File name:

Driver_Updater_setup.exe

Full analysis: https://app.any.run/tasks/ee7d06ee-9e2b-47b3-bfd4-7ce77f5deae3
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: September 08, 2024, 11:22:22
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

CB055D7DDB5B500C5FCB0051428FC3CC

SHA1:

C98493F9809C8FD95FD8067A2F1CADF2EE4CEAD3

SHA256:

011D634221DC4DE0498600568F37E27DE35CFE60FC2C2B22C2AA87871FB10C0A

SSDEEP:

98304:6+QqZ8fuhL4lMReXlNfUBJYZ35eJHcOpJn5KZD5pk0uypuJTMVLagOVFp+OKCJbP:ari9iJiRLFTA/YNswKfwv5z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADWARE has been detected (SURICATA)

      • PCHelpSoftDriverUpdater.exe (PID: 780)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Driver_Updater_setup.tmp (PID: 6472)
      • PCHelpSoftDriverUpdater.exe (PID: 780)
      • PCHelpSoftDriverUpdater.exe (PID: 1288)
    • Executable content was dropped or overwritten

      • Driver_Updater_setup.exe (PID: 3584)
      • Driver_Updater_setup.exe (PID: 1372)
      • Driver_Updater_setup.tmp (PID: 532)
    • Drops 7-zip archiver for unpacking

      • Driver_Updater_setup.tmp (PID: 532)
    • Reads the Windows owner or organization settings

      • Driver_Updater_setup.tmp (PID: 532)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 788)
      • schtasks.exe (PID: 3812)
    • Application launched itself

      • PCHelpSoftDriverUpdater.exe (PID: 780)
    • Checks Windows Trust Settings

      • PCHelpSoftDriverUpdater.exe (PID: 780)
    • Access to an unwanted program domain was detected

      • PCHelpSoftDriverUpdater.exe (PID: 780)
  • INFO

    • Create files in a temporary directory

      • Driver_Updater_setup.exe (PID: 3584)
      • Driver_Updater_setup.exe (PID: 1372)
      • Driver_Updater_setup.tmp (PID: 532)
      • PCHelpSoftDriverUpdater.exe (PID: 780)
    • Checks supported languages

      • Driver_Updater_setup.exe (PID: 3584)
      • Driver_Updater_setup.tmp (PID: 6472)
      • Driver_Updater_setup.tmp (PID: 532)
      • Driver_Updater_setup.exe (PID: 1372)
      • PCHelpSoftDriverUpdater.exe (PID: 1288)
      • PCHelpSoftDriverUpdater.exe (PID: 6372)
      • PCHelpSoftDriverUpdater.exe (PID: 780)
      • DriverPro.exe (PID: 2232)
      • identity_helper.exe (PID: 7036)
    • Process checks computer location settings

      • Driver_Updater_setup.tmp (PID: 6472)
      • PCHelpSoftDriverUpdater.exe (PID: 1288)
      • PCHelpSoftDriverUpdater.exe (PID: 780)
      • PCHelpSoftDriverUpdater.exe (PID: 6372)
    • Reads the computer name

      • Driver_Updater_setup.tmp (PID: 6472)
      • Driver_Updater_setup.tmp (PID: 532)
      • PCHelpSoftDriverUpdater.exe (PID: 1288)
      • PCHelpSoftDriverUpdater.exe (PID: 780)
      • DriverPro.exe (PID: 2232)
      • identity_helper.exe (PID: 7036)
      • PCHelpSoftDriverUpdater.exe (PID: 6372)
    • Creates files in the program directory

      • Driver_Updater_setup.tmp (PID: 532)
      • DriverPro.exe (PID: 2232)
    • Creates a software uninstall entry

      • Driver_Updater_setup.tmp (PID: 532)
    • Creates files or folders in the user directory

      • PCHelpSoftDriverUpdater.exe (PID: 1288)
      • PCHelpSoftDriverUpdater.exe (PID: 780)
      • PCHelpSoftDriverUpdater.exe (PID: 6372)
    • Checks proxy server information

      • PCHelpSoftDriverUpdater.exe (PID: 780)
    • Reads the machine GUID from the registry

      • PCHelpSoftDriverUpdater.exe (PID: 780)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 780)
    • The process uses the downloaded file

      • PCHelpSoftDriverUpdater.exe (PID: 780)
      • PCHelpSoftDriverUpdater.exe (PID: 1288)
    • Reads the software policy settings

      • PCHelpSoftDriverUpdater.exe (PID: 780)
    • Application launched itself

      • msedge.exe (PID: 5944)
      • msedge.exe (PID: 6172)
    • Reads Environment values

      • identity_helper.exe (PID: 7036)
    • Manual execution by a user

      • msedge.exe (PID: 6172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 08:09:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 68096
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.1.1130.0
ProductVersionNumber: 7.1.1130.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: PC HelpSoft
FileDescription: PC HelpSoft Driver Updater
FileVersion: 7.1.1130.0
LegalCopyright: PC HelpSoft
OriginalFileName:
ProductName: PC HelpSoft Driver Updater
ProductVersion: 7.1.1130.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
218
Monitored processes
89
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start driver_updater_setup.exe driver_updater_setup.tmp no specs driver_updater_setup.exe driver_updater_setup.tmp pchelpsoftdriverupdater.exe no specs schtasks.exe no specs schtasks.exe no specs conhost.exe no specs conhost.exe no specs #ADWARE pchelpsoftdriverupdater.exe driverpro.exe no specs pchelpsoftdriverupdater.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
320"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=6028 --field-trial-handle=2416,i,15621302893085309548,14825300510626219907,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
360"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6364 --field-trial-handle=2416,i,15621302893085309548,14825300510626219907,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
400"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=4320 --field-trial-handle=2416,i,15621302893085309548,14825300510626219907,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
508"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2504 --field-trial-handle=2364,i,11866424252238519883,15409172636654742532,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
532"C:\Users\admin\AppData\Local\Temp\is-U6125.tmp\Driver_Updater_setup.tmp" /SL5="$903A4,5837648,810496,C:\Users\admin\Desktop\Driver_Updater_setup.exe" /SPAWNWND=$80316 /NOTIFYWND=$903D2 C:\Users\admin\AppData\Local\Temp\is-U6125.tmp\Driver_Updater_setup.tmp
Driver_Updater_setup.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-u6125.tmp\driver_updater_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mpr.dll
608"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=5476 --field-trial-handle=2416,i,15621302893085309548,14825300510626219907,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
780"C:\Program Files (x86)\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /START /INSTALLEDC:\Program Files (x86)\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe
Driver_Updater_setup.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Version:
7.1.1130
Modules
Images
c:\program files (x86)\pc helpsoft driver updater\pchelpsoftdriverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
788"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Monitoring" /FC:\Windows\SysWOW64\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
788"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5160 --field-trial-handle=2416,i,15621302893085309548,14825300510626219907,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
788"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=31 --mojo-platform-channel-handle=6828 --field-trial-handle=2416,i,15621302893085309548,14825300510626219907,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
11 874
Read events
11 664
Write events
186
Delete events
24

Modification events

(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.HDM_encrypted\OpenWithProgids
Operation:writeName:PCHelpSoftDriverUpdater.HDM_encrypted
Value:
(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\PCHelpSoftDriverUpdater.exe\SupportedTypes
Operation:writeName:.HDM_encrypted
Value:
(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\PC HelpSoft Driver Updater
Operation:writeName:Language
Value:
1
(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\PC HelpSoft Driver Updater
Operation:writeName:DelayedStart
Value:
0
(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\PC HelpSoft Driver Updater
Operation:writeName:SetupName
Value:
C:\Users\admin\Desktop\Driver_Updater_setup.exe
(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC HelpSoft Driver Updater_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.0
(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC HelpSoft Driver Updater_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\PC HelpSoft Driver Updater
(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC HelpSoft Driver Updater_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\PC HelpSoft Driver Updater\
(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC HelpSoft Driver Updater_is1
Operation:writeName:Inno Setup: Icon Group
Value:
PC HelpSoft Driver Updater
(PID) Process:(532) Driver_Updater_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC HelpSoft Driver Updater_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
36
Suspicious files
870
Text files
327
Unknown types
10

Dropped files

PID
Process
Filename
Type
3584Driver_Updater_setup.exeC:\Users\admin\AppData\Local\Temp\is-V1R7P.tmp\Driver_Updater_setup.tmpexecutable
MD5:4947F753EB5C3B1AA3CE496A9AB30130
SHA256:1CB7131714F41D651792F15B48A128840C959A5190D076A7FEE5FE8B8EFE232D
532Driver_Updater_setup.tmpC:\Users\admin\AppData\Local\Temp\is-5S3FL.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
532Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\DriverPro.exeexecutable
MD5:34392941C1918C5639E8C0CBFA64115E
SHA256:C825552C99C321DFBAAE6B16D797F80A6557C555689BD78AF815B0D48B0CCB05
532Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\unins000.exeexecutable
MD5:4947F753EB5C3B1AA3CE496A9AB30130
SHA256:1CB7131714F41D651792F15B48A128840C959A5190D076A7FEE5FE8B8EFE232D
532Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\Danish.inibinary
MD5:25BB2EAECB641EC8E07C30CA3B8CF387
SHA256:D4BDFA83D66E9FBFA5B5C0DA832C4766D539FD7B1F2EDDEE53E7DBC7E8E095E9
532Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\is-KQ0GN.tmpexecutable
MD5:4947F753EB5C3B1AA3CE496A9AB30130
SHA256:1CB7131714F41D651792F15B48A128840C959A5190D076A7FEE5FE8B8EFE232D
532Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\is-RM5OF.tmptext
MD5:C12E324F7BA24C91F31927D7A720294A
SHA256:BAD8F599F3B38B7F67E77E26AEC057FA8849C0CB80B72AC9E7265F9DCB3AF199
532Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\Settings.initext
MD5:C12E324F7BA24C91F31927D7A720294A
SHA256:BAD8F599F3B38B7F67E77E26AEC057FA8849C0CB80B72AC9E7265F9DCB3AF199
532Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\is-6J5PL.tmpexecutable
MD5:33BEA8D12BB5F49A948B650A882F54FE
SHA256:B82D89D84D2815B550810DCBB7F99E68B793DC152AA3838C8F953A7BE50B750F
532Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\is-LUKRP.tmpimage
MD5:915F2CE934FD4789216B91BF9C2609FD
SHA256:135D81FEEF8BC93E48F3D929D9249ABE56E8B0A566F51964C8CAD28602219250
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
244
DNS requests
252
Threats
51

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
780
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.84:80
http://api.playanext.com/httpapi
unknown
unknown
6344
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
768
lsass.exe
GET
200
18.245.65.219:80
http://ocsp.r2m03.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQqHI%2BsdmapawQncL1rpCEZZ8gTSAQUVdkYX9IczAHhWLS%2Bq9lVQgHXLgICEAIZ3N4iW9BAI0lEJQIp3%2F0%3D
unknown
unknown
780
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.84:80
http://api.playanext.com/httpapi
unknown
unknown
768
lsass.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
unknown
780
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.84:80
http://api.playanext.com/httpapi
unknown
unknown
780
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.84:80
http://api.playanext.com/httpapi
unknown
unknown
780
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.84:80
http://api.playanext.com/httpapi
unknown
unknown
2816
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6252
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1780
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6344
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6344
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
  • 20.73.194.208
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted
google.com
  • 172.217.23.110
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.160.14
  • 40.126.32.138
  • 20.190.160.20
  • 40.126.32.133
  • 40.126.32.136
  • 40.126.32.74
  • 40.126.32.134
  • 40.126.32.140
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
drivers.avqtools.com
  • 116.203.251.147
unknown
offers.playanext.com
  • 13.225.78.32
  • 13.225.78.23
  • 13.225.78.64
  • 13.225.78.119
unknown
api.playanext.com
  • 18.245.86.84
  • 18.245.86.79
  • 18.245.86.26
  • 18.245.86.105
whitelisted
cloud.pchelpsoft.com
  • 104.26.0.116
  • 172.67.73.195
  • 104.26.1.116
unknown

Threats

PID
Process
Class
Message
780
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
780
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
780
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
780
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
780
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7028
msedge.exe
Misc activity
ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard Low Port)
7028
msedge.exe
Misc activity
ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard Low Port)
7028
msedge.exe
Misc activity
ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard High Port)
7028
msedge.exe
Misc activity
ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard High Port)
7028
msedge.exe
Misc activity
ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard Low Port)
No debug info