File signature: UPX -> www.upx.sourceforge.net [Overlay]
Created process: (null),C:\Windows\system32\instsrv OracleInstManager C:\Windows\system32\srvany.exe,C:\Windows\System32
Created process: (null),C:\Windows\system32\reg.exe add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\OracleInstManager /v Type /t REG_DWORD /d 272 /f,C:\Windows\System32
Created process: (null),C:\Windows\system32\reg.exe add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\OracleInstManager\Parameters /v Application /t REG_SZ /d C:\windows\system32\MSInstallMgr.exe /f,C:\Windows\System32
Created process: (null),sc config OracleInstManager type= auto,C:\Windows\System32
Created process: (null),sc delete OracleInstManager,C:\Windows\System32
Created process: (null),sc start OracleInstManager,C:\Windows\System32
Created process: (null),sc stop OracleInstManager,C:\Windows\System32
Defined file type copied to Windows folder: C:\windows\system32\instsrv.exe
Defined file type copied to Windows folder: C:\windows\system32\MSInstallMgr.exe
Defined file type copied to Windows folder: C:\windows\system32\srvany.exe
Defined registry AutoStart location added or modified: machine\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5 = created registry key
Defined registry AutoStart location added or modified: machine\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9 = created registry key
|