Directory: c:\users\<username>\appdata\local\temp\ nsnc469.tmp No Action Required
____________________________
Registry Actions
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->DisplayVersion:13.20, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->NSIS:StartMenuDir:XYplorer, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\XYplorer->URLInfoAbout:http://www.xyplorer.com/, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->Publisher:Donald Lessau, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\XYplorer->InstallLocation:C:\Program Files (x86)\ XYplorer, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->VersionMajor:13, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->VersionMinor:20, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-1035394184-3343349579-4230999837-1001_CLASSES\Local Settings\MuiCache\88A\ 52C64B7E->LanguageList:..., Registry Hive: 64 bit Repaired
____________________________
System Settings Actions
Event: Browser process start (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ userinfo.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ system.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ nsdialogs.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ startmenu.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\program files (x86)\XYplorer\ XYplorer.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\program files (x86)\XYplorer\ XYcopy.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\program files (x86)\XYplorer\ uninstall.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: Process start: c:\program files (x86)\XYplorer\ XYplorer.exe, PID:4836 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: Process start: c:\users\<username>\appdata\local\temp\wz9c1f\ xyplorer_13.20_install.exe, PID:6536 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: Process start: c:\program files (x86)\k-lite codec pack\media player classic\ mpc-hc.exe, PID:1508 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
____________________________
Suspicious Actions
Event: Attempt to start a remote thread in a process address space (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: Accessibility API usage (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
____________________________
XYplorer Beta Club