| File name: | DriverUpdate-setup.exe |
| Full analysis: | https://app.any.run/tasks/c8e3cf7e-054b-4fbe-b468-94d074018796 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | December 03, 2019, 15:38:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 10FA3CC2E6F6F105005EFCC75725820B |
| SHA1: | AFAEBE6CFC278D0D2FA8A17FBC73830F898E0B57 |
| SHA256: | 1785FE1FF495DC3D62B4B66C66049462161101C60733CA91A20F3DCAE5DE1C14 |
| SSDEEP: | 12288:4ttWjN+hoYL+q64mEgAbXKTYvnqFo78Co3Nep6oA:4t0jBYr6FEHkYvb8C56oA |
| .exe | | | InstallShield setup (36.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (26.6) |
| .exe | | | Win64 Executable (generic) (23.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:07:20 16:41:24+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 344064 |
| InitializedDataSize: | 618496 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x35f50 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.8.1.0 |
| ProductVersionNumber: | 2.8.1.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Slimware Utilities Holdings, Inc. |
| FileDescription: | DriverUpdate Setup Wizard |
| FileVersion: | 2.8.1 |
| InternalName: | LittleInstaller |
| LegalCopyright: | Copyright 2011-2016 Slimware Utilities Holdings, Inc. |
| OriginalFileName: | DriverUpdate-setup.exe |
| ProductName: | DriverUpdate |
| ProductVersion: | 2.8.1 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 20-Jul-2017 14:41:24 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Slimware Utilities Holdings, Inc. |
| FileDescription: | DriverUpdate Setup Wizard |
| FileVersion: | 2.8.1 |
| InternalName: | LittleInstaller |
| LegalCopyright: | Copyright 2011-2016 Slimware Utilities Holdings, Inc. |
| OriginalFilename: | DriverUpdate-setup.exe |
| ProductName: | DriverUpdate |
| ProductVersion: | 2.8.1 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 20-Jul-2017 14:41:24 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0005307A | 0x00054000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.59771 |
.rdata | 0x00055000 | 0x00016BE4 | 0x00017000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.69908 |
.data | 0x0006C000 | 0x00007D3C | 0x00004000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.6193 |
.rsrc | 0x00074000 | 0x0006AB5A | 0x0006B000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.79436 |
.reloc | 0x000DF000 | 0x0000C524 | 0x0000D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.95882 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 3.23702 | 598 | UNKNOWN | UNKNOWN | UNKNOWN |
2 | 2.66886 | 68 | UNKNOWN | Japanese - Japan | RT_STRING |
3 | 3.91366 | 2216 | UNKNOWN | UNKNOWN | RT_ICON |
4 | 3.47151 | 1384 | UNKNOWN | UNKNOWN | RT_ICON |
7 | 4.15611 | 174 | UNKNOWN | Japanese - Japan | RT_STRING |
63 | 4.17327 | 228 | UNKNOWN | Japanese - Japan | RT_STRING |
64 | 4.69236 | 554 | UNKNOWN | Japanese - Japan | RT_STRING |
65 | 4.03979 | 212 | UNKNOWN | Japanese - Japan | RT_STRING |
66 | 4.2619 | 172 | UNKNOWN | Japanese - Japan | RT_STRING |
67 | 4.21069 | 300 | UNKNOWN | Japanese - Japan | RT_STRING |
ADVAPI32.dll |
COMCTL32.dll |
COMDLG32.dll |
CRYPT32.dll (delay-loaded) |
GDI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 284 | "C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe" | C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe | explorer.exe | ||||||||||||
User: admin Company: Slimware Utilities Holdings, Inc. Integrity Level: MEDIUM Description: SlimCleaner Plus Exit code: 0 Version: 2.8.3 Modules
| |||||||||||||||
| 348 | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 | C:\Windows\System32\csrss.exe | — | — | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Client Server Runtime Process Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 352 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 584 | C:\Windows\system32\MsiExec.exe -Embedding D9427453AD315418B8BFC4BAADB12451 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 864 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1044 | "C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.exe" -Embedding | C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: SlimWare Utilities Holdings, Inc. Integrity Level: SYSTEM Description: SlimWare.Session Server Exit code: 0 Version: 1.0.4 Modules
| |||||||||||||||
| 1248 | "C:\Users\admin\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Updates\hdd.exe" | C:\Users\admin\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Updates\hdd.exe | DriverUpdate.exe | ||||||||||||
User: admin Company: Slimware Utilities Holdings, Inc. Integrity Level: HIGH Description: DriverUpdate Setup Wizard Exit code: 0 Version: 2.14.2 Modules
| |||||||||||||||
| 1708 | "C:\Users\admin\AppData\Local\Temp\DriverUpdate-setup.exe" | C:\Users\admin\AppData\Local\Temp\DriverUpdate-setup.exe | — | explorer.exe | |||||||||||
User: admin Company: Slimware Utilities Holdings, Inc. Integrity Level: MEDIUM Description: DriverUpdate Setup Wizard Exit code: 3221226540 Version: 2.8.1 Modules
| |||||||||||||||
| 1772 | C:\Windows\system32\MsiExec.exe -Embedding 00D0DBA4B1F3DD9F59BB5CC31B8586A1 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1800 | "C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.exe" | C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.exe | — | services.exe | |||||||||||
User: SYSTEM Company: SlimWare Utilities Holdings, Inc. Integrity Level: SYSTEM Description: SlimWare.Services Service Exit code: 0 Version: 1.0.6 Modules
| |||||||||||||||
| (PID) Process: | (3756) DriverUpdate-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\SlimWare Utilities Inc |
| Operation: | write | Name: | MachineID |
Value: 36BA7363A56C93459F815111D75CE139 | |||
| (PID) Process: | (3756) DriverUpdate-setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2708) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2708) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 940A00008E99F7CEEFA9D501 | |||
| (PID) Process: | (2708) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 94667B8D24EA4BCD019D6ACDA4D1A540E6D6C0ED3C0C15C96C2A20FF23D05475 | |||
| (PID) Process: | (2708) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1772) MsiExec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | write | Name: | Owner |
Value: EC060000E079FBCFEFA9D501 | |||
| (PID) Process: | (1772) MsiExec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | write | Name: | SessionHash |
Value: A99426EC77F466196FC94D2DE959487D702491B1AED5CDD626E381DDE298BABA | |||
| (PID) Process: | (1772) MsiExec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1772) MsiExec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\DriverUpdate\DriverUpdate.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3756 | DriverUpdate-setup.exe | C:\Users\admin\AppData\Local\Temp\swuB754.tmp | — | |
MD5:— | SHA256:— | |||
| 3756 | DriverUpdate-setup.exe | C:\Users\admin\AppData\Local\Temp\swuB754.tmp.msi | — | |
MD5:— | SHA256:— | |||
| 3756 | DriverUpdate-setup.exe | C:\Users\Public\Documents\Downloaded Installers\{6E06A8AD-D979-4F59-A5FD-A10CB94057DE}\setup.msi | — | |
MD5:— | SHA256:— | |||
| 2708 | msiexec.exe | C:\Windows\Installer\3a6b81.msi | — | |
MD5:— | SHA256:— | |||
| 2708 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF128E35044C01C714.TMP | — | |
MD5:— | SHA256:— | |||
| 2708 | msiexec.exe | C:\Windows\Installer\MSI716F.tmp | — | |
MD5:— | SHA256:— | |||
| 2708 | msiexec.exe | C:\Program Files\DriverUpdate\DriverUpdate.exe | — | |
MD5:— | SHA256:— | |||
| 2708 | msiexec.exe | C:\Windows\Installer\MSI6EBD.tmp | executable | |
MD5:— | SHA256:— | |||
| 864 | svchost.exe | C:\Windows\appcompat\programs\RecentFileCache.bcf | txt | |
MD5:— | SHA256:— | |||
| 2708 | msiexec.exe | C:\Windows\Installer\MSI7064.tmp | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3156 | scp6577.tmp.exe | GET | 200 | 54.164.207.74:80 | http://stc.slimwareutilities.com/gettrack?product=SW1&p2=%5ESW2%5Exdm887%5E%5E&secondOfferOrigin=%5ESW1%5Exdm111&ul_stubid=fb362fb5-80c4-4190-886b-50c227015bfe | US | — | — | shared |
3756 | DriverUpdate-setup.exe | GET | 200 | 143.204.208.33:80 | http://download.driverupdate.net/6.1/x86/DriverUpdate-setup.msi.bz2 | US | compressed | 7.27 Mb | shared |
3156 | scp6577.tmp.exe | GET | 200 | 143.204.208.9:80 | http://cdn.slimcleaner.com/downloads/scplus/SlimCleanerPlus_en-US_x86_Silent.exe | US | executable | 17.2 Mb | whitelisted |
3748 | DriverUpdate.exe | POST | 404 | 54.158.10.23:80 | http://apps-api.slimwareutilities.com/v1/AutoActivate | US | html | 162 b | malicious |
3756 | DriverUpdate-setup.exe | GET | 200 | 34.236.116.104:80 | http://trk.slimwareutilities.com/ulc.php?ev=InstallerAccepted&upl=YToxMDp7czo5OiJ1bF9zdHViaWQiO3M6MzY6ImZiMzYyZmI1LTgwYzQtNDE5MC04ODZiLTUwYzIyNzAxNWJmZSI7czoxMDoidWxfY29icmFuZCI7czozOiJTVzIiO3M6MTE6InVsX2NhbXBhaWduIjtzOjY6InhkbTg4NyI7czo4OiJ1bF9zdWJpZCI7czoyNjoiQ0xlQnU1dWdoTllDRllRVzB3b2RIR2tHX0EiO3M6NzoicHJvZHVjdCI7czozOiJTVzIiO3M6MTE6ImJyb3dzZXJUeXBlIjtzOjQ6IkVkZ2UiO3M6MTQ6ImJyb3dzZXJWZXJzaW9uIjtzOjg6IjE1LjE1MDYzIjtzOjE1OiJicm93c2VyTGFuZ3VhZ2UiO3M6NToiZW4tZ2IiO3M6MTA6InBsYXRmb3JtT1MiO3M6NzoiV2luZG93cyI7czoxNzoicGxhdGZvcm1PU1ZlcnNpb24iO3M6NDoiMTAuMCI7fQ%3D%3D&machineId=6373BA36-6CA5-4593-9F81-5111D75CE139&productVersion=2.8.1 | US | text | 2 b | malicious |
3156 | scp6577.tmp.exe | GET | 200 | 52.7.3.6:80 | http://trk.slimwareutilities.com/ulc.php?ev=InstallerInvoked&platformOSVersion=6.1&secondOfferOrigin=%5ESW1%5Exdm111&ul_stubid=fb362fb5-80c4-4190-886b-50c227015bfe&p2=%5ESW2%5Exdm887%5E%5E&installer=SD0&product=SW1&installerVersion=2.4.1&machineId=6373BA36-6CA5-4593-9F81-5111D75CE139&platformOS=Windows | US | text | 2 b | malicious |
3756 | DriverUpdate-setup.exe | GET | 200 | 34.236.116.104:80 | http://trk.slimwareutilities.com/ulc.php?ev=InstallerInvoked&upl=YToxMDp7czo5OiJ1bF9zdHViaWQiO3M6MzY6ImZiMzYyZmI1LTgwYzQtNDE5MC04ODZiLTUwYzIyNzAxNWJmZSI7czoxMDoidWxfY29icmFuZCI7czozOiJTVzIiO3M6MTE6InVsX2NhbXBhaWduIjtzOjY6InhkbTg4NyI7czo4OiJ1bF9zdWJpZCI7czoyNjoiQ0xlQnU1dWdoTllDRllRVzB3b2RIR2tHX0EiO3M6NzoicHJvZHVjdCI7czozOiJTVzIiO3M6MTE6ImJyb3dzZXJUeXBlIjtzOjQ6IkVkZ2UiO3M6MTQ6ImJyb3dzZXJWZXJzaW9uIjtzOjg6IjE1LjE1MDYzIjtzOjE1OiJicm93c2VyTGFuZ3VhZ2UiO3M6NToiZW4tZ2IiO3M6MTA6InBsYXRmb3JtT1MiO3M6NzoiV2luZG93cyI7czoxNzoicGxhdGZvcm1PU1ZlcnNpb24iO3M6NDoiMTAuMCI7fQ%3D%3D&machineId=6373BA36-6CA5-4593-9F81-5111D75CE139&productVersion=2.8.1&msBclVersion=4.7.0 | US | text | 2 b | malicious |
3756 | DriverUpdate-setup.exe | GET | 200 | 143.204.208.9:80 | http://cdn.slimcleaner.com/downloads/scplus/SlimCleanerPlus.x86.Downloader.exe.bz2 | US | compressed | 135 Kb | whitelisted |
3116 | SlimWare.Session.exe | GET | 200 | 52.7.3.6:80 | http://trk.slimwareutilities.com/ulc.php?ev=Startup&platformOSVersion=6.1&installId=5E53D10E-5C60-42EB-B51E-3C567E531950&browser=edge&productVersion=5.1.1&product=SW2&hasUI=no&upl=YToxMDp7czo5OiJ1bF9zdHViaWQiO3M6MzY6ImZiMzYyZmI1LTgwYzQtNDE5MC04ODZiLTUwYzIyNzAxNWJmZSI7czoxMDoidWxfY29icmFuZCI7czozOiJTVzIiO3M6MTE6InVsX2NhbXBhaWduIjtzOjY6InhkbTg4NyI7czo4OiJ1bF9zdWJpZCI7czoyNjoiQ0xlQnU1dWdoTllDRllRVzB3b2RIR2tHX0EiO3M6NzoicHJvZHVjdCI7czozOiJTVzIiO3M6MTE6ImJyb3dzZXJUeXBlIjtzOjQ6IkVkZ2UiO3M6MTQ6ImJyb3dzZXJWZXJzaW9uIjtzOjg6IjE1LjE1MDYzIjtzOjE1OiJicm93c2VyTGFuZ3VhZ2UiO3M6NToiZW4tZ2IiO3M6MTA6InBsYXRmb3JtT1MiO3M6NzoiV2luZG93cyI7czoxNzoicGxhdGZvcm1PU1ZlcnNpb24iO3M6NDoiMTAuMCI7fQ%3D%3D&machineId=6373BA36-6CA5-4593-9F81-5111D75CE139&isRegistered=no&platformOS=Windows&eventSource=SYSTEM | US | text | 2 b | malicious |
3748 | DriverUpdate.exe | GET | 200 | 205.185.216.10:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.4 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3756 | DriverUpdate-setup.exe | 34.236.116.104:80 | trk.slimwareutilities.com | Amazon.com, Inc. | US | malicious |
3756 | DriverUpdate-setup.exe | 143.204.208.9:80 | cdn.slimcleaner.com | — | US | suspicious |
3756 | DriverUpdate-setup.exe | 143.204.208.33:80 | download.driverupdate.net | — | US | suspicious |
3748 | DriverUpdate.exe | 54.158.10.23:80 | apps-api.slimwareutilities.com | Amazon.com, Inc. | US | malicious |
3748 | DriverUpdate.exe | 205.185.216.10:80 | www.download.windowsupdate.com | Highwinds Network Group, Inc. | US | whitelisted |
3748 | DriverUpdate.exe | 52.72.12.18:443 | driverrpc.driverupdate.net | Amazon.com, Inc. | US | unknown |
3156 | scp6577.tmp.exe | 54.164.207.74:80 | stc.slimwareutilities.com | Amazon.com, Inc. | US | malicious |
3116 | SlimWare.Session.exe | 52.7.3.6:80 | trk.slimwareutilities.com | Amazon.com, Inc. | US | malicious |
3156 | scp6577.tmp.exe | 143.204.208.9:80 | cdn.slimcleaner.com | — | US | suspicious |
3748 | DriverUpdate.exe | 34.232.249.166:80 | www.driverupdate.net | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
trk.slimwareutilities.com |
| unknown |
download.driverupdate.net |
| shared |
cdn.slimcleaner.com |
| whitelisted |
apps-api.slimwareutilities.com |
| malicious |
driverrpc.driverupdate.net |
| unknown |
www.download.windowsupdate.com |
| whitelisted |
stc.slimwareutilities.com |
| shared |
www.driverupdate.net |
| unknown |
www.slimware.com |
| unknown |
slimware.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
3756 | DriverUpdate-setup.exe | Generic Protocol Command Decode | SURICATA HTTP Request abnormal Content-Encoding header |
3756 | DriverUpdate-setup.exe | Misc activity | ADWARE [PTsecurity] Win32/Slimware.A potentially unwanted Checkin |
3756 | DriverUpdate-setup.exe | Generic Protocol Command Decode | SURICATA HTTP Request abnormal Content-Encoding header |
3756 | DriverUpdate-setup.exe | Misc activity | ADWARE [PTsecurity] Win32/Slimware.A potentially unwanted Checkin |
3756 | DriverUpdate-setup.exe | Generic Protocol Command Decode | SURICATA HTTP Request abnormal Content-Encoding header |
3756 | DriverUpdate-setup.exe | Misc activity | ADWARE [PTsecurity] Win32/Slimware.A potentially unwanted Checkin |
3748 | DriverUpdate.exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.DriverUpdate |
3756 | DriverUpdate-setup.exe | Generic Protocol Command Decode | SURICATA HTTP Request abnormal Content-Encoding header |
3756 | DriverUpdate-setup.exe | Misc activity | ADWARE [PTsecurity] Win32/Slimware.A potentially unwanted Checkin |
3116 | SlimWare.Session.exe | Generic Protocol Command Decode | SURICATA HTTP Request abnormal Content-Encoding header |
Process | Message |
|---|---|
DriverUpdate-setup.exe | Failed to load SetDefaultDlLDirectories
|
DriverUpdate-setup.exe | Failed to load SetDefaultDlLDirectories
|
DriverUpdate-setup.exe | Loading C:\Windows\system32\BCRYPT.DLL
|
DriverUpdate-setup.exe | Loading C:\Windows\system32\RSAENH.DLL
|
DriverUpdate-setup.exe | Loading C:\Windows\system32\CRYPT32.DLL
|
DriverUpdate-setup.exe | Loading C:\Windows\system32\USERENV.DLL
|
DriverUpdate-setup.exe | Loading C:\Windows\system32\USERENV.DLL
|
DriverUpdate-setup.exe | Loading C:\Windows\system32\WINTRUST.DLL
|
DriverUpdate-setup.exe | Loading C:\Windows\system32\GDIPLUS.DLL
|
DriverUpdate-setup.exe | Loading C:\Windows\system32\MSI.DLL
|