| MalAgent.J_72964 is a Trojan. A Trojan is a program that pretends to have a valid use, but in fact modifies the user's computer in malicious ways. Trojans do not replicate or spread to other computers. 
 Mutexes created
 
 
 Directory level activity
 
 File level activity
 
 Registry level activity
 
 Library level activity
 load - library - C:\WINDOWS\system32\rpcss.dllload - library - C:\WINDOWS\system32\uxtheme.dllload - library - uxtheme.dllload - library - OLEAUT32.DLLload - library - oleaut32.dllload - library - ole32.dllload - library - SXS.DLLload - library - USER32load - library - C:\WINDOWS\system32\kernel32.dllload - library - kernel32load - library - user32load - library - ntdllload - library - shell32load - library - advapi32load - library - advapi32
 
 Process API calls used
 
 ZwMapViewOfSectionVirtualProtectExNtCreateSectionNtFreeVirtualMemoryNtProtectVirtualMemory
 
 Registry API calls used
 
 NtOpenKeyNtQueryValueKeyRegOpenKeyExARegOpenKeyExWRegOpenKeyExW
 
 System API calls used
 
 LdrGetDllHandleLdrLoadDllIsDebuggerPresentLdrGetProcedureAddressSetWindowsHookExALdrGetProcedureAddress
 
 Filesystem API calls used
 
 NtCreateFileNtQueryInformationFileNtSetInformationFileNtQueryInformationFile
 Network
 
 UDP source >>  destination
 
 192.168.30.254 >> 192.168.30.8192.168.30.8 >> 192.168.30.255
 
 TCP source >> destination
 
 192.168.30.8 >> 192.168.30.254
 
 
 Domains:
 DNS Request:
 HTTP Request:
 DLL related data
 Number of DLL's imported = 1
 
 |