| File name: | DefenderRemover.exe |
| Full analysis: | https://app.any.run/tasks/24df1f53-a30a-46b3-a73a-c5aa3a8061bf |
| Verdict: | Malicious activity |
| Analysis date: | October 22, 2023, 02:16:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 0CA124641117A60490958117D60B3CED |
| SHA1: | 73ACE6C707D29E2D16E8385AE9C17BA4142D0917 |
| SHA256: | 19C09FAD30C786CC22FB38D3F97021C0B35AAA9CD288D44970A45B5D1CB86070 |
| SSDEEP: | 24576:+hUhnNLRsf4mZQjzbQOLIArg79Ie2cLKifsRHFhU4Ccqpzz4hzh0:+hUhnNLWf4mZQjzcOLIArg79Ie2cLKib |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:11:18 17:27:35+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 104960 |
| InitializedDataSize: | 91136 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x14b04 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.5.6.0 |
| ProductVersionNumber: | 12.5.6.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Gallery Inc |
| FileDescription: | Defender Remover |
| FileVersion: | 12.5.6 |
| LegalCopyright: | Gallery Inc. |
| ProductName: | Defender Remover |
| ProductVersion: | 12.5.6 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 148 | taskkill.exe /f /im "SecurityHealthSystray.exe" | C:\Windows\System32\taskkill.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 372 | "C:\Users\admin\AppData\Local\Temp\DefenderRemover.exe" | C:\Users\admin\AppData\Local\Temp\DefenderRemover.exe | — | explorer.exe | |||||||||||
User: admin Company: Gallery Inc Integrity Level: MEDIUM Description: Defender Remover Exit code: 3221226540 Version: 12.5.6 Modules
| |||||||||||||||
| 552 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 Modules
| |||||||||||||||
| 776 | C:\Windows\system32\sipnotify.exe -LogonOrUnlock | C:\Windows\System32\sipnotify.exe | — | taskeng.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: sipnotify Exit code: 0 Version: 6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716) Modules
| |||||||||||||||
| 1880 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 Modules
| |||||||||||||||
| 1928 | taskkill.exe /f /im "smartscreen.exe" | C:\Windows\System32\taskkill.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2504 | C:\Windows\system32\cmd.exe /c .\Script_Run.bat | C:\Windows\System32\cmd.exe | — | DefenderRemover.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2592 | taskkill.exe /f /im "explorer.exe" | C:\Windows\System32\taskkill.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2628 | taskkill.exe /f /im "CompatTelRunner.exe" | C:\Windows\System32\taskkill.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2708 | taskkill.exe /f /im "MsMpEng.exe" | C:\Windows\System32\taskkill.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1880) IMEKLMG.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\IMEJP\14.0 |
| Operation: | write | Name: | SetPreload |
Value: 1 | |||
| (PID) Process: | (552) IMEKLMG.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\IMEKR\14.0 |
| Operation: | write | Name: | SetPreload |
Value: 1 | |||
| (PID) Process: | (776) sipnotify.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3808) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{069C3E2E-1475-4C7C-807F-825FD013EEE9}\{99B9D879-3B18-4E14-8EC9-714219FE5D0B} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3808) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E64E2FF4-6241-4299-8EC1-2B46F6DA71B7}\{99B9D879-3B18-4E14-8EC9-714219FE5D0B} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3808) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E64E2FF4-6241-4299-8EC1-2B46F6DA71B7} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3808) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{069C3E2E-1475-4C7C-807F-825FD013EEE9} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3808) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{2D0359F0-0873-4314-9D7A-C3B47B2EB783} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3304) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9B6B7F81-C3B6-45F6-A698-3293772B0432}\{99B9D879-3B18-4E14-8EC9-714219FE5D0B} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3304) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9B6B7F81-C3B6-45F6-A698-3293772B0432}\{C860D197-F12B-4F0B-8E4D-E7BBFC9E5D46} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\app_icon.ico | image | |
MD5:7D5F541A9A9D34F590D7B2D6EC0679C9 | SHA256:41E74B6217B1E44F8EA07EDC3C2677E28EEFCDF84E0B8A8299FE7601840B15BA | |||
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Disabler\Disable.reg | text | |
MD5:829F09083D98F7997276052600B46CDB | SHA256:0CD173050E2C8DC4C57FAD2CB2DD539E8B2EC240C83CC1D0EAAD06686FF05FC6 | |||
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\license | text | |
MD5:B7D8C78F833C8E135126A40AF0A61EFD | SHA256:B39F865F1B11CFFEC80DB73944CDCA7B578EB4581316302B1A8EC9312E584F29 | |||
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\README.md | text | |
MD5:04D3BF0CE437FFE372DC6677D7550930 | SHA256:3A7CE9A038E9AF620122868C492D10E691B97469E56B8A4B0BF8DD64E4A4478B | |||
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Disabler\Enable.reg | text | |
MD5:756C953F88FF4CC6909A8F95DEEDB93C | SHA256:B3D07AAEA97D861C1D7354409896E326C42A3702491B1B6A89986BC63F44D274 | |||
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\DisablerS\Enable.reg | text | |
MD5:62DE041AA55EC42385B147C8ED78497F | SHA256:6A3C6CA0DF2BB5A67B1D7348F6D6B22023E0D9839FEEC9393DB1C0B4BA767D88 | |||
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\REGS\Antivirus_d.reg | text | |
MD5:24931D8EE11E4410C19CFDD37CD0E18C | SHA256:6B305D80101FAC4333095FED6B3F88403D1B097E9DDA6A8157AF5DD38615F343 | |||
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\FDL.txt | text | |
MD5:2307412AED450AF11898C14C41DD352C | SHA256:6D7A32E601EE3061B7244ADE529C5508C0667DB866BAD8EFFBCA0B88D1F0747C | |||
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\REGS\Disable Antivirus Protection.reg | text | |
MD5:1ED85B1FD58EAF5B12F230E9F861EFA5 | SHA256:BB5E1CD5973932797A7C3C1706255C7314FD0843558CE270E296C735C1BB256F | |||
| 3328 | DefenderRemover.exe | C:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\DisablerS\Disable.reg | text | |
MD5:4C1B99671D4DFDAB576F815F68703407 | SHA256:9CE7E4665026E6FCD3BB0178F37F251652109DFCAB25B90C968801A8494DBB45 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 200 | 23.212.215.38:80 | http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133424182173750000 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
— | — | 23.212.215.38:80 | query.prod.cms.rt.microsoft.com | AKAMAI-AS | AU | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
— | — | 239.255.255.250:1900 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
query.prod.cms.rt.microsoft.com |
| whitelisted |