File name:

QQBrowser_Setup_qb10.exe

Full analysis: https://app.any.run/tasks/c5297ca6-cb30-4c35-8720-61bc0d4445ae
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: January 13, 2024, 18:21:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
sogou
qrcode
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

493A532F0A397B3FBBB040F75C869616

SHA1:

B8030E0270D8F0931B20C6E21BC292099812D9A6

SHA256:

305D695D8446E772403D21B9644B1736C7AE37BA59BE89DF43B540156CA379DD

SSDEEP:

49152:yx+73OfHRyZaeKzBfWIYKpzAge5EKmBtzXoCjV0j5M0RHARb7ZRER8aiYBcKHUDT:yqwIRWFp0ge5E/Lz4C50jhgRHPEqbYiv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 1528)
      • icacls.exe (PID: 2168)
      • icacls.exe (PID: 1784)
      • QQBrowser.exe (PID: 2592)
      • QQBrowser.exe (PID: 2560)
      • QQBrowser.exe (PID: 2844)
      • QQBrowser.exe (PID: 2832)
      • QQBrowser.exe (PID: 3072)
      • QQBrowser.exe (PID: 3068)
      • QQBrowser.exe (PID: 948)
      • QQBrowser.exe (PID: 968)
      • QQBrowser.exe (PID: 2964)
      • QQBrowser.exe (PID: 3328)
      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 3492)
      • QQBrowser.exe (PID: 3516)
      • QQBrowser.exe (PID: 3676)
      • QQBrowser.exe (PID: 3668)
      • QQBrowser.exe (PID: 3740)
      • QQBrowser.exe (PID: 3908)
      • QQBrowser.exe (PID: 4032)
      • QQBrowser.exe (PID: 1604)
      • QQBrowser.exe (PID: 1836)
      • QQBrowser.exe (PID: 1344)
      • QQBrowser.exe (PID: 1316)
      • QQBrowser.exe (PID: 3808)
      • QQBrowser.exe (PID: 4088)
      • QQBrowser.exe (PID: 3464)
      • QQBrowser.exe (PID: 3444)
      • QQBrowser.exe (PID: 1832)
      • QQBrowser.exe (PID: 3556)
      • QQBrowser.exe (PID: 3952)
      • QQBrowser.exe (PID: 2620)
      • QQBrowser.exe (PID: 3268)
      • QQBrowser.exe (PID: 4072)
      • QQBrowser.exe (PID: 3232)
      • QQBrowser.exe (PID: 2444)
      • QQBrowser.exe (PID: 2904)
      • QQBrowser.exe (PID: 1924)
      • regsvr32.exe (PID: 1776)
      • QQBrowser.exe (PID: 2072)
      • QQBrowser.exe (PID: 3636)
      • QQBrowser.exe (PID: 3736)
      • TsService.exe (PID: 2832)
      • QQBrowser.exe (PID: 1540)
      • QQBrowserLiveup.exe (PID: 3604)
      • QQBrowser.exe (PID: 3648)
      • QQBrowser.exe (PID: 3888)
      • TsService.exe (PID: 3536)
      • QQBrowser.exe (PID: 2868)
      • QQBrowser.exe (PID: 1016)
      • QQBrowser.exe (PID: 3948)
      • QQBrowser.exe (PID: 1932)
      • QQBrowser.exe (PID: 3304)
      • QQBrowser.exe (PID: 1852)
    • Drops the executable file immediately after the start

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 3808)
      • QQBrowser.exe (PID: 1832)
      • QQBrowser.exe (PID: 1852)
    • Steals credentials from Web Browsers

      • QQBrowser.exe (PID: 1852)
    • Creates a writable file in the system directory

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • TsService.exe (PID: 3536)
    • Registers / Runs the DLL via REGSVR32.EXE

      • QQBrowser_Setup_qb10.exe (PID: 2416)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 2444)
      • QQBrowserLiveup.exe (PID: 3604)
    • Process drops legitimate windows executable

      • QQBrowser_Setup_qb10.exe (PID: 2416)
    • Uses ICACLS.EXE to modify access control lists

      • QQBrowser_Setup_qb10.exe (PID: 2416)
    • Executable content was dropped or overwritten

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 3808)
      • QQBrowser.exe (PID: 1832)
    • The process verifies whether the antivirus software is installed

      • icacls.exe (PID: 1784)
      • icacls.exe (PID: 2168)
      • QQBrowser.exe (PID: 2592)
      • QQBrowser.exe (PID: 2560)
      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 1528)
      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 2844)
      • QQBrowser.exe (PID: 2832)
      • QQBrowser.exe (PID: 3072)
      • QQBrowser.exe (PID: 3068)
      • QQBrowser.exe (PID: 948)
      • QQBrowser.exe (PID: 2964)
      • QQBrowser.exe (PID: 968)
      • QQBrowser.exe (PID: 3328)
      • QQBrowser.exe (PID: 3516)
      • QQBrowser.exe (PID: 3492)
      • QQBrowser.exe (PID: 3676)
      • QQBrowser.exe (PID: 3668)
      • QQBrowser.exe (PID: 3740)
      • QQBrowser.exe (PID: 3908)
      • QQBrowser.exe (PID: 4032)
      • QQBrowser.exe (PID: 1604)
      • QQBrowser.exe (PID: 1836)
      • QQBrowser.exe (PID: 1316)
      • QQBrowser.exe (PID: 3808)
      • QQBrowser.exe (PID: 4088)
      • QQBrowser.exe (PID: 1344)
      • QQBrowser.exe (PID: 3444)
      • QQBrowser.exe (PID: 3556)
      • QQBrowser.exe (PID: 3464)
      • QQBrowser.exe (PID: 1832)
      • QQBrowser.exe (PID: 3952)
      • QQBrowser.exe (PID: 4072)
      • QQBrowser.exe (PID: 2620)
      • QQBrowser.exe (PID: 2444)
      • QQBrowser.exe (PID: 3268)
      • QQBrowser.exe (PID: 1924)
      • QQBrowser.exe (PID: 3232)
      • QQBrowser.exe (PID: 2904)
      • QQBrowser.exe (PID: 3736)
      • QQBrowser.exe (PID: 3636)
      • QQBrowser.exe (PID: 2072)
      • QQBrowser.exe (PID: 1540)
      • TsService.exe (PID: 2832)
      • TsService.exe (PID: 3536)
      • QQBrowserLiveup.exe (PID: 3604)
      • QQBrowser.exe (PID: 3648)
      • QQBrowser.exe (PID: 3888)
      • QQBrowser.exe (PID: 1932)
      • QQBrowser.exe (PID: 2868)
      • QQBrowser.exe (PID: 1016)
      • QQBrowser.exe (PID: 3948)
      • QQBrowser.exe (PID: 3304)
    • Drops a system driver (possible attempt to evade defenses)

      • QQBrowser_Setup_qb10.exe (PID: 2416)
    • Application launched itself

      • QQBrowser.exe (PID: 2592)
      • QQBrowser.exe (PID: 1852)
    • Reads the Internet Settings

      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 3444)
      • QQBrowser.exe (PID: 2444)
      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • TsService.exe (PID: 2832)
      • QQBrowser.exe (PID: 2592)
    • Reads security settings of Internet Explorer

      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 2444)
    • Checks Windows Trust Settings

      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 2444)
      • TsService.exe (PID: 3536)
    • Reads Mozilla Firefox installation path

      • QQBrowser.exe (PID: 1852)
    • Connects to unusual port

      • QQBrowser.exe (PID: 1852)
    • Creates files in the driver directory

      • QQBrowser_Setup_qb10.exe (PID: 2416)
    • Executes as Windows Service

      • TsService.exe (PID: 3536)
    • Creates or modifies Windows services

      • QQBrowser_Setup_qb10.exe (PID: 2416)
    • Changes default file association

      • TsService.exe (PID: 3536)
  • INFO

    • Checks supported languages

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 2592)
      • QQBrowser.exe (PID: 2560)
      • QQBrowser.exe (PID: 1528)
      • QQBrowser.exe (PID: 2844)
      • QQBrowser.exe (PID: 2964)
      • QQBrowser.exe (PID: 2832)
      • QQBrowser.exe (PID: 3072)
      • QQBrowser.exe (PID: 948)
      • QQBrowser.exe (PID: 968)
      • QQBrowser.exe (PID: 3328)
      • QQBrowser.exe (PID: 3516)
      • QQBrowser.exe (PID: 3492)
      • QQBrowser.exe (PID: 3676)
      • QQBrowser.exe (PID: 3740)
      • QQBrowser.exe (PID: 3908)
      • QQBrowser.exe (PID: 3668)
      • QQBrowser.exe (PID: 1604)
      • QQBrowser.exe (PID: 4032)
      • QQBrowser.exe (PID: 1836)
      • QQBrowser.exe (PID: 3068)
      • QQBrowser.exe (PID: 3808)
      • QQBrowser.exe (PID: 1316)
      • QQBrowser.exe (PID: 4088)
      • QQBrowser.exe (PID: 1344)
      • QQBrowser.exe (PID: 3464)
      • QQBrowser.exe (PID: 3444)
      • QQBrowser.exe (PID: 3556)
      • QQBrowser.exe (PID: 3952)
      • QQBrowser.exe (PID: 1832)
      • QQBrowser.exe (PID: 4072)
      • QQBrowser.exe (PID: 2620)
      • QQBrowser.exe (PID: 1924)
      • QQBrowser.exe (PID: 2444)
      • QQBrowser.exe (PID: 3268)
      • QQBrowser.exe (PID: 3232)
      • QQBrowser.exe (PID: 2904)
      • QQBrowser.exe (PID: 3736)
      • QQBrowser.exe (PID: 2072)
      • QQBrowser.exe (PID: 3636)
      • QQBrowser.exe (PID: 1540)
      • TsService.exe (PID: 2832)
      • QQBrowserLiveup.exe (PID: 3604)
      • TsService.exe (PID: 3536)
      • QQBrowser.exe (PID: 3648)
      • QQBrowser.exe (PID: 3888)
      • QQBrowser.exe (PID: 1932)
      • QQBrowser.exe (PID: 2868)
      • QQBrowser.exe (PID: 3304)
      • QQBrowser.exe (PID: 1016)
      • QQBrowser.exe (PID: 3948)
    • Reads the computer name

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 2592)
      • QQBrowser.exe (PID: 1528)
      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 3072)
      • QQBrowser.exe (PID: 2964)
      • QQBrowser.exe (PID: 2844)
      • QQBrowser.exe (PID: 968)
      • QQBrowser.exe (PID: 3068)
      • QQBrowser.exe (PID: 2832)
      • QQBrowser.exe (PID: 3328)
      • QQBrowser.exe (PID: 3492)
      • QQBrowser.exe (PID: 3676)
      • QQBrowser.exe (PID: 3668)
      • QQBrowser.exe (PID: 3740)
      • QQBrowser.exe (PID: 3908)
      • QQBrowser.exe (PID: 4032)
      • QQBrowser.exe (PID: 1604)
      • QQBrowser.exe (PID: 1344)
      • QQBrowser.exe (PID: 3808)
      • QQBrowser.exe (PID: 1316)
      • QQBrowser.exe (PID: 1836)
      • QQBrowser.exe (PID: 4088)
      • QQBrowser.exe (PID: 3464)
      • QQBrowser.exe (PID: 3556)
      • QQBrowser.exe (PID: 1832)
      • QQBrowser.exe (PID: 3952)
      • QQBrowser.exe (PID: 4072)
      • QQBrowser.exe (PID: 3444)
      • QQBrowser.exe (PID: 1924)
      • QQBrowser.exe (PID: 2620)
      • QQBrowser.exe (PID: 2444)
      • QQBrowser.exe (PID: 3268)
      • QQBrowser.exe (PID: 3232)
      • QQBrowser.exe (PID: 2904)
      • QQBrowser.exe (PID: 3736)
      • QQBrowser.exe (PID: 3636)
      • QQBrowser.exe (PID: 1540)
      • TsService.exe (PID: 2832)
      • QQBrowserLiveup.exe (PID: 3604)
      • TsService.exe (PID: 3536)
      • QQBrowser.exe (PID: 3648)
      • QQBrowser.exe (PID: 3888)
      • QQBrowser.exe (PID: 2868)
      • QQBrowser.exe (PID: 1932)
      • QQBrowser.exe (PID: 1016)
      • QQBrowser.exe (PID: 3948)
      • QQBrowser.exe (PID: 3304)
    • Process checks whether UAC notifications are on

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 1528)
      • TsService.exe (PID: 2832)
      • TsService.exe (PID: 3536)
      • QQBrowserLiveup.exe (PID: 3604)
    • Reads the machine GUID from the registry

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 2592)
      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 3072)
      • QQBrowser.exe (PID: 2832)
      • QQBrowser.exe (PID: 3328)
      • QQBrowser.exe (PID: 3676)
      • QQBrowser.exe (PID: 3668)
      • QQBrowser.exe (PID: 3740)
      • QQBrowser.exe (PID: 3444)
      • QQBrowser.exe (PID: 2444)
      • QQBrowser.exe (PID: 2072)
      • QQBrowser.exe (PID: 3636)
      • QQBrowser.exe (PID: 1540)
      • TsService.exe (PID: 3536)
      • QQBrowserLiveup.exe (PID: 3604)
      • QQBrowser.exe (PID: 3888)
      • QQBrowser.exe (PID: 2868)
      • QQBrowser.exe (PID: 1932)
      • QQBrowser.exe (PID: 3304)
    • Creates files in the program directory

      • QQBrowser_Setup_qb10.exe (PID: 2416)
    • Create files in a temporary directory

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 2592)
      • QQBrowser.exe (PID: 1852)
    • Creates files or folders in the user directory

      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 3444)
      • QQBrowser.exe (PID: 2444)
      • QQBrowserLiveup.exe (PID: 3604)
    • Manual execution by a user

      • QQBrowser.exe (PID: 2592)
    • Checks proxy server information

      • QQBrowser.exe (PID: 2472)
      • QQBrowser.exe (PID: 1852)
      • QQBrowser.exe (PID: 3444)
      • QQBrowser.exe (PID: 2444)
      • QQBrowser_Setup_qb10.exe (PID: 2416)
      • TsService.exe (PID: 2832)
    • Reads the time zone

      • QQBrowser.exe (PID: 2844)
      • QQBrowser.exe (PID: 3068)
      • QQBrowser.exe (PID: 2832)
      • QQBrowser.exe (PID: 3072)
      • QQBrowser.exe (PID: 968)
      • QQBrowser.exe (PID: 3328)
      • QQBrowser.exe (PID: 3676)
      • QQBrowser.exe (PID: 3740)
      • QQBrowser.exe (PID: 3668)
      • QQBrowser.exe (PID: 3636)
      • QQBrowser.exe (PID: 1540)
      • TsService.exe (PID: 3536)
      • QQBrowser.exe (PID: 1932)
      • QQBrowser.exe (PID: 3304)
      • QQBrowser.exe (PID: 2868)
    • Process checks computer location settings

      • QQBrowser.exe (PID: 3072)
      • QQBrowser.exe (PID: 968)
      • QQBrowser.exe (PID: 3068)
      • QQBrowser.exe (PID: 2832)
      • QQBrowser.exe (PID: 2844)
      • QQBrowser.exe (PID: 3328)
      • QQBrowser.exe (PID: 3676)
      • QQBrowser.exe (PID: 3740)
      • QQBrowser.exe (PID: 3668)
      • QQBrowser.exe (PID: 3636)
      • QQBrowser.exe (PID: 1540)
      • QQBrowser.exe (PID: 1932)
      • QQBrowser.exe (PID: 2868)
      • QQBrowser.exe (PID: 3304)
    • Reads CPU info

      • QQBrowser.exe (PID: 3516)
      • QQBrowser.exe (PID: 3444)
      • QQBrowser.exe (PID: 2444)
      • TsService.exe (PID: 3536)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1970:01:27 15:43:12+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 856064
InitializedDataSize: 81920
UninitializedDataSize: 1605632
EntryPoint: 0x2598c0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 10.8.4560.400
ProductVersionNumber: 10.8.4560.400
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
Comments: 2014-07-16 00:00:00
CompanyName: Tencent Inc.
FileDescription: QQ浏览器安装程序
FileVersion: 10.8.4560.400
InternalName: QQBrowser
LegalCopyright: Copyright © 2018 Tencent. All Rights Reserved.
ProductName: QQ 浏览器
ProductVersion: 10.8.4560.400
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
105
Monitored processes
58
Malicious processes
56
Suspicious processes
0

Behavior graph

Click at the process to see the details
start qqbrowser_setup_qb10.exe icacls.exe icacls.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe no specs qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe regsvr32.exe qqbrowser.exe qqbrowser.exe tsservice.exe tsservice.exe qqbrowserliveup.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser.exe qqbrowser_setup_qb10.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Users\admin\Desktop\QQBrowser_Setup_qb10.exe" C:\Users\admin\Desktop\QQBrowser_Setup_qb10.exeexplorer.exe
User:
admin
Company:
Tencent Inc.
Integrity Level:
MEDIUM
Description:
QQ浏览器安装程序
Exit code:
3221226540
Version:
10.8.4560.400
Modules
Images
c:\users\admin\desktop\qqbrowser_setup_qb10.exe
c:\windows\system32\ntdll.dll
948"C:\Program Files\Tencent\QQBrowser\QQBrowser.exe" --type=utility --field-trial-handle=2460,899476284211639477,17293865700893513719,131072 --enable-features=frame-login,qqbrowser-union-enable,sync-local-preference,sync-timestamp,use-bookmark-password --lang=zh-CN --no-sandbox --frame-version=10.8.4560.400 --service-request-channel-token=13496231223953982140 --mojo-platform-channel-handle=3568 /prefetch:8C:\Program Files\Tencent\QQBrowser\QQBrowser.exe
QQBrowser.exe
User:
admin
Company:
Tencent
Integrity Level:
MEDIUM
Description:
QQBrowser
Exit code:
4294967295
Version:
10.8.4560.400
Modules
Images
c:\program files\tencent\qqbrowser\qqbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\tencent\qqbrowser\10.8.4560.400\chrome_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
968"C:\Program Files\Tencent\QQBrowser\QQBrowser.exe" --type=renderer --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-nacl --field-trial-handle=2460,899476284211639477,17293865700893513719,131072 --enable-features=frame-login,qqbrowser-union-enable,sync-local-preference,sync-timestamp,use-bookmark-password --disable-databases --service-pipe-token=16356176868426126399 --lang=zh-CN --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-nacl --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16356176868426126399 --renderer-client-id=4 --frame-version=10.8.4560.400 --mojo-platform-channel-handle=3364 /prefetch:1C:\Program Files\Tencent\QQBrowser\QQBrowser.exe
QQBrowser.exe
User:
admin
Company:
Tencent
Integrity Level:
LOW
Description:
QQBrowser
Exit code:
0
Version:
10.8.4560.400
Modules
Images
c:\program files\tencent\qqbrowser\qqbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\tencent\qqbrowser\10.8.4560.400\chrome_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
1016"C:\Program Files\Tencent\QQBrowser\QQBrowser.exe" --type=utility --field-trial-handle=2460,899476284211639477,17293865700893513719,131072 --enable-features=frame-login,qqbrowser-union-enable,sync-local-preference,sync-timestamp,use-bookmark-password --lang=zh-CN --service-sandbox-type=utility --frame-version=10.8.4560.400 --service-request-channel-token=12794882334632664416 --mojo-platform-channel-handle=5520 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Tencent\QQBrowser\QQBrowser.exe
QQBrowser.exe
User:
admin
Company:
Tencent
Integrity Level:
LOW
Description:
QQBrowser
Exit code:
4294967295
Version:
10.8.4560.400
Modules
Images
c:\program files\tencent\qqbrowser\qqbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\tencent\qqbrowser\10.8.4560.400\chrome_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
1308"C:\Program Files\Tencent\QQBrowser\QQBrowser.exe" --type=renderer --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-nacl --field-trial-handle=2460,899476284211639477,17293865700893513719,131072 --enable-features=frame-login,qqbrowser-union-enable,sync-local-preference,sync-timestamp,use-bookmark-password --disable-gpu-compositing --service-pipe-token=16681281781581528533 --lang=zh-CN --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-nacl --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16681281781581528533 --renderer-client-id=17 --frame-version=10.8.4560.400 --mojo-platform-channel-handle=6320 /prefetch:1C:\Program Files\Tencent\QQBrowser\QQBrowser.exeQQBrowser.exe
User:
admin
Company:
Tencent
Integrity Level:
LOW
Description:
QQBrowser
Exit code:
0
Version:
10.8.4560.400
Modules
Images
c:\program files\tencent\qqbrowser\qqbrowser.exe
c:\windows\system32\ntdll.dll
1316"C:\Program Files\Tencent\QQBrowser\QQBrowser.exe" --type=utility --field-trial-handle=2460,899476284211639477,17293865700893513719,131072 --enable-features=frame-login,qqbrowser-union-enable,sync-local-preference,sync-timestamp,use-bookmark-password --lang=zh-CN --service-sandbox-type=utility --frame-version=10.8.4560.400 --service-request-channel-token=1865738842704577111 --mojo-platform-channel-handle=6436 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Tencent\QQBrowser\QQBrowser.exe
QQBrowser.exe
User:
admin
Company:
Tencent
Integrity Level:
LOW
Description:
QQBrowser
Exit code:
4294967295
Version:
10.8.4560.400
Modules
Images
c:\program files\tencent\qqbrowser\qqbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\tencent\qqbrowser\10.8.4560.400\chrome_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
1344"C:\Program Files\Tencent\QQBrowser\QQBrowser.exe" --type=utility --field-trial-handle=2460,899476284211639477,17293865700893513719,131072 --enable-features=frame-login,qqbrowser-union-enable,sync-local-preference,sync-timestamp,use-bookmark-password --lang=zh-CN --service-sandbox-type=utility --frame-version=10.8.4560.400 --service-request-channel-token=6652379986529209048 --mojo-platform-channel-handle=6432 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Tencent\QQBrowser\QQBrowser.exe
QQBrowser.exe
User:
admin
Company:
Tencent
Integrity Level:
LOW
Description:
QQBrowser
Exit code:
4294967295
Version:
10.8.4560.400
Modules
Images
c:\program files\tencent\qqbrowser\qqbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\tencent\qqbrowser\10.8.4560.400\chrome_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
1528"C:\Program Files\Tencent\QQBrowser\QQBrowser.exe" --type=assistant --clipboard /prefetch:8C:\Program Files\Tencent\QQBrowser\QQBrowser.exe
QQBrowser.exe
User:
admin
Company:
Tencent
Integrity Level:
MEDIUM
Description:
QQBrowser
Exit code:
0
Version:
10.8.4560.400
Modules
Images
c:\program files\tencent\qqbrowser\qqbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\tencent\qqbrowser\10.8.4560.400\chrome_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
1540"C:\Program Files\Tencent\QQBrowser\QQBrowser.exe" --type=renderer --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-nacl --field-trial-handle=2460,899476284211639477,17293865700893513719,131072 --enable-features=frame-login,qqbrowser-union-enable,sync-local-preference,sync-timestamp,use-bookmark-password --disable-gpu-compositing --service-pipe-token=4829723257938574160 --lang=zh-CN --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-nacl --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4829723257938574160 --renderer-client-id=36 --frame-version=10.8.4560.400 --mojo-platform-channel-handle=7388 /prefetch:1C:\Program Files\Tencent\QQBrowser\QQBrowser.exe
QQBrowser.exe
User:
admin
Company:
Tencent
Integrity Level:
LOW
Description:
QQBrowser
Exit code:
0
Version:
10.8.4560.400
Modules
Images
c:\program files\tencent\qqbrowser\qqbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\tencent\qqbrowser\10.8.4560.400\chrome_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
1604"C:\Program Files\Tencent\QQBrowser\QQBrowser.exe" --type=utility --field-trial-handle=2460,899476284211639477,17293865700893513719,131072 --enable-features=frame-login,qqbrowser-union-enable,sync-local-preference,sync-timestamp,use-bookmark-password --lang=zh-CN --service-sandbox-type=utility --frame-version=10.8.4560.400 --service-request-channel-token=1461649270634039464 --mojo-platform-channel-handle=6816 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Tencent\QQBrowser\QQBrowser.exe
QQBrowser.exe
User:
admin
Company:
Tencent
Integrity Level:
LOW
Description:
QQBrowser
Exit code:
4294967295
Version:
10.8.4560.400
Modules
Images
c:\program files\tencent\qqbrowser\qqbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\tencent\qqbrowser\10.8.4560.400\chrome_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
Total events
39 607
Read events
39 010
Write events
579
Delete events
18

Modification events

(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Operation:writeName:FavoritesResolve
Value:
CE0200004C0000000114020000000000C00000000000004683008000200000008351B924BB3DD3018351B924BB3DD3017BA28924BB3DD3018505000000000000010000000000000000000000000000007C0114001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016001401320085050000454B864A2000494E5445524E7E312E4C4E4B0000A60008000400EFBE454B864A454B864A2A000000613E000000000400000000000000000056000000000049006E007400650072006E006500740020004500780070006C006F007200650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00690065003400750069006E00690074002E006500780065002C002D0037003300310000001C00520000001D00EFBE02004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C00740000001C000000A00000001C000000010000001C0000002D000000000000009F00000011000000030000004736BAC41000000000433A5C55736572735C61646D696E5C417070446174615C526F616D696E675C4D6963726F736F66745C496E7465726E6574204578706C6F7265725C517569636B204C61756E63685C557365722050696E6E65645C5461736B4261725C496E7465726E6574204578706C6F7265722E6C6E6B000060000000030000A05800000000000000706300000000000000000000000000005CF1A7C03D50454982D81E2FB6820766D9090401F1A9E711A8D15254004AAD115CF1A7C03D50454982D81E2FB6820766D9090401F1A9E711A8D15254004AAD1100000000C70200004C0000000114020000000000C0000000000000468300800020000000DDB3BB24BB3DD301DDB3BB24BB3DD30148294ED33C04CA01CC0400000000000001000000000000000000000000000000760114001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016000E013200CC040000EE3AB624200057494E444F577E312E4C4E4B00007E0008000400EFBE454B864A454B864A2A000000673E0000000005000000000000000000540000000000570069006E0064006F007700730020004500780070006C006F007200650072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003600370000001C00740000001D00EFBE02007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001C0000009F0000001C000000010000001C0000002D000000000000009E00000011000000030000004736BAC41000000000433A5C55736572735C61646D696E5C417070446174615C526F616D696E675C4D6963726F736F66745C496E7465726E6574204578706C6F7265725C517569636B204C61756E63685C557365722050696E6E65645C5461736B4261725C57696E646F7773204578706C6F7265722E6C6E6B000060000000030000A05800000000000000706300000000000000000000000000005CF1A7C03D50454982D81E2FB6820766DA090401F1A9E711A8D15254004AAD115CF1A7C03D50454982D81E2FB6820766DA090401F1A9E711A8D15254004AAD1100000000CD0200004C0000000114020000000000C00000000000004683008000200000003716BE24BB3DD3013716BE24BB3DD301298CC0B4FB88CB01EB0500000000000001000000000000000000000000000000780114001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B004200610072000000160010013200EB050000743D33AD200057494E444F577E322E4C4E4B0000A80008000400EFBE454B864A454B864A2A0000006B3E00000000050000000000000000005C0000000000570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0075006E007200650067006D00700032002E006500780065002C002D00340000001C004C0000001D00EFBE02004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E004D00650064006900610050006C0061007900650072003300320000001C000000A30000001C000000010000001C0000002D00000000000000A200000011000000030000004736BAC41000000000433A5C55736572735C61646D696E5C417070446174615C526F616D696E675C4D6963726F736F66745C496E7465726E6574204578706C6F7265725C517569636B204C61756E63685C557365722050696E6E65645C5461736B4261725C57696E646F7773204D6564696120506C617965722E6C6E6B000060000000030000A05800000000000000706300000000000000000000000000005CF1A7C03D50454982D81E2FB6820766DB090401F1A9E711A8D15254004AAD115CF1A7C03D50454982D81E2FB6820766DB090401F1A9E711A8D15254004AAD11000000003C0200004C0000000114020000000000C000000000000046830080002000000017E829EFBF3ED40117E829EFBF3ED401D2754AC6BF3ED4017A0800000000000001000000000000000000000000000000EE0014001F80C827341F105C1042AA032EE45287D66852003100000000001C4D7D5911005461736B426172003C0008000400EFBE454B864A1C4D7D592A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600860032007A0800001C4D59592000474F4F474C457E312E4C4E4B0000500008000400EFBE1C4D7D591C4D7D592A00000097C0000000000100000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C001A0000001D00EFBE02004300680072006F006D00650000001C0000009C0000001C000000010000001C0000002D000000000000009B00000011000000030000004736BAC41000000000433A5C55736572735C61646D696E5C417070446174615C526F616D696E675C4D6963726F736F66745C496E7465726E6574204578706C6F7265725C517569636B204C61756E63685C557365722050696E6E65645C5461736B4261725C476F6F676C65204368726F6D652E6C6E6B000060000000030000A05800000000000000706300000000000000000000000000005CF1A7C03D50454982D81E2FB68207669B2D8645B0AAE81192B35254004AAD115CF1A7C03D50454982D81E2FB68207669B2D8645B0AAE81192B35254004AAD11000000003F0200004C0000000114020000000000C0000000000000468300800020000000CF689912EBAFD901CF689912EBAFD901FE668B12EBAFD901C60800000000000001000000000000000000000000000000F00014001F80C827341F105C1042AA032EE45287D6685200310000000000E656884A11005461736B426172003C0008000400EFBE454B864AE656884A2A000000603E00000000040000000000000000000000000000005400610073006B004200610072000000160088003200C6080000E656884A20004D4943524F537E312E4C4E4B0000520008000400EFBEE656884AE656884A2A00000081E400000000060000000000000000000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B0000001C001A0000001D00EFBE02004D005300450064006700650000001C0000009D0000001C000000010000001C0000002D000000000000009C00000011000000030000004736BAC41000000000433A5C55736572735C61646D696E5C417070446174615C526F616D696E675C4D6963726F736F66745C496E7465726E6574204578706C6F7265725C517569636B204C61756E63685C557365722050696E6E65645C5461736B4261725C4D6963726F736F667420456467652E6C6E6B000060000000030000A05800000000000000757365722D70630000000000000000005CF1A7C03D50454982D81E2FB68207660A614119DE1BEE11B03012A9866C77DE5CF1A7C03D50454982D81E2FB68207660A614119DE1BEE11B03012A9866C77DE00000000
(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Operation:writeName:Favorites
Value:
007C01000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016001401320085050000454B864A2000494E5445524E7E312E4C4E4B0000A60008000400EFBE454B864A454B864A2A000000613E000000000400000000000000000056000000000049006E007400650072006E006500740020004500780070006C006F007200650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00690065003400750069006E00690074002E006500780065002C002D0037003300310000001C00520000001D00EFBE02004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C00740000001C000000007601000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016000E013200CC040000EE3AB624200057494E444F577E312E4C4E4B00007E0008000400EFBE454B864A454B864A2A000000673E0000000005000000000000000000540000000000570069006E0064006F007700730020004500780070006C006F007200650072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003600370000001C00740000001D00EFBE02007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001C000000007801000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B004200610072000000160010013200EB050000743D33AD200057494E444F577E322E4C4E4B0000A80008000400EFBE454B864A454B864A2A0000006B3E00000000050000000000000000005C0000000000570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0075006E007200650067006D00700032002E006500780065002C002D00340000001C004C0000001D00EFBE02004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E004D00650064006900610050006C0061007900650072003300320000001C00000000EE00000014001F80C827341F105C1042AA032EE45287D66852003100000000001C4D7D5911005461736B426172003C0008000400EFBE454B864A1C4D7D592A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600860032007A0800001C4D59592000474F4F474C457E312E4C4E4B0000500008000400EFBE1C4D7D591C4D7D592A00000097C0000000000100000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C001A0000001D00EFBE02004300680072006F006D00650000001C00000000F000000014001F80C827341F105C1042AA032EE45287D6685200310000000000E656884A11005461736B426172003C0008000400EFBE454B864AE656884A2A000000603E00000000040000000000000000000000000000005400610073006B004200610072000000160088003200C6080000E656884A20004D4943524F537E312E4C4E4B0000520008000400EFBEE656884AE656884A2A00000081E400000000060000000000000000000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B0000001C001A0000001D00EFBE02004D005300450064006700650000001C000000FF
(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Operation:writeName:FavoritesChanges
Value:
14
(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Operation:writeName:FavoritesVersion
Value:
2
(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice
Operation:delete keyName:(default)
Value:
(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice
Operation:delete keyName:(default)
Value:
(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice
Operation:delete keyName:(default)
Value:
(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice
Operation:delete keyName:(default)
Value:
(PID) Process:(2416) QQBrowser_Setup_qb10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice
Operation:delete keyName:(default)
Value:
Executable files
125
Suspicious files
378
Text files
1 014
Unknown types
3

Dropped files

PID
Process
Filename
Type
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\bin\qb_200_percent.pak
MD5:
SHA256:
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\bin\resources.pak
MD5:
SHA256:
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\bin\locales\qb\en-US.pakbinary
MD5:BD1D263BB604DF6C657931E21577158D
SHA256:C5CABE327563853CD7A75734935F37C3E98FA473C6547531166A2FA4360071EE
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\bin\Historybinary
MD5:FAD23839EC8B52E276D8F50FE3AD9DA2
SHA256:9755CCFC3269D688665D8DE67190CB9D6A62C96D9CA22578ECE01C9FC485873A
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\bin\data\manifesthtml
MD5:A3B1C8A68D3E310EF68E432138523BCB
SHA256:803EE3CFDD68BE0622FB41FCE786DF3771A313DC010AE089A23B103B0E1B92B0
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\license.txttext
MD5:F8581FF0348DE970315072E4D7998A38
SHA256:5CA3E9481BB486F5164246A2841A2D20C5D69E275C0083781FDDED3B4C6CFD03
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\Config.xmlxml
MD5:A21A2EF9926FA7D7444AF00B66841DFD
SHA256:DEBC12CD6A37590983018283871E8C528D94061C88AE5DBBF2ABF584561B9886
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\nsis_skin.gtbinary
MD5:DFDAE15B5C5DAA8C509C9EF53D467A32
SHA256:47789E3CB45BF37F903E70EB2E887C3FD0D1A51B3A550973AD711BF3F868A0BE
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\bin\WidevineCdm\licensetext
MD5:7406820F5D56FDA6BAFFA951C60679D2
SHA256:20DE375707692099B3132084695377CE5FEC0AEC05813DEDCCE094B8EDA44386
2416QQBrowser_Setup_qb10.exeC:\Users\admin\AppData\Local\Temp\14abdfabc\bin\chrome_200_percent.pakbinary
MD5:76ADFA42D017D19D7A59EF7EF9A854E7
SHA256:2CD7D75508787E47D24A70D6889F295F0E288BCFA2BE98CA351A6208732CF033
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
93
TCP/UDP connections
668
DNS requests
125
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2416
QQBrowser_Setup_qb10.exe
GET
115.56.76.128:80
http://dldir1.qq.com/invc/tt/QQBrowser_Setup_10.8.4560.400_for_downloader.exe
unknown
unknown
1852
QQBrowser.exe
GET
200
182.254.116.116:80
http://182.254.116.116:80/d?dn=6d439c1c2b68342b04f12ea518d09cad&id=171
unknown
text
64 b
unknown
1852
QQBrowser.exe
GET
302
43.135.106.77:80
http://browser.qq.com/?ch=fallback
unknown
html
137 b
unknown
1852
QQBrowser.exe
GET
302
43.154.240.84:80
http://daohang.qq.com/favicon.ico?fr=bkmark
unknown
html
137 b
unknown
1852
QQBrowser.exe
GET
302
43.154.240.84:80
http://daohang.qq.com/?fr=hmpage
unknown
html
137 b
unknown
2472
QQBrowser.exe
POST
200
183.47.104.158:80
http://qbwup.imtt.qq.com/
unknown
binary
93 b
unknown
2472
QQBrowser.exe
POST
200
183.47.104.158:80
http://qbwup.imtt.qq.com/
unknown
binary
93 b
unknown
2472
QQBrowser.exe
POST
200
183.47.104.158:80
http://qbwup.imtt.qq.com/
unknown
binary
93 b
unknown
1852
QQBrowser.exe
POST
200
43.154.240.217:8080
http://wup.imtt.qq.com:8080/?encrypt=17&len=1024&v=3&iv=8ABF93C4AE444da0&id=a690d5f54b43ca535af266c3180769c7&qbkey=82B15BF0948B242C60A07AE622EEB9D5C83F900F37FEBC896485A664B905D3440A3AA21203E834F9322351976B5F673EDEAFD205ABECC16C0A303D70B66D7D2FEEEAFE72A2AD190E211153263C4F3029EECA7B6119B2F122211C342A3FAE8D6B360D0D625931E4EA3B06D7160AD2A808B7A98A7B4EF7444912A2E7F57D9EBF11
unknown
binary
160 b
unknown
1852
QQBrowser.exe
POST
200
43.154.240.217:8080
http://wup.imtt.qq.com:8080/?encrypt=17&len=1024&v=3&iv=A5BD80BDCA6F4915&id=a690d5f54b43ca535af266c3180769c7&qbkey=6A78D84D2F5CB2F332C1CAD721D15DB5BA675CA0831E6C814C788B05D5FCC19508FAA332460E44236929587F769201599E7D8D073013D9A175EB1DF000BA8D36459FA012F45A6FC359D51F2961DE8D4CB0D2A04C32FD6AFB0DB8B7F0771F1BAEF5F9CBC8FC24C9135EC27DD834A48EDF9D99DB2C94C41E75EB99591A31CA1A3B
unknown
binary
240 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2416
QQBrowser_Setup_qb10.exe
43.135.106.42:443
go.browser.qq.com
Tencent Building, Kejizhongyi Avenue
HK
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2416
QQBrowser_Setup_qb10.exe
115.56.76.128:80
dldir1.qq.com
CHINA UNICOM China169 Backbone
CN
unknown
2416
QQBrowser_Setup_qb10.exe
129.226.107.80:443
wup.browser.qq.com
Tencent Building, Kejizhongyi Avenue
HK
unknown
2472
QQBrowser.exe
101.33.47.206:8081
oth.eve.mdt.qq.com
Tencent Building, Kejizhongyi Avenue
SG
unknown
2472
QQBrowser.exe
183.47.104.158:80
qbwup.imtt.qq.com
Chinanet
CN
unknown
1852
QQBrowser.exe
43.156.86.17:33445
ts.qq.com
Tencent Building, Kejizhongyi Avenue
SG
unknown
1852
QQBrowser.exe
182.254.116.116:80
Shenzhen Tencent Computer Systems Company Limited
CN
unknown

DNS requests

Domain
IP
Reputation
go.browser.qq.com
  • 43.135.106.42
  • 43.135.106.212
whitelisted
dldir1.qq.com
  • 115.56.76.128
  • 202.97.231.11
  • 123.6.2.151
  • 61.54.91.227
  • 115.56.90.245
  • 1.58.245.77
  • 119.36.226.159
  • 61.163.203.31
  • 113.1.0.204
  • 221.15.67.45
  • 123.6.2.138
  • 121.29.2.225
  • 36.249.92.111
  • 123.138.255.5
  • 61.54.91.122
whitelisted
wup.browser.qq.com
  • 129.226.107.80
  • 129.226.106.211
whitelisted
oth.eve.mdt.qq.com
  • 101.33.47.206
  • 101.33.47.68
unknown
www.qq.com
  • 23.196.244.121
  • 23.73.140.209
  • 2.16.184.177
whitelisted
qbwup.imtt.qq.com
  • 183.47.104.158
  • 183.47.126.106
  • 14.22.9.100
unknown
ts.qq.com
  • 43.156.86.17
unknown
www.gstatic.com
  • 142.250.186.35
whitelisted
accounts.google.com
  • 142.251.31.84
shared
newtab.browser.qq.com
  • 43.135.106.42
  • 43.135.106.212
unknown

Threats

PID
Process
Class
Message
2416
QQBrowser_Setup_qb10.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2472
QQBrowser.exe
Potential Corporate Privacy Violation
ET POLICY QQ Browser WUP Request - qbpcstatf.stat
3536
TsService.exe
Potential Corporate Privacy Violation
ET POLICY QQ Browser WUP Request - qbpcstatf.stat
3536
TsService.exe
Potential Corporate Privacy Violation
ET POLICY QQ Browser WUP Request - qbpcstatf.stat
Process
Message
QQBrowser_Setup_qb10.exe
qbinstall| "C:\Program Files\Tencent\QQBrowser" /inheritance:d /Q
QQBrowser_Setup_qb10.exe
qbinstall| "C:\Program Files\Tencent\QQBrowser" /inheritance:d /Q2
QQBrowser_Setup_qb10.exe
qbinstall| "C:\Program Files\Tencent\QQBrowser" /remove:g "Authenticated Users" /Q2
QQBrowser_Setup_qb10.exe
qbinstall| "C:\Program Files\Tencent\QQBrowser" /remove:g "Authenticated Users" /Q
QQBrowser.exe
qbclipboard:[MsgWnd::OnCreate(67)] start
QQBrowser_Setup_qb10.exe
qbinstall|/s "C:\Program Files\Tencent\QQBrowser\10.8.4560.400\webp\WebpDecodeFilter.dll"
QQBrowser_Setup_qb10.exe
qbinstall|/s "C:\Program Files\Tencent\QQBrowser\10.8.4560.400\webp\WebpDecodeFilter.dll"2
QQBrowserLiveup.exe
liveup: QQbrower Liveup Begin cmd:
QQBrowserLiveup.exe
liveup: InitType:0
QQBrowserLiveup.exe
liveup: RealType:0