Summary | ZeroBOX

utorrent_installer.exe

NSIS Malicious Library UPX PE File DLL PE32 ZIP Format
Category Machine Started Completed
FILE s1_win7_x6403_us Feb. 18, 2025, 5:23 p.m. Feb. 18, 2025, 5:25 p.m.
Size 3.7MB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 66e88723258eb66e6831fa451494efe3
SHA256 f1f7c3f9ff5b1861c0b0056795e5b39f660f87ad32e750129cfdae423ed32501
CRC32 9A23DBC1
ssdeep 98304:UfyPR3cFFaec4eie3FIt0HVf9tg/Cyo2ErtfGh:USR3l15It0HVICxrt2
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • NSIS_Installer - Null Soft Installer
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Time & API Arguments Status Return Repeated

CryptGenKey

crypto_handle: 0x00e347a0
algorithm_identifier: 0x00000001 ()
flags: 16385
key:
provider_handle: 0x00e51fd8
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34d60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ¤RSA1ñ.üOP¸îµ4Qü ‘g«?km„±Ü+ÍÂPn\›<Þø¤Ÿ¼ÖMéäµø"‡Œëv x¨Ð,UÙèˁJq|.µí€D©_:ºÀM$Ü 0™Dã4ۓ¢&wðª? ê½é¢¼<ÞÄI;D‹«UtZŽBž£¸
crypto_handle: 0x00e34d60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34d60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ¤RSA1ñ.üOP¸îµ4Qü ‘g«?km„±Ü+ÍÂPn\›<Þø¤Ÿ¼ÖMéäµø"‡Œëv x¨Ð,UÙèˁJq|.µí€D©_:ºÀM$Ü 0™Dã4ۓ¢&wðª? ê½é¢¼<ÞÄI;D‹«UtZŽBž£¸
crypto_handle: 0x00e34d60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34d20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34d20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: ¤RSA2ñ.üOP¸îµ4Qü ‘g«?km„±Ü+ÍÂPn\›<Þø¤Ÿ¼ÖMéäµø"‡Œëv x¨Ð,UÙèˁJq|.µí€D©_:ºÀM$Ü 0™Dã4ۓ¢&wðª? ê½é¢¼<ÞÄI;D‹«UtZŽBž£¸‡uìÆh(™vאAÏ>TëÆ~Õ7À"®^Kè¡:lGY†õH5ëïØ`V©G±û~I ¿Òî;ÀÝfsëÇUaë<œDSr(ª{Œ£ºHŸÒWeÇ*9†g½_ïÁÚ~+iš#ŽªokýÐé^þÍW'ð֌èW¸q`ÀÈ<ÀÌ)îK»²’ ia­_ߏ”¦ä™õI‹“˜÷ó!ЗšÃ°l‰¬pJ*á»Or7ƒuµIX-q|¦ë]}¨‚žÆ—Ž4uîy@ æ”XtÛn§BM‰AKàJ·Íû «ž&9Wˆ€…‚¸Óá|­0~Ï×DeJ$_Ñ ¥ÑÔ?îÞ^æE×NF‡|Gív=Ši®9 ™8Æ$D ålx-Vºá÷Ž$7Ú'/¯¨Í?HÛ^•øi®+û»0™8^éït|e… <›Oý—8(¶Ö!KB)连1[ùçNãÔEra”f×j¸ø”c«Œ÷ žÝ~@È–<ùþ^RW±•˜ªî?é¶ ;·äÕO™åKä ¹cVƒ±JÊŌ ëS~ZT1*ƒ
crypto_handle: 0x00e34f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
suspicious_features POST method with no referer header suspicious_request POST http://i-6000.b-47194.ut.bench.utorrent.com/e?i=6000
suspicious_features POST method with no referer header suspicious_request POST http://i-21.b-47194.ut.bench.utorrent.com/e?i=21
request POST http://i-6000.b-47194.ut.bench.utorrent.com/e?i=6000
request GET http://utorrent.com/download/langpacks/dl.php?build=47194&ref=client&client=utorrent&sys_l=ko&sel_l=28523&tk=release
request GET http://legacy.utorrent.com/scripts/dl.php?build=47194&ref=client&client=utorrent&sys_l=ko&sel_l=28523&tk=release
request GET http://update.utorrent.com/installoffer.php?h=4pR3xYqNmDodIgSS&v=113293402&w=1DB10106&l=ko&c=KR&w64=1&db=ie&cl=uTorrent&tsub=1&svp=4
request POST http://i-21.b-47194.ut.bench.utorrent.com/e?i=21
request GET http://update.utorrent.com/installstats.php?cl=uTorrent&v=113293402&h=4pR3xYqNmDodIgSS&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showtbexists&pid=2116&cau=0&lunv=0&tbe=0&view=win32
request GET http://update.utorrent.com/installstats.php?cl=uTorrent&v=113293402&h=4pR3xYqNmDodIgSS&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showwarning&pid=2116&cau=0&lunv=0&view=win32
request POST http://i-6000.b-47194.ut.bench.utorrent.com/e?i=6000
request POST http://i-21.b-47194.ut.bench.utorrent.com/e?i=21
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 776
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x74275000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 776
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x74265000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925980160
free_bytes_available: 9925980160
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925976064
free_bytes_available: 9925976064
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925976064
free_bytes_available: 9925976064
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925976064
free_bytes_available: 9925976064
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925976064
free_bytes_available: 9925976064
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925976064
free_bytes_available: 9925976064
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925939200
free_bytes_available: 9925939200
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9925935104
free_bytes_available: 9925935104
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9926008832
free_bytes_available: 9926008832
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9926008832
free_bytes_available: 9926008832
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9926008832
free_bytes_available: 9926008832
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9926008832
free_bytes_available: 9926008832
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9926008832
free_bytes_available: 9926008832
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9926008832
free_bytes_available: 9926008832
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9926008832
free_bytes_available: 9926008832
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9924677632
free_bytes_available: 9924677632
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9924677632
free_bytes_available: 9924677632
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920946176
free_bytes_available: 9920946176
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920946176
free_bytes_available: 9920946176
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9920942080
free_bytes_available: 9920942080
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp\utorrent.exe
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp\System.dll
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp\INetC.dll
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp\nsisFirewall.dll
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp\utorrent.exe
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp\nsisFirewall.dll
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp\utorrent.exe
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp\System.dll
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp\INetC.dll
ESET-NOD32 a variant of Win32/uTorrent.E potentially unwanted
Antiy-AVL GrayWare/Win32.uTorrent.e
DeepInstinct MALICIOUS
VBA32 suspected of Trojan.Downloader.gen
Malwarebytes PUP.Optional.BundleInstaller
Ikarus PUA.uTorrent
Fortinet Riskware/uTorrent.E6A1
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 46
family: 2
111 0
section {u'size_of_data': u'0x0001c600', u'virtual_address': u'0x00050000', u'entropy': 7.209826701068137, u'name': u'.rsrc', u'virtual_size': u'0x0001c600'} entropy 7.20982670107 description A section with a high entropy has been found
entropy 0.780068728522 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeManageVolumePrivilege
1 1 0
Time & API Arguments Status Return Repeated

RegOpenKeyExW

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
2 0

RegOpenKeyExW

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
2 0

RegOpenKeyExW

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
2 0
file C:\Users\test22\AppData\Local\Temp\nsnC0AC.tmp
Time & API Arguments Status Return Repeated

RegSetValueExA

key_handle: 0x000004e8
regkey_r: ProxyEnable
reg_type: 4 (REG_DWORD)
value: 0
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
1 0 0
process utorrent_installer.exe useragent NSIS_Inetc (Mozilla)
process utorrent.exe useragent uTorrent(47194105433.6
registry HKEY_CURRENT_USER\Software\Wine