File name:

Driver_Updater_setup.exe

Full analysis: https://app.any.run/tasks/8d3c88fd-70bc-432b-88ab-052e4a78b4c5
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: March 07, 2025, 08:34:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
delphi
inno
installer
adware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

B8FF763A66EF51EF79636D5F725B7B31

SHA1:

66479AED07A5AFCD65D7C8D8D1F1C7FD8A7AA120

SHA256:

153218D7B79FE58998370BF4E5165F7F69AD38E71BD9C9CB16F7FD1FEC558BAC

SSDEEP:

98304:c+cD4dnhX+zQXNlC9R3qOVM020Cwi2GNXGQwx07jQ8kRnsMQK9j6yvddeUzWSu/s:OvGgZwIkUz03o

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADWARE has been detected (SURICATA)

      • PCHelpSoftDriverUpdater.exe (PID: 5892)
    • Actions looks like stealing of personal data

      • avg_secure_browser_setup.exe (PID: 4944)
    • Steals credentials from Web Browsers

      • avg_secure_browser_setup.exe (PID: 4944)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Driver_Updater_setup.exe (PID: 6972)
      • Driver_Updater_setup.exe (PID: 3768)
      • Driver_Updater_setup.tmp (PID: 6036)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • avg_secure_browser_setup.exe (PID: 4944)
      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • Reads the Windows owner or organization settings

      • Driver_Updater_setup.tmp (PID: 6036)
    • Reads security settings of Internet Explorer

      • Driver_Updater_setup.tmp (PID: 4980)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • PCHelpSoftDriverUpdater.exe (PID: 7408)
      • ShellExperienceHost.exe (PID: 2040)
      • avg_secure_browser_setup.exe (PID: 4944)
    • Drops 7-zip archiver for unpacking

      • Driver_Updater_setup.tmp (PID: 6036)
    • Application launched itself

      • PCHelpSoftDriverUpdater.exe (PID: 5892)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 7588)
      • schtasks.exe (PID: 7628)
    • Access to an unwanted program domain was detected

      • PCHelpSoftDriverUpdater.exe (PID: 5892)
    • Reads the BIOS version

      • avg_secure_browser_setup.exe (PID: 4944)
    • The process verifies whether the antivirus software is installed

      • avg_secure_browser_setup.exe (PID: 4944)
    • Starts itself from another location

      • AVGBrowserUpdate.exe (PID: 2432)
    • Creates/Modifies COM task schedule object

      • AVGBrowserUpdate.exe (PID: 7984)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 1052)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7356)
    • Executes as Windows Service

      • AVGBrowserUpdate.exe (PID: 4776)
    • Potential Corporate Privacy Violation

      • AVGBrowserUpdate.exe (PID: 4776)
    • Process requests binary or script from the Internet

      • AVGBrowserUpdate.exe (PID: 4776)
  • INFO

    • Checks supported languages

      • Driver_Updater_setup.tmp (PID: 4980)
      • Driver_Updater_setup.exe (PID: 3768)
      • Driver_Updater_setup.tmp (PID: 6036)
      • Driver_Updater_setup.exe (PID: 6972)
      • PCHelpSoftDriverUpdater.exe (PID: 7408)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • DriverPro.exe (PID: 7380)
      • PCHelpSoftDriverUpdater.exe (PID: 7704)
      • avg_secure_browser_setup.exe (PID: 4944)
      • ShellExperienceHost.exe (PID: 2040)
      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
      • AVGBrowserUpdate.exe (PID: 6036)
      • AVGBrowserUpdate.exe (PID: 7984)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 1052)
      • AVGBrowserUpdateComRegisterShell64.exe (PID: 7356)
      • AVGBrowserUpdate.exe (PID: 4812)
      • AVGBrowserUpdate.exe (PID: 4776)
    • Reads the computer name

      • Driver_Updater_setup.tmp (PID: 4980)
      • Driver_Updater_setup.tmp (PID: 6036)
      • PCHelpSoftDriverUpdater.exe (PID: 7408)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • DriverPro.exe (PID: 7380)
      • PCHelpSoftDriverUpdater.exe (PID: 7704)
      • AVGBrowserUpdate.exe (PID: 4776)
      • AVGBrowserUpdate.exe (PID: 6036)
    • Process checks computer location settings

      • Driver_Updater_setup.tmp (PID: 4980)
      • PCHelpSoftDriverUpdater.exe (PID: 7408)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • PCHelpSoftDriverUpdater.exe (PID: 7704)
      • avg_secure_browser_setup.exe (PID: 4944)
      • AVGBrowserUpdate.exe (PID: 2432)
    • Create files in a temporary directory

      • Driver_Updater_setup.exe (PID: 3768)
      • Driver_Updater_setup.tmp (PID: 6036)
      • Driver_Updater_setup.exe (PID: 6972)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • avg_secure_browser_setup.exe (PID: 4944)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7456)
      • BackgroundTransferHost.exe (PID: 7672)
      • BackgroundTransferHost.exe (PID: 7844)
      • BackgroundTransferHost.exe (PID: 8060)
      • BackgroundTransferHost.exe (PID: 1244)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 7672)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • avg_secure_browser_setup.exe (PID: 4944)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 7672)
      • PCHelpSoftDriverUpdater.exe (PID: 7704)
      • PCHelpSoftDriverUpdater.exe (PID: 7408)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 7672)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • slui.exe (PID: 5048)
      • avg_secure_browser_setup.exe (PID: 4944)
      • AVGBrowserUpdate.exe (PID: 7544)
    • Detects InnoSetup installer (YARA)

      • Driver_Updater_setup.tmp (PID: 6036)
      • Driver_Updater_setup.tmp (PID: 4980)
      • Driver_Updater_setup.exe (PID: 3768)
      • Driver_Updater_setup.exe (PID: 6972)
    • Compiled with Borland Delphi (YARA)

      • Driver_Updater_setup.exe (PID: 6972)
      • Driver_Updater_setup.tmp (PID: 4980)
      • Driver_Updater_setup.exe (PID: 3768)
      • Driver_Updater_setup.tmp (PID: 6036)
      • PCHelpSoftDriverUpdater.exe (PID: 5892)
    • Creates files in the program directory

      • Driver_Updater_setup.tmp (PID: 6036)
      • DriverPro.exe (PID: 7380)
    • The sample compiled with english language support

      • Driver_Updater_setup.tmp (PID: 6036)
      • avg_secure_browser_setup.exe (PID: 4944)
      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • Creates a software uninstall entry

      • Driver_Updater_setup.tmp (PID: 6036)
    • Reads the machine GUID from the registry

      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • avg_secure_browser_setup.exe (PID: 4944)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 5892)
    • The sample compiled with arabic language support

      • PCHelpSoftDriverUpdater.exe (PID: 5892)
      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • Reads Environment values

      • avg_secure_browser_setup.exe (PID: 4944)
    • The sample compiled with bulgarian language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with czech language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with german language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with Indonesian language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with french language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with Italian language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with japanese language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with korean language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with portuguese language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with slovak language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with swedish language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with chinese language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with russian language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with turkish language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
    • The sample compiled with polish language support

      • AVGBrowserUpdateSetup.exe (PID: 7664)
      • AVGBrowserUpdate.exe (PID: 2432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 68096
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.1.1350.0
ProductVersionNumber: 7.1.1350.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: PC HelpSoft
FileDescription: PC HelpSoft Driver Updater
FileVersion: 7.1.1350.0
LegalCopyright: PC HelpSoft
OriginalFileName:
ProductName: PC HelpSoft Driver Updater
ProductVersion: 7.1.1350.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
173
Monitored processes
32
Malicious processes
7
Suspicious processes
3

Behavior graph

Click at the process to see the details
start driver_updater_setup.exe driver_updater_setup.tmp no specs driver_updater_setup.exe driver_updater_setup.tmp sppextcomobj.exe no specs slui.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs pchelpsoftdriverupdater.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs #ADWARE pchelpsoftdriverupdater.exe driverpro.exe no specs pchelpsoftdriverupdater.exe no specs shellexperiencehost.exe no specs slui.exe avg_secure_browser_setup.exe avgbrowserupdatesetup.exe avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdatecomregistershell64.exe no specs avgbrowserupdate.exe avgbrowserupdate.exe no specs avgbrowserupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
896C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1052"C:\Program Files (x86)\AVG\Browser\Update\1.8.1693.6\AVGBrowserUpdateComRegisterShell64.exe" C:\Program Files (x86)\AVG\Browser\Update\1.8.1693.6\AVGBrowserUpdateComRegisterShell64.exeAVGBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Browser Com Register Shell 64
Exit code:
0
Version:
1.8.1693.6
Modules
Images
c:\program files (x86)\avg\browser\update\1.8.1693.6\avgbrowserupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1244"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
1280"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2040"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wincorlib.dll
2432"C:\Program Files (x86)\GUM1187.tmp\AVGBrowserUpdate.exe" /silent /install "bundlename=AVG Secure Browser&appguid={48F69C39-1356-4A7B-A899-70E3539D4982}&appname=AVG Secure Browser&needsadmin=true&lang=en-US&brand=9221&installargs=--no-create-user-shortcuts --auto-import-data%3Dmsedge --import-cookies"C:\Program Files (x86)\GUM1187.tmp\AVGBrowserUpdate.exe
AVGBrowserUpdateSetup.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Browser
Version:
1.8.1693.6
Modules
Images
c:\program files (x86)\gum1187.tmp\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3768"C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe" /SPAWNWND=$402A2 /NOTIFYWND=$A02DA C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe
Driver_Updater_setup.tmp
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater
Exit code:
0
Version:
7.1.1350.0
Modules
Images
c:\users\admin\appdata\local\temp\driver_updater_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4776"C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe" /svcC:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe
services.exe
User:
SYSTEM
Company:
Gen Digital Inc.
Integrity Level:
SYSTEM
Description:
AVG Browser
Version:
1.8.1693.6
Modules
Images
c:\program files (x86)\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
4812"C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe" /handoff "bundlename=AVG Secure Browser&appguid={48F69C39-1356-4A7B-A899-70E3539D4982}&appname=AVG Secure Browser&needsadmin=true&lang=en-US&brand=9221&installargs=--no-create-user-shortcuts --auto-import-data%3Dmsedge --import-cookies" /installsource otherinstallcmd /sessionid "{0AFF3735-A905-4896-B1E2-03F830D134CC}" /silentC:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exeAVGBrowserUpdate.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Browser
Version:
1.8.1693.6
Modules
Images
c:\program files (x86)\avg\browser\update\avgbrowserupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4944avg_secure_browser_setup.exe /s /run_source="avg_ppi_pc_help_du" /make-default=0C:\Users\admin\AppData\Local\Temp\avg_secure_browser_setup.exe
PCHelpSoftDriverUpdater.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
AVG Secure Browser Setup
Version:
8.11.9.7512
Modules
Images
c:\users\admin\appdata\local\temp\avg_secure_browser_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
17 578
Read events
17 163
Write events
377
Delete events
38

Modification events

(PID) Process:(7456) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7456) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7456) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7672) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7672) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7672) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7844) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7844) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7844) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1244) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
181
Suspicious files
36
Text files
101
Unknown types
0

Dropped files

PID
Process
Filename
Type
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\89d283f9-ebbd-436b-b5c7-42df3524e0f4.down_data
MD5:
SHA256:
6036Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\unins000.exeexecutable
MD5:8E6C55BBBAC8810FFA09748FFC755C69
SHA256:4A9961D6C361F64D11C8BDF759F476176F4709BED93C8F0648C25DCAE028ED86
3768Driver_Updater_setup.exeC:\Users\admin\AppData\Local\Temp\is-FBFDO.tmp\Driver_Updater_setup.tmpexecutable
MD5:8E6C55BBBAC8810FFA09748FFC755C69
SHA256:4A9961D6C361F64D11C8BDF759F476176F4709BED93C8F0648C25DCAE028ED86
6972Driver_Updater_setup.exeC:\Users\admin\AppData\Local\Temp\is-T6KRV.tmp\Driver_Updater_setup.tmpexecutable
MD5:8E6C55BBBAC8810FFA09748FFC755C69
SHA256:4A9961D6C361F64D11C8BDF759F476176F4709BED93C8F0648C25DCAE028ED86
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:4A2AAA78FC621098326BAC01EEB20F01
SHA256:722DFFC75DC2B9B1821F25E1D0E3427360100209D9672C56A9459AEEB6AF8CE0
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\2a8bb3f5-5067-46c3-aa5b-72186d5815fe.6c942d35-31c4-467b-98cb-11869292c4a6.down_metabinary
MD5:316F9D82B93AAE16A42E2E4EC43A6191
SHA256:982A8EB963D2BBE73397BF2F04F181532D84D525609F582025D9D6DE9414127C
6036Driver_Updater_setup.tmpC:\Users\admin\AppData\Local\Temp\is-SU62B.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6036Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\is-LEQPE.tmpexecutable
MD5:8E6C55BBBAC8810FFA09748FFC755C69
SHA256:4A9961D6C361F64D11C8BDF759F476176F4709BED93C8F0648C25DCAE028ED86
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\89d283f9-ebbd-436b-b5c7-42df3524e0f4.6c942d35-31c4-467b-98cb-11869292c4a6.down_metabinary
MD5:316F9D82B93AAE16A42E2E4EC43A6191
SHA256:982A8EB963D2BBE73397BF2F04F181532D84D525609F582025D9D6DE9414127C
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:38989CDC9B939CBF439472EC8FEBE5D7
SHA256:0188CCDAB61284075618619F99DBB9FC9BA066DF5B1FF02EC5684476CABA0732
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
61
DNS requests
32
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
300
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7672
BackgroundTransferHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5892
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
whitelisted
756
lsass.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
whitelisted
756
lsass.exe
GET
200
18.245.65.219:80
http://ocsp.r2m03.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQqHI%2BsdmapawQncL1rpCEZZ8gTSAQUVdkYX9IczAHhWLS%2Bq9lVQgHXLgICEAIZ3N4iW9BAI0lEJQIp3%2F0%3D
unknown
whitelisted
7540
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7540
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5892
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
whitelisted
5892
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
300
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
300
backgroundTaskHost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7672
BackgroundTransferHost.exe
92.123.104.65:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.184.238
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.160.22
  • 20.190.160.4
  • 20.190.160.67
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.76
  • 40.126.32.140
  • 20.190.160.65
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
www.bing.com
  • 92.123.104.65
  • 92.123.104.7
  • 92.123.104.12
  • 92.123.104.14
  • 92.123.104.67
  • 92.123.104.5
  • 92.123.104.17
  • 92.123.104.13
  • 92.123.104.4
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
drivers.avqtools.com
  • 116.203.251.147
unknown
www.microsoft.com
  • 95.101.149.131
whitelisted

Threats

PID
Process
Class
Message
5892
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
5892
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
5892
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
5892
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
5892
PCHelpSoftDriverUpdater.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
4776
AVGBrowserUpdate.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
No debug info