- May
- 13,740
- 209
After updating TCMD last night, there was, in %TEMP%,
That file is actually an executable. It's digitally signed by "Caphyon SRL" and it seems to have an interest in the registry keys listed below (and not in any others). What's it all about?
These strings are in the file.
Code:
2017-03-10 20:07 497,304 Ins62B0.tmp
These strings are in the file.
HKLM\SYSTEM\CurrentControlSet\Services\W3SVC\DisplayName
HKLM\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKLM\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\Install
HKLM\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client\Install
HKLM\SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.5\SP
HKLM\SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.5\Install
HKLM\SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.0\Setup\InstallSuccess
HKLM\SOFTWARE\Microsoft\NET Framework Setup\NDP\v2.0.50727\Install
HKLM\SOFTWARE\Microsoft\NET Framework Setup\NDP\v1.1.4322\Install
HKLM\SOFTWARE\Microsoft\.NETFramework\policy\v1.0\3705
HKLM\SOFTWARE\Microsoft\DirectX\Version
HKLM\Software\Adobe\Acrobat Reader\11.0\InstallPath\
HKLM\Software\Adobe\Acrobat Reader\10.0\InstallPath\
HKLM\Software\Adobe\Acrobat Reader\9.0\InstallPath\
HKLM\Software\Adobe\Acrobat Reader\8.0\InstallPath\
HKLM\Software\Adobe\Acrobat Reader\7.0\InstallPath\
HKLM\Software\Adobe\Acrobat Reader\6.0\InstallPath\
HKLM\Software\Adobe\Acrobat Reader\5.0\InstallPath\
HKLM\SOFTWARE\JavaSoft\Java Runtime Environment\CurrentVersion
HKLM\SOFTWARE\JavaSoft\Java Development Kit\CurrentVersion
HKLM\SOFTWARE\Microsoft\XNA\Framework\v4.0\NativeLibraryPath
HKLM\SOFTWARE\Microsoft\XNA\Framework\v3.1\NativeLibraryPath
HKLM\SOFTWARE\Microsoft\XNA\Framework\v3.0\NativeLibraryPath
HKLM\SOFTWARE\Microsoft\XNA\Framework\v2.0\NativeLibraryPath
HKLM\SOFTWARE\Microsoft\XNA\Framework\v1.0\NativeLibraryPath
HKLM\SOFTWARE\Microsoft\Office\16.0\Access\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\15.0\Access\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\14.0\Access\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\12.0\Access\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\11.0\Access\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\16.0\Excel\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\15.0\Excel\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\14.0\Excel\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\12.0\Excel\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\11.0\Excel\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\12.0\Groove\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\15.0\InfoPath\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\14.0\InfoPath\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\12.0\InfoPath\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\11.0\InfoPath\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\16.0\OneNote\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\15.0\OneNote\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\14.0\OneNote\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\12.0\OneNote\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\11.0\OneNote\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\16.0\Outlook\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\15.0\Outlook\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\14.0\Outlook\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\12.0\Outlook\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\11.0\Outlook\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\14.0\Groove\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\16.0\PowerPoint\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\15.0\PowerPoint\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\14.0\PowerPoint\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\12.0\PowerPoint\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\11.0\PowerPoint\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\16.0\Publisher\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\15.0\Publisher\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\14.0\Publisher\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\12.0\Publisher\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\11.0\Publisher\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\16.0\Word\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\15.0\Word\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\14.0\Word\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\12.0\Word\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\11.0\Word\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Office\15.0\Groove\InstallRoot\Path
HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\130\SQLServer2016\CurrentVersion\Version
HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\120\Tools\ClientSetup\CurrentVersion\CurrentVersion
HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\110\Tools\ClientSetup\CurrentVersion\CurrentVersion
HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\100\Tools\ClientSetup\CurrentVersion\CurrentVersion
HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\90\Tools\ClientSetup\CurrentVersion\CurrentVersion
HKLM\SOFTWARE\Microsoft\Microsoft SQL Server Compact Edition\v4.0\ENU\DesktopRuntimeVersion
HKLM\SOFTWARE\Microsoft\Microsoft SQL Server Compact Edition\v3.5\ENU\DesktopRuntimeServicePackLevel
HKLM\SOFTWARE\Microsoft\Microsoft SQL Server Compact Edition\v3.5\ENU\DesktopRuntimeVersion
HKLM\SOFTWARE\Microsoft\VSTO Runtime Setup\v4\Install
HKLM\Software\Microsoft\VSTO Runtime Setup\v9.0.21022\Install
HKLM\Software\Microsoft\vsto runtime Setup\v2.0.50727\Install
HKLM\SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\16.0\SharePoint
HKLM\SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\15.0\SharePoint
HKLM\SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\14.0\SharePoint
HKLM\SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\12.0\SharePoint
HKLM\SOFTWARE\Microsoft\PowerShell\3\PowerShellEngine\PowerShellVersion
HKLM\SOFTWARE\Microsoft\PowerShell\1\PowerShellEngine\PowerShellVersion
HKLM\SOFTWARE\Microsoft\PowerShell\1\Install