File name:

PCHelpSoftDriverUpdater_upg.exe

Full analysis: https://app.any.run/tasks/88477051-99b1-4140-9868-7e599f84719f
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: February 27, 2025, 07:37:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
adware
delphi
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

B8FF763A66EF51EF79636D5F725B7B31

SHA1:

66479AED07A5AFCD65D7C8D8D1F1C7FD8A7AA120

SHA256:

153218D7B79FE58998370BF4E5165F7F69AD38E71BD9C9CB16F7FD1FEC558BAC

SSDEEP:

98304:c+cD4dnhX+zQXNlC9R3qOVM020Cwi2GNXGQwx07jQ8kRnsMQK9j6yvddeUzWSu/s:OvGgZwIkUz03o

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADWARE has been detected (SURICATA)

      • PCHelpSoftDriverUpdater.exe (PID: 7460)
    • Actions looks like stealing of personal data

      • avg_secure_browser_setup.exe (PID: 5408)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PCHelpSoftDriverUpdater_upg.exe (PID: 3300)
      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • avg_secure_browser_setup.exe (PID: 5408)
      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • Reads security settings of Internet Explorer

      • PCHelpSoftDriverUpdater_upg.tmp (PID: 6808)
      • PCHelpSoftDriverUpdater.exe (PID: 8060)
      • ShellExperienceHost.exe (PID: 6112)
      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • avg_secure_browser_setup.exe (PID: 5408)
      • AVGBrowserUpdate.exe (PID: 5200)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 1276)
      • schtasks.exe (PID: 7272)
    • Application launched itself

      • PCHelpSoftDriverUpdater.exe (PID: 7460)
    • Access to an unwanted program domain was detected

      • PCHelpSoftDriverUpdater.exe (PID: 7460)
    • Checks Windows Trust Settings

      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • avg_secure_browser_setup.exe (PID: 5408)
    • Reads the BIOS version

      • avg_secure_browser_setup.exe (PID: 5408)
    • The process verifies whether the antivirus software is installed

      • avg_secure_browser_setup.exe (PID: 5408)
    • Searches for installed software

      • avg_secure_browser_setup.exe (PID: 5408)
    • Creates/Modifies COM task schedule object

      • AVGBrowserUpdate.exe (PID: 4608)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 1196)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7632)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7844)
      • AVGBrowserUpdate.exe (PID: 5200)
    • Disables SEHOP

      • AVGBrowserUpdate.exe (PID: 5200)
    • Starts itself from another location

      • AVGBrowserUpdate.exe (PID: 5200)
    • Executes as Windows Service

      • AVGBrowserUpdate.exe (PID: 8116)
    • Potential Corporate Privacy Violation

      • AVGBrowserUpdate.exe (PID: 8116)
  • INFO

    • Checks supported languages

      • PCHelpSoftDriverUpdater_upg.exe (PID: 3300)
      • PCHelpSoftDriverUpdater_upg.tmp (PID: 6808)
      • PCHelpSoftDriverUpdater.exe (PID: 8060)
      • DriverPro.exe (PID: 7484)
      • PCHelpSoftDriverUpdater.exe (PID: 7288)
      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • ShellExperienceHost.exe (PID: 6112)
      • avg_secure_browser_setup.exe (PID: 5408)
      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
      • AVGBrowserUpdate.exe (PID: 7184)
      • AVGBrowserUpdate.exe (PID: 4608)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7632)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 1196)
      • AVGBrowserUpdate.exe (PID: 7996)
      • AVGBrowserUpdate.exe (PID: 7416)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7844)
      • AVGBrowserUpdate.exe (PID: 8116)
    • Create files in a temporary directory

      • PCHelpSoftDriverUpdater_upg.exe (PID: 3300)
      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • avg_secure_browser_setup.exe (PID: 5408)
    • Process checks computer location settings

      • PCHelpSoftDriverUpdater_upg.tmp (PID: 6808)
      • PCHelpSoftDriverUpdater.exe (PID: 8060)
      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • PCHelpSoftDriverUpdater.exe (PID: 7288)
      • avg_secure_browser_setup.exe (PID: 5408)
      • AVGBrowserUpdate.exe (PID: 5200)
    • Reads the computer name

      • PCHelpSoftDriverUpdater_upg.tmp (PID: 6808)
      • PCHelpSoftDriverUpdater.exe (PID: 8060)
      • DriverPro.exe (PID: 7484)
      • PCHelpSoftDriverUpdater.exe (PID: 7288)
      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • ShellExperienceHost.exe (PID: 6112)
      • avg_secure_browser_setup.exe (PID: 5408)
      • AVGBrowserUpdate.exe (PID: 5200)
      • AVGBrowserUpdate.exe (PID: 4608)
      • AVGBrowserUpdate.exe (PID: 7184)
      • AVGBrowserUpdate.exe (PID: 7996)
      • AVGBrowserUpdate.exe (PID: 7416)
      • AVGBrowserUpdate.exe (PID: 8116)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 7532)
      • PCHelpSoftDriverUpdater.exe (PID: 8060)
      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • PCHelpSoftDriverUpdater.exe (PID: 7288)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7324)
      • BackgroundTransferHost.exe (PID: 7708)
      • BackgroundTransferHost.exe (PID: 7532)
      • BackgroundTransferHost.exe (PID: 7952)
      • BackgroundTransferHost.exe (PID: 6132)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 7532)
      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • slui.exe (PID: 6132)
      • avg_secure_browser_setup.exe (PID: 5408)
      • AVGBrowserUpdate.exe (PID: 7996)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 7532)
      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • slui.exe (PID: 6132)
      • avg_secure_browser_setup.exe (PID: 5408)
      • AVGBrowserUpdate.exe (PID: 7996)
      • AVGBrowserUpdate.exe (PID: 8116)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 7460)
    • Creates files in the program directory

      • DriverPro.exe (PID: 7484)
    • Reads the machine GUID from the registry

      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • avg_secure_browser_setup.exe (PID: 5408)
      • AVGBrowserUpdate.exe (PID: 5200)
      • AVGBrowserUpdate.exe (PID: 8116)
    • Compiled with Borland Delphi (YARA)

      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • slui.exe (PID: 6132)
      • PCHelpSoftDriverUpdater.exe (PID: 7288)
    • The sample compiled with arabic language support

      • PCHelpSoftDriverUpdater.exe (PID: 7460)
      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with english language support

      • avg_secure_browser_setup.exe (PID: 5408)
      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • Reads Environment values

      • avg_secure_browser_setup.exe (PID: 5408)
    • The sample compiled with Indonesian language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with japanese language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with czech language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with bulgarian language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with Italian language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with german language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with russian language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with slovak language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with turkish language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with chinese language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with french language support

      • AVGBrowserUpdate.exe (PID: 5200)
      • AVGBrowserUpdateSetup.exe (PID: 7772)
    • The sample compiled with swedish language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with korean language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with polish language support

      • AVGBrowserUpdateSetup.exe (PID: 7772)
      • AVGBrowserUpdate.exe (PID: 5200)
    • The sample compiled with portuguese language support

      • AVGBrowserUpdate.exe (PID: 5200)
      • AVGBrowserUpdateSetup.exe (PID: 7772)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 68096
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.1.1350.0
ProductVersionNumber: 7.1.1350.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: PC HelpSoft
FileDescription: PC HelpSoft Driver Updater
FileVersion: 7.1.1350.0
LegalCopyright: PC HelpSoft
OriginalFileName:
ProductName: PC HelpSoft Driver Updater
ProductVersion: 7.1.1350.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
167
Monitored processes
29
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start pchelpsoftdriverupdater_upg.exe pchelpsoftdriverupdater_upg.tmp no specs pchelpsoftdriverupdater_upg.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs pchelpsoftdriverupdater.exe no specs backgroundtransferhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs #ADWARE pchelpsoftdriverupdater.exe driverpro.exe no specs pchelpsoftdriverupdater.exe no specs shellexperiencehost.exe no specs slui.exe avg_secure_browser_setup.exe avgbrowserupdatesetup.exe avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
1196"C:\Program Files (x86)\AVG\Browser\Update\1.8.1693.6\AVGBrowserUpdateComRegisterShell64.exe" C:\Program Files (x86)\AVG\Browser\Update\1.8.1693.6\AVGBrowserUpdateComRegisterShell64.exeAVGBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Browser Com Register Shell 64
Exit code:
0
Version:
1.8.1693.6
Modules
Images
c:\program files (x86)\avg\browser\update\1.8.1693.6\avgbrowserupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1276"C:\Windows\System32\schtasks.exe" /Delete /TN "PC HelpSoft Driver Updater Schedule" /FC:\Windows\SysWOW64\schtasks.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1324"C:\Users\admin\AppData\Local\Temp\PCHelpSoftDriverUpdater_upg.exe" /SPAWNWND=$30308 /NOTIFYWND=$A02D2 C:\Users\admin\AppData\Local\Temp\PCHelpSoftDriverUpdater_upg.exe
PCHelpSoftDriverUpdater_upg.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
7.1.1350.0
3300"C:\Users\admin\AppData\Local\Temp\PCHelpSoftDriverUpdater_upg.exe" C:\Users\admin\AppData\Local\Temp\PCHelpSoftDriverUpdater_upg.exe
explorer.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
MEDIUM
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
7.1.1350.0
Modules
Images
c:\users\admin\appdata\local\temp\pchelpsoftdriverupdater_upg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4560\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4608"C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe" /regserverC:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exeAVGBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Browser
Exit code:
0
Version:
1.8.1693.6
Modules
Images
c:\program files (x86)\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5200"C:\Program Files (x86)\GUM5288.tmp\AVGBrowserUpdate.exe" /silent /install "bundlename=AVG Secure Browser&appguid={48F69C39-1356-4A7B-A899-70E3539D4982}&appname=AVG Secure Browser&needsadmin=true&lang=en-US&brand=9221&installargs=--no-create-user-shortcuts --auto-import-data%3Dmsedge --import-cookies"C:\Program Files (x86)\GUM5288.tmp\AVGBrowserUpdate.exe
AVGBrowserUpdateSetup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Browser
Version:
1.8.1693.6
Modules
Images
c:\program files (x86)\gum5288.tmp\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5408avg_secure_browser_setup.exe /s /run_source="avg_ppi_pc_help_du" /make-default=0C:\Users\admin\AppData\Local\Temp\avg_secure_browser_setup.exe
PCHelpSoftDriverUpdater.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Secure Browser Setup
Version:
8.11.9.7512
Modules
Images
c:\users\admin\appdata\local\temp\avg_secure_browser_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6112"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wincorlib.dll
6132"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
17 020
Read events
16 512
Write events
471
Delete events
37

Modification events

(PID) Process:(7324) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7324) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7324) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7708) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7708) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7708) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7532) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7532) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7532) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7952) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
161
Suspicious files
27
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
7532BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\392b6310-9d73-485e-9114-b46b80080747.down_data
MD5:
SHA256:
7460PCHelpSoftDriverUpdater.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\10_64[1].7z
MD5:
SHA256:
7460PCHelpSoftDriverUpdater.exeC:\Users\admin\AppData\Roaming\PC HelpSoft Driver Updater\Drivers0.7z
MD5:
SHA256:
7460PCHelpSoftDriverUpdater.exeC:\Users\admin\AppData\Roaming\PC HelpSoft Driver Updater\Drivers_ex.db
MD5:
SHA256:
7460PCHelpSoftDriverUpdater.exeC:\Users\admin\AppData\Local\Temp\etilqs_B4T8z0AdWMn6U9f
MD5:
SHA256:
7460PCHelpSoftDriverUpdater.exeC:\Users\admin\AppData\Roaming\PC HelpSoft Driver Updater\Drivers_new.db
MD5:
SHA256:
8060PCHelpSoftDriverUpdater.exeC:\Users\admin\AppData\Roaming\PC HelpSoft Driver Updater\program.logtext
MD5:7EBD6566C57EF5C5C779C82231C37F39
SHA256:739092CE47C30863375B97B4193D8A11A17DD2BC85AC6673CDA8C2AE01321BA5
7460PCHelpSoftDriverUpdater.exeC:\Windows\INF\display.PNFbinary
MD5:85A08521131CBA419035B9EC14492404
SHA256:1C61196F4D34C6C8708CFC6372C592ED9B493237F2112848B4BE04ACFCBD44AA
7532BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\f879b2b4-5015-4f9d-a46f-ef7109881779.up_meta_securebinary
MD5:B6F5F96DD2BC0CB5F4283967CF0ACBC0
SHA256:9515BDAD6505A5A947FAF01222FD10C1B17B1688ACDC2853AA963E9DD2B84D23
7460PCHelpSoftDriverUpdater.exeC:\Windows\INF\machine.PNFbinary
MD5:94A11EA53BB172E4E16CCBEFE95BCE51
SHA256:53B33367D556D6510C9C8DADF8A3F3ED2DC207CEEB2CBE2517095F16E860116C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
58
DNS requests
33
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7532
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7460
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
whitelisted
756
lsass.exe
GET
200
18.173.208.27:80
http://ocsp.r2m03.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQqHI%2BsdmapawQncL1rpCEZZ8gTSAQUVdkYX9IczAHhWLS%2Bq9lVQgHXLgICEAIZ3N4iW9BAI0lEJQIp3%2F0%3D
unknown
whitelisted
756
lsass.exe
GET
200
18.66.145.213:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
whitelisted
7460
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
whitelisted
7460
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
whitelisted
7460
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
whitelisted
7460
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
whitelisted
7804
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7804
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
40.126.31.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.31.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3008
backgroundTaskHost.exe
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2040
backgroundTaskHost.exe
20.223.35.26:443
fd.api.iris.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.174
whitelisted
login.live.com
  • 40.126.31.130
  • 20.190.159.131
  • 40.126.31.67
  • 20.190.159.0
  • 40.126.31.128
  • 20.190.159.71
  • 40.126.31.2
  • 40.126.31.71
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 184.30.131.245
whitelisted
drivers.avqtools.com
  • 116.203.251.147
unknown
offers.playanext.com
  • 99.86.4.92
  • 99.86.4.112
  • 99.86.4.23
  • 99.86.4.76
unknown

Threats

PID
Process
Class
Message
7460
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7460
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7460
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7460
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7460
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
8116
AVGBrowserUpdate.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
No debug info