download:

/soft/uninstaller/Advanced_Uninstaller13.exe

Full analysis: https://app.any.run/tasks/1d61cbef-e0bf-4b77-bd79-e5862b9cf74b
Verdict: Malicious activity
Analysis date: January 10, 2024, 20:50:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3AA3F12ACB3B152E57A3292982D19890

SHA1:

CD52481B643A04B50DE89BFF182E06F544BAC992

SHA256:

5A11FCD53B28C802AACD216019BCA8586394EA32063E0530409276DD65877F55

SSDEEP:

196608:O/j9WNQcqF6POFhLuXHVnVyqlvpvHjU3z67z6TVZ7uYHmNYyMlcll1mgUjcD9/:O/xW6cqcPOFMXHdl1jaYz6TVZ7lQDMlQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • healthcheck.exe (PID: 2444)
      • uninstaller.exe (PID: 2964)
      • checker.exe (PID: 2228)
    • Steals credentials from Web Browsers

      • healthcheck.exe (PID: 2444)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • Advanced_Uninstaller13.tmp (PID: 268)
    • Reads the Internet Settings

      • Advanced_Uninstaller13.tmp (PID: 268)
      • uninstaller.exe (PID: 2740)
    • Adds/modifies Windows certificates

      • Advanced_Uninstaller13.tmp (PID: 268)
    • Searches for installed software

      • regedit.exe (PID: 2424)
      • uninstaller.exe (PID: 2560)
      • uninstaller.exe (PID: 1904)
      • dllhost.exe (PID: 3060)
      • uninstaller.exe (PID: 2964)
      • checker.exe (PID: 2228)
    • The process verifies whether the antivirus software is installed

      • healthcheck.exe (PID: 2444)
    • Uses TASKKILL.EXE to kill process

      • Advanced_Uninstaller13.tmp (PID: 268)
    • Uses TASKKILL.EXE to kill Browsers

      • uninstaller.exe (PID: 2964)
    • Reads the Windows owner or organization settings

      • Advanced_Uninstaller13.tmp (PID: 268)
  • INFO

    • Checks supported languages

      • Advanced_Uninstaller13.exe (PID: 128)
      • Advanced_Uninstaller13.tmp (PID: 1776)
      • Advanced_Uninstaller13.exe (PID: 492)
      • healthcheck.exe (PID: 2444)
      • stop_aup.exe (PID: 1584)
      • uninstaller.exe (PID: 2472)
      • uninstaller.exe (PID: 2560)
      • uninstaller.exe (PID: 1904)
      • uninstaller.exe (PID: 1424)
      • uninstaller.exe (PID: 2740)
      • uninstaller.exe (PID: 2964)
      • checker.exe (PID: 2228)
      • Advanced_Uninstaller13.tmp (PID: 268)
      • pwsh.exe (PID: 2204)
    • Drops the executable file immediately after the start

      • Advanced_Uninstaller13.exe (PID: 128)
      • Advanced_Uninstaller13.exe (PID: 492)
      • Advanced_Uninstaller13.tmp (PID: 268)
    • Reads the machine GUID from the registry

      • Advanced_Uninstaller13.tmp (PID: 268)
      • uninstaller.exe (PID: 1904)
      • uninstaller.exe (PID: 1424)
      • uninstaller.exe (PID: 2560)
      • uninstaller.exe (PID: 2964)
      • checker.exe (PID: 2228)
    • Creates files in the program directory

      • Advanced_Uninstaller13.tmp (PID: 268)
      • regedit.exe (PID: 796)
      • regedit.exe (PID: 2424)
      • healthcheck.exe (PID: 2444)
      • uninstaller.exe (PID: 2560)
      • uninstaller.exe (PID: 2964)
      • chrome.exe (PID: 1168)
    • Checks for external IP

      • Advanced_Uninstaller13.tmp (PID: 268)
    • Reads the computer name

      • Advanced_Uninstaller13.tmp (PID: 1776)
      • stop_aup.exe (PID: 1584)
      • healthcheck.exe (PID: 2444)
      • uninstaller.exe (PID: 2740)
      • uninstaller.exe (PID: 2472)
      • uninstaller.exe (PID: 2560)
      • uninstaller.exe (PID: 1424)
      • uninstaller.exe (PID: 2964)
      • uninstaller.exe (PID: 1904)
      • checker.exe (PID: 2228)
      • pwsh.exe (PID: 2204)
      • Advanced_Uninstaller13.tmp (PID: 268)
    • Create files in a temporary directory

      • Advanced_Uninstaller13.exe (PID: 128)
      • Advanced_Uninstaller13.exe (PID: 492)
      • Advanced_Uninstaller13.tmp (PID: 268)
    • Process drops legitimate windows executable

      • Advanced_Uninstaller13.tmp (PID: 268)
    • Creates files or folders in the user directory

      • Advanced_Uninstaller13.tmp (PID: 268)
      • uninstaller.exe (PID: 1424)
      • uninstaller.exe (PID: 2964)
      • uninstaller.exe (PID: 2560)
      • checker.exe (PID: 2228)
    • Checks proxy server information

      • Advanced_Uninstaller13.tmp (PID: 268)
    • The process executes via Task Scheduler

      • uninstaller.exe (PID: 2560)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2060)
    • Application launched itself

      • msedge.exe (PID: 2844)
      • msedge.exe (PID: 2460)
      • chrome.exe (PID: 1168)
    • Manual execution by a user

      • msedge.exe (PID: 2460)
      • pwsh.exe (PID: 2204)
    • Connects to the CnC server

      • Advanced_Uninstaller13.tmp (PID: 268)
    • The process uses the downloaded file

      • chrome.exe (PID: 3072)
      • chrome.exe (PID: 296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (74.3)
.exe | Win32 Executable Delphi generic (9.6)
.scr | Windows screen saver (8.8)
.exe | Win32 Executable (generic) (3)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 40448
InitializedDataSize: 382976
UninitializedDataSize: -
EntryPoint: 0xa5f8
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Innovative Solutions
FileDescription: Advanced Uninstaller PRO Setup
FileVersion:
LegalCopyright: © Innovative Solutions
ProductName: Advanced Uninstaller PRO
ProductVersion: 13.26.0.68
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
103
Monitored processes
56
Malicious processes
10
Suspicious processes
1

Behavior graph

Click at the process to see the details
start advanced_uninstaller13.exe no specs advanced_uninstaller13.tmp no specs advanced_uninstaller13.exe advanced_uninstaller13.tmp stop_aup.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs regedit.exe no specs regedit.exe no specs healthcheck.exe uninstaller.exe no specs uninstaller.exe no specs uninstaller.exe uninstaller.exe no specs uninstaller.exe no specs vssvc.exe no specs SPPSurrogate no specs msedge.exe no specs uninstaller.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs checker.exe msedge.exe no specs taskkill.exe no specs chrome.exe chrome.exe no specs msedge.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs chrome.exe no specs msedge.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs pwsh.exe chrome.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\Advanced_Uninstaller13.exe" C:\Users\admin\AppData\Local\Temp\Advanced_Uninstaller13.exeexplorer.exe
User:
admin
Company:
Innovative Solutions
Integrity Level:
MEDIUM
Description:
Advanced Uninstaller PRO Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\advanced_uninstaller13.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
268"C:\Users\admin\AppData\Local\Temp\is-5A8ET.tmp\Advanced_Uninstaller13.tmp" /SL5="$90102,11834898,424448,C:\Users\admin\AppData\Local\Temp\Advanced_Uninstaller13.exe" /SPAWNWND=$401AE /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-5A8ET.tmp\Advanced_Uninstaller13.tmp
Advanced_Uninstaller13.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-5a8et.tmp\advanced_uninstaller13.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
296"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3832 --field-trial-handle=1396,i,13741534263326305257,333577615894582428,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
296"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4372 --field-trial-handle=1336,i,6836809636027866880,18254855225870676969,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
492"C:\Users\admin\AppData\Local\Temp\Advanced_Uninstaller13.exe" /SPAWNWND=$401AE /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\Advanced_Uninstaller13.exe
Advanced_Uninstaller13.tmp
User:
admin
Company:
Innovative Solutions
Integrity Level:
HIGH
Description:
Advanced Uninstaller PRO Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\advanced_uninstaller13.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
796"C:\Windows\regedit.exe" /e entries2.dat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UninstallC:\Windows\regedit.exeAdvanced_Uninstaller13.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1168"C:\Program Files\Google\Chrome\Application\chrome.exe" https://www.advanceduninstaller.com/aup-dhc-extension.html?cmd=test&tick=000E3C88-1&stop=NOC:\Program Files\Google\Chrome\Application\chrome.exe
uninstaller.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
1236"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1460 --field-trial-handle=1336,i,6836809636027866880,18254855225870676969,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1424"C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\Uninstaller.exe" -PINC:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\uninstaller.exeAdvanced_Uninstaller13.tmp
User:
admin
Company:
Innovative Solutions GRUP SRL
Integrity Level:
HIGH
Description:
Advanced Uninstaller PRO
Exit code:
0
Version:
13.26.0.68
Modules
Images
c:\program files\innovative solutions\advanced uninstaller pro\uninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1544"Taskkill.exe" /IM innoupd.exe /FC:\Windows\System32\taskkill.exeAdvanced_Uninstaller13.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
Total events
45 632
Read events
45 143
Write events
489
Delete events
0

Modification events

(PID) Process:(268) Advanced_Uninstaller13.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) Advanced_Uninstaller13.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8
Operation:writeName:Blob
Value:
1900000001000000100000002FE1F70BB05D7C92335BC5E05B984DA662000000010000002000000096BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C60B000000010000001A0000004900530052004700200052006F006F007400200058003100000014000000010000001400000079B459E67BB6E5E40173800888C81A58F6E99B6E1D000000010000001000000073B6876195F5D18E048510422AEF04E309000000010000000C000000300A06082B06010505070301030000000100000014000000CABD2A79A1076A31F21D253635CB039D4329A5E80F00000001000000200000003F0411EDE9C4477057D57E57883B1F205B20CDC0F3263129B1EE0269A2678F6320000000010000006F0500003082056B30820353A0030201020211008210CFB0D240E3594463E0BB63828B00300D06092A864886F70D01010B0500304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F74205831301E170D3135303630343131303433385A170D3335303630343131303433385A304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F7420583130820222300D06092A864886F70D01010105000382020F003082020A0282020100ADE82473F41437F39B9E2B57281C87BEDCB7DF38908C6E3CE657A078F775C2A2FEF56A6EF6004F28DBDE68866C4493B6B163FD14126BBF1FD2EA319B217ED1333CBA48F5DD79DFB3B8FF12F1219A4BC18A8671694A66666C8F7E3C70BFAD292206F3E4C0E680AEE24B8FB7997E94039FD347977C99482353E838AE4F0A6F832ED149578C8074B6DA2FD0388D7B0370211B75F2303CFA8FAEDDDA63ABEB164FC28E114B7ECF0BE8FFB5772EF4B27B4AE04C12250C708D0329A0E15324EC13D9EE19BF10B34A8C3F89A36151DEAC870794F46371EC2EE26F5B9881E1895C34796C76EF3B906279E6DBA49A2F26C5D010E10EDED9108E16FBB7F7A8F7C7E50207988F360895E7E237960D36759EFB0E72B11D9BBC03F94905D881DD05B42AD641E9AC0176950A0FD8DFD5BD121F352F28176CD298C1A80964776E4737BACEAC595E689D7F72D689C50641293E593EDD26F524C911A75AA34C401F46A199B5A73A516E863B9E7D72A712057859ED3E5178150B038F8DD02F05B23E7B4A1C4B730512FCC6EAE050137C439374B3CA74E78E1F0108D030D45B7136B407BAC130305C48B7823B98A67D608AA2A32982CCBABD83041BA2830341A1D605F11BC2B6F0A87C863B46A8482A88DC769A76BF1F6AA53D198FEB38F364DEC82B0D0A28FFF7DBE21542D422D0275DE179FE18E77088AD4EE6D98B3AC6DD27516EFFBC64F533434F0203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E0416041479B459E67BB6E5E40173800888C81A58F6E99B6E300D06092A864886F70D01010B05000382020100551F58A9BCB2A850D00CB1D81A6920272908AC61755C8A6EF882E5692FD5F6564BB9B8731059D321977EE74C71FBB2D260AD39A80BEA17215685F1500E59EBCEE059E9BAC915EF869D8F8480F6E4E99190DC179B621B45F06695D27C6FC2EA3BEF1FCFCBD6AE27F1A9B0C8AEFD7D7E9AFA2204EBFFD97FEA912B22B1170E8FF28A345B58D8FC01C954B9B826CC8A8833894C2D843C82DFEE965705BA2CBBF7C4B7C74E3B82BE31C822737392D1C280A43939103323824C3C9F86B255981DBE29868C229B9EE26B3B573A82704DDC09C789CB0A074D6CE85D8EC9EFCEABC7BBB52B4E45D64AD026CCE572CA086AA595E315A1F7A4EDC92C5FA5FBFFAC28022EBED77BBBE3717B9016D3075E46537C3707428CD3C4969CD599B52AE0951A8048AE4C3907CECC47A452952BBAB8FBADD233537DE51D4D6DD5A1B1C7426FE64027355CA328B7078DE78D3390E7239FFB509C796C46D5B415B3966E7E9B0C963AB8522D3FD65BE1FB08C284FE24A8A389DAAC6AE1182AB1A843615BD31FDC3B8D76F22DE88D75DF17336C3D53FB7BCB415FFFDCA2D06138E196B8AC5D8B37D775D533C09911AE9D41C1727584BE0241425F67244894D19B27BE073FB9B84F817451E17AB7ED9D23E2BEE0D52804133C31039EDD7A6C8FC60718C67FDE478E3F289E0406CFA5543477BDEC899BE91743DF5BDB5FFE8E1E57A2CD409D7E6222DADE1827
(PID) Process:(268) Advanced_Uninstaller13.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8
Operation:writeName:Blob
Value:
0400000001000000100000000CD2F9E0DA1773E9ED864DA5E370E74E0F00000001000000200000003F0411EDE9C4477057D57E57883B1F205B20CDC0F3263129B1EE0269A2678F63030000000100000014000000CABD2A79A1076A31F21D253635CB039D4329A5E809000000010000000C000000300A06082B060105050703011D000000010000001000000073B6876195F5D18E048510422AEF04E314000000010000001400000079B459E67BB6E5E40173800888C81A58F6E99B6E0B000000010000001A0000004900530052004700200052006F006F007400200058003100000062000000010000002000000096BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C61900000001000000100000002FE1F70BB05D7C92335BC5E05B984DA620000000010000006F0500003082056B30820353A0030201020211008210CFB0D240E3594463E0BB63828B00300D06092A864886F70D01010B0500304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F74205831301E170D3135303630343131303433385A170D3335303630343131303433385A304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F7420583130820222300D06092A864886F70D01010105000382020F003082020A0282020100ADE82473F41437F39B9E2B57281C87BEDCB7DF38908C6E3CE657A078F775C2A2FEF56A6EF6004F28DBDE68866C4493B6B163FD14126BBF1FD2EA319B217ED1333CBA48F5DD79DFB3B8FF12F1219A4BC18A8671694A66666C8F7E3C70BFAD292206F3E4C0E680AEE24B8FB7997E94039FD347977C99482353E838AE4F0A6F832ED149578C8074B6DA2FD0388D7B0370211B75F2303CFA8FAEDDDA63ABEB164FC28E114B7ECF0BE8FFB5772EF4B27B4AE04C12250C708D0329A0E15324EC13D9EE19BF10B34A8C3F89A36151DEAC870794F46371EC2EE26F5B9881E1895C34796C76EF3B906279E6DBA49A2F26C5D010E10EDED9108E16FBB7F7A8F7C7E50207988F360895E7E237960D36759EFB0E72B11D9BBC03F94905D881DD05B42AD641E9AC0176950A0FD8DFD5BD121F352F28176CD298C1A80964776E4737BACEAC595E689D7F72D689C50641293E593EDD26F524C911A75AA34C401F46A199B5A73A516E863B9E7D72A712057859ED3E5178150B038F8DD02F05B23E7B4A1C4B730512FCC6EAE050137C439374B3CA74E78E1F0108D030D45B7136B407BAC130305C48B7823B98A67D608AA2A32982CCBABD83041BA2830341A1D605F11BC2B6F0A87C863B46A8482A88DC769A76BF1F6AA53D198FEB38F364DEC82B0D0A28FFF7DBE21542D422D0275DE179FE18E77088AD4EE6D98B3AC6DD27516EFFBC64F533434F0203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E0416041479B459E67BB6E5E40173800888C81A58F6E99B6E300D06092A864886F70D01010B05000382020100551F58A9BCB2A850D00CB1D81A6920272908AC61755C8A6EF882E5692FD5F6564BB9B8731059D321977EE74C71FBB2D260AD39A80BEA17215685F1500E59EBCEE059E9BAC915EF869D8F8480F6E4E99190DC179B621B45F06695D27C6FC2EA3BEF1FCFCBD6AE27F1A9B0C8AEFD7D7E9AFA2204EBFFD97FEA912B22B1170E8FF28A345B58D8FC01C954B9B826CC8A8833894C2D843C82DFEE965705BA2CBBF7C4B7C74E3B82BE31C822737392D1C280A43939103323824C3C9F86B255981DBE29868C229B9EE26B3B573A82704DDC09C789CB0A074D6CE85D8EC9EFCEABC7BBB52B4E45D64AD026CCE572CA086AA595E315A1F7A4EDC92C5FA5FBFFAC28022EBED77BBBE3717B9016D3075E46537C3707428CD3C4969CD599B52AE0951A8048AE4C3907CECC47A452952BBAB8FBADD233537DE51D4D6DD5A1B1C7426FE64027355CA328B7078DE78D3390E7239FFB509C796C46D5B415B3966E7E9B0C963AB8522D3FD65BE1FB08C284FE24A8A389DAAC6AE1182AB1A843615BD31FDC3B8D76F22DE88D75DF17336C3D53FB7BCB415FFFDCA2D06138E196B8AC5D8B37D775D533C09911AE9D41C1727584BE0241425F67244894D19B27BE073FB9B84F817451E17AB7ED9D23E2BEE0D52804133C31039EDD7A6C8FC60718C67FDE478E3F289E0406CFA5543477BDEC899BE91743DF5BDB5FFE8E1E57A2CD409D7E6222DADE1827
(PID) Process:(268) Advanced_Uninstaller13.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Innovative Solutions\Advanced Uninstaller PRO\13\Settings
Operation:writeName:language_folder
Value:
C:\ProgramData\Innovative Solutions\Advanced Uninstaller
(PID) Process:(2740) uninstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:writeName:C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\uninstaller.exe
Value:
DisableNXShowUI
(PID) Process:(2740) uninstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2740) uninstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2472) uninstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:writeName:C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\uninstaller.exe
Value:
DisableNXShowUI
(PID) Process:(2472) uninstaller.exeKey:HKEY_CURRENT_USER\Software\Innovative Solutions\Advanced Uninstaller PRO\Settings
Operation:writeName:LocalizerExt
Value:
EXE
(PID) Process:(2560) uninstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:writeName:C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\uninstaller.exe
Value:
DisableNXShowUI
Executable files
39
Suspicious files
266
Text files
226
Unknown types
1

Dropped files

PID
Process
Filename
Type
268Advanced_Uninstaller13.tmpC:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\is-H0MMP.tmp
MD5:
SHA256:
268Advanced_Uninstaller13.tmpC:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\coupons.bin
MD5:
SHA256:
268Advanced_Uninstaller13.tmpC:\Users\admin\AppData\Local\Temp\is-2MKE9.tmp\analytics_v2.dllexecutable
MD5:6A4CACB69B796FB55C332F1B19A78B9B
SHA256:A1AB57237F4CFA03713EC9C72E89C7466B558D9A9E08AAAD7F4B8E98A2083BD3
268Advanced_Uninstaller13.tmpC:\Users\admin\AppData\Local\Temp\is-2MKE9.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
268Advanced_Uninstaller13.tmpC:\Users\admin\AppData\Local\Temp\Cab2DA.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
268Advanced_Uninstaller13.tmpC:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\is-KFUNB.tmpexecutable
MD5:3E48D32FCA25227840BCE192002A7570
SHA256:CDACA0F068B62612766C2E275EE3C702742E509F08642640C3DFAE4DDC8111B6
268Advanced_Uninstaller13.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:0F952D396F29FE5AAD68C3DD460A6E7F
SHA256:4D31A568833C9B2E634DE37223DCCFB85CF04ABF519917F90E29A6B14F6D341B
268Advanced_Uninstaller13.tmpC:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\unins000.exeexecutable
MD5:3E48D32FCA25227840BCE192002A7570
SHA256:CDACA0F068B62612766C2E275EE3C702742E509F08642640C3DFAE4DDC8111B6
268Advanced_Uninstaller13.tmpC:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\is-IPOCT.tmpexecutable
MD5:739EFAB20532083C3B91BD6C7BFF9817
SHA256:3188EE4A2DADCABA790992C18D65A430E1AB0D4703D82D091AB2E16271293C91
492Advanced_Uninstaller13.exeC:\Users\admin\AppData\Local\Temp\is-5A8ET.tmp\Advanced_Uninstaller13.tmpexecutable
MD5:D53D6662DB091C3233AB56AB7E2BABD0
SHA256:C9B49399B3DEC9003AE924736F7C947CA2A8821EF31797145A9C241DD91429C1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
87
DNS requests
93
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
268
Advanced_Uninstaller13.tmp
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?bbdfe4b13a85bec4
unknown
compressed
65.2 Kb
unknown
2560
uninstaller.exe
GET
404
168.119.201.56:80
http://www.advanceduninstaller.com/promo8///_v3.xml
unknown
html
2.24 Kb
unknown
2964
uninstaller.exe
GET
200
168.119.201.56:80
http://www.advanceduninstaller.com/promo8//Other%20websites/_v3.xml
unknown
text
5.20 Kb
unknown
2964
uninstaller.exe
GET
404
168.119.201.56:80
http://www.advanceduninstaller.com/promo8/Other%20websites/ntv/bonus-2/small_buy_n.bmp
unknown
html
2.24 Kb
unknown
268
Advanced_Uninstaller13.tmp
GET
200
34.117.186.192:80
http://ipinfo.io/json
unknown
binary
263 b
unknown
2964
uninstaller.exe
GET
200
168.119.201.56:80
http://www.advanceduninstaller.com/promo8//Other%20websites/_default/bonus-2/small_buy_n.bmp
unknown
image
49.4 Kb
unknown
3428
msedge.exe
GET
200
168.119.201.56:80
http://www.advanceduninstaller.com/welcome/?c=DE
unknown
html
12.9 Kb
unknown
3428
msedge.exe
GET
200
168.119.201.56:80
http://www.advanceduninstaller.com/vendor/bootstrap/css/bootstrap.min.css
unknown
text
141 Kb
unknown
3428
msedge.exe
GET
200
168.119.201.56:80
http://www.advanceduninstaller.com/vendor/font/css/fontawesome-all.css
unknown
text
42.2 Kb
unknown
2964
uninstaller.exe
POST
200
168.119.201.56:80
http://www.advanceduninstaller.com/app-info/get-comments.php
unknown
text
3.98 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
268
Advanced_Uninstaller13.tmp
34.117.186.192:443
ipinfo.io
GOOGLE-CLOUD-PLATFORM
US
unknown
268
Advanced_Uninstaller13.tmp
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
268
Advanced_Uninstaller13.tmp
142.250.185.174:443
www.google-analytics.com
GOOGLE
US
whitelisted
268
Advanced_Uninstaller13.tmp
34.117.186.192:80
ipinfo.io
GOOGLE-CLOUD-PLATFORM
US
unknown
2560
uninstaller.exe
168.119.201.56:80
dhc.advanceduninstaller.com
Hetzner Online GmbH
UA
unknown
2964
uninstaller.exe
168.119.201.56:80
dhc.advanceduninstaller.com
Hetzner Online GmbH
UA
unknown
2460
msedge.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
ipinfo.io
  • 34.117.186.192
shared
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
www.google-analytics.com
  • 142.250.185.174
whitelisted
dhc.advanceduninstaller.com
  • 168.119.201.56
unknown
www.advanceduninstaller.com
  • 168.119.201.56
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.31.251.109
whitelisted
innofiles.com
  • 168.119.201.56
unknown

Threats

PID
Process
Class
Message
268
Advanced_Uninstaller13.tmp
Device Retrieving External IP Address Detected
ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io)
268
Advanced_Uninstaller13.tmp
Misc activity
ET ADWARE_PUP Drivermax Utility Checkin Activity
268
Advanced_Uninstaller13.tmp
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ipinfo.io
Process
Message
pwsh.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 2204. Message ID: [0x2509].