Summary | ZeroBOX

utorrent_installer.exe

NSIS Malicious Library UPX PE File DLL PE32 ZIP Format
Category Machine Started Completed
FILE s1_win7_x6402 Feb. 18, 2025, 5:23 p.m. Feb. 18, 2025, 5:26 p.m.
Size 3.7MB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 66e88723258eb66e6831fa451494efe3
SHA256 f1f7c3f9ff5b1861c0b0056795e5b39f660f87ad32e750129cfdae423ed32501
CRC32 9A23DBC1
ssdeep 98304:UfyPR3cFFaec4eie3FIt0HVf9tg/Cyo2ErtfGh:USR3l15It0HVICxrt2
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • NSIS_Installer - Null Soft Installer
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Time & API Arguments Status Return Repeated

CryptGenKey

crypto_handle: 0x00ed4920
algorithm_identifier: 0x00000001 ()
flags: 16385
key:
provider_handle: 0x00ef2bd0
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed47a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ¤RSA1Ӑ‡¤ õ®í²ðîÄûK`±ìbêØÓbúÐÜ^Âe­–'£‹}mE’xw™Œ,=µ¢‚Éjž.‰©5«o†zÎs¡¿¿ÈÞq„J?Ô- «4o‰Š˜9œŽ˜Ôf4ísAiœKO=ÙµÃ1s P„HAÍò@o¨[oùvMš bÃâ
crypto_handle: 0x00ed47a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed47a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ¤RSA1Ӑ‡¤ õ®í²ðîÄûK`±ìbêØÓbúÐÜ^Âe­–'£‹}mE’xw™Œ,=µ¢‚Éjž.‰©5«o†zÎs¡¿¿ÈÞq„J?Ô- «4o‰Š˜9œŽ˜Ôf4ísAiœKO=ÙµÃ1s P„HAÍò@o¨[oùvMš bÃâ
crypto_handle: 0x00ed47a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0

CryptExportKey

buffer: ¤RSA2Ӑ‡¤ õ®í²ðîÄûK`±ìbêØÓbúÐÜ^Âe­–'£‹}mE’xw™Œ,=µ¢‚Éjž.‰©5«o†zÎs¡¿¿ÈÞq„J?Ô- «4o‰Š˜9œŽ˜Ôf4ísAiœKO=ÙµÃ1s P„HAÍò@o¨[oùvMš bÃâ7Á¹Vɇ´{i»ã_/݄Ñ$yM¤†ä¡ƒWA6‡]öAÓLÆSƒR7Šó>”>ú¥‡íP”XÓòE޼ Nv˜ ˜ì¥ö–÷ŸpªÍø˜ºD4V¯½ðX¨p}n¶åRíWà?Kߒ'à JaIŒÿ8l\éUîå$)lB½‚ç$tH(Aä{Ù»ä[ÃßvkìXìê?Å?éø3ÇHÖ¢áiËÔ£ŽnˆÈh§Ç›RžêA„‘l•½H«ÝË2ƒ:Ò˟Š–½‹M,æÀóžÈè£!NŒâ˚,ψDìÑ¢ú>"p¢)/K­ ´ÙÎÿΊ:¢f8¥‹;+„_°Û(üi P¯-y©Ï¥y›8¿¼‘O€¢s§D{T›á«G/Ï!3"fu Azԕ/q Öòî<¿£Æþ-³ByüÞµÊ> 쬚K:ž ¾²—×ÜÙ7‚åÊükÿ¬²ƒ+ $ˆԣ.¨msêS.C‰äo7Á¶é ÂVίéggé½Â4©¨ß’Æo(HˆHÐ4 GhÐç½h×yÞðX#;c!éN¡ƒ³’»
crypto_handle: 0x00ed4a60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 7
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
suspicious_features POST method with no referer header suspicious_request POST http://i-6000.b-47194.ut.bench.utorrent.com/e?i=6000
suspicious_features POST method with no referer header suspicious_request POST http://i-21.b-47194.ut.bench.utorrent.com/e?i=21
request POST http://i-6000.b-47194.ut.bench.utorrent.com/e?i=6000
request GET http://utorrent.com/download/langpacks/dl.php?build=47194&ref=client&client=utorrent&sys_l=ko&sel_l=28523&tk=release
request GET http://legacy.utorrent.com/scripts/dl.php?build=47194&ref=client&client=utorrent&sys_l=ko&sel_l=28523&tk=release
request GET http://update.utorrent.com/installoffer.php?h=NCCsadz1MhCI1sDI&v=113293402&w=1DB10106&l=ko&c=KR&w64=1&db=ie&cl=uTorrent&tsub=1&svp=4
request POST http://i-21.b-47194.ut.bench.utorrent.com/e?i=21
request GET http://update.utorrent.com/installstats.php?cl=uTorrent&v=113293402&h=NCCsadz1MhCI1sDI&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showtbexists&pid=2104&cau=0&lunv=0&tbe=0&view=win32
request GET http://update.utorrent.com/installstats.php?cl=uTorrent&v=113293402&h=NCCsadz1MhCI1sDI&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showwarning&pid=2104&cau=0&lunv=0&view=win32
request POST http://i-6000.b-47194.ut.bench.utorrent.com/e?i=6000
request POST http://i-21.b-47194.ut.bench.utorrent.com/e?i=21
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 3024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x740d5000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 3024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x740c5000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 3024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73f22000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2104
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73f22000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2104
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73823000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115475968
free_bytes_available: 9115475968
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115471872
free_bytes_available: 9115471872
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115471872
free_bytes_available: 9115471872
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115471872
free_bytes_available: 9115471872
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115471872
free_bytes_available: 9115471872
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115480064
free_bytes_available: 9115480064
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115459584
free_bytes_available: 9115459584
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115111424
free_bytes_available: 9115111424
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115111424
free_bytes_available: 9115111424
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115045888
free_bytes_available: 9115045888
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115045888
free_bytes_available: 9115045888
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115045888
free_bytes_available: 9115045888
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115045888
free_bytes_available: 9115045888
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115045888
free_bytes_available: 9115045888
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9115045888
free_bytes_available: 9115045888
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9113784320
free_bytes_available: 9113784320
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108721664
free_bytes_available: 9108721664
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108721664
free_bytes_available: 9108721664
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108717568
free_bytes_available: 9108717568
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108721664
free_bytes_available: 9108721664
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108721664
free_bytes_available: 9108721664
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108721664
free_bytes_available: 9108721664
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108721664
free_bytes_available: 9108721664
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9108721664
free_bytes_available: 9108721664
root_path: C:\Users\test22\AppData\Roaming\uTorrent\share
total_number_of_bytes: 34252779520
1 1 0
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp\System.dll
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp\utorrent.exe
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp\nsisFirewall.dll
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp\INetC.dll
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp\utorrent.exe
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp\nsisFirewall.dll
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp\utorrent.exe
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp\System.dll
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp\INetC.dll
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 46
family: 2
111 0
section {u'size_of_data': u'0x0001c600', u'virtual_address': u'0x00050000', u'entropy': 7.209826701068137, u'name': u'.rsrc', u'virtual_size': u'0x0001c600'} entropy 7.20982670107 description A section with a high entropy has been found
entropy 0.780068728522 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeManageVolumePrivilege
1 1 0
Time & API Arguments Status Return Repeated

RegOpenKeyExW

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
2 0

RegOpenKeyExW

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
2 0

RegOpenKeyExW

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
2 0
file C:\Users\test22\AppData\Local\Temp\nsa2AB5.tmp
Time & API Arguments Status Return Repeated

RegSetValueExA

key_handle: 0x000004ec
regkey_r: ProxyEnable
reg_type: 4 (REG_DWORD)
value: 0
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
1 0 0
Time & API Arguments Status Return Repeated

RegSetValueExA

key_handle: 0x000004ec
regkey_r: ProxyOverride
reg_type: 1 (REG_SZ)
value: 127.0.0.1:16107;
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
1 0 0
process utorrent_installer.exe useragent NSIS_Inetc (Mozilla)
process utorrent.exe useragent uTorrent(47194105433.6
registry HKEY_CURRENT_USER\Software\Wine