File name:

Driver_Updater_setup.exe

Full analysis: https://app.any.run/tasks/3ca6e6c7-e9af-4704-927d-5ce62f2d14c7
Verdict: Malicious activity
Analysis date: July 05, 2024, 20:15:06
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B7843358B89B468731B6DA637100A639

SHA1:

1941CD27AED1296CB3A549712967F6F8B5A23238

SHA256:

5DC9237F8F3D1088D02CCDC24098D7BAF7B3C9E5DECAFB30632FA1183AF174AC

SSDEEP:

98304:7+QqZ8fkhL4lMReXlNfUBJYZ35eJHcOpJn5KZD5pk0uypuJTMVLagOVFp+OKCJbj:Zri9i9rtsrWQL2/uN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Driver_Updater_setup.exe (PID: 3996)
      • Driver_Updater_setup.tmp (PID: 6376)
      • Driver_Updater_setup.exe (PID: 6340)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 3936)
      • drvinst.exe (PID: 1768)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Driver_Updater_setup.exe (PID: 3996)
      • Driver_Updater_setup.tmp (PID: 6376)
      • Driver_Updater_setup.exe (PID: 6340)
    • Reads security settings of Internet Explorer

      • Driver_Updater_setup.tmp (PID: 3968)
      • PCHelpSoftDriverUpdater.exe (PID: 6452)
      • PCHelpSoftDriverUpdater.exe (PID: 6796)
      • stub64.exe (PID: 2668)
    • Reads the date of Windows installation

      • Driver_Updater_setup.tmp (PID: 3968)
      • PCHelpSoftDriverUpdater.exe (PID: 6452)
      • PCHelpSoftDriverUpdater.exe (PID: 6796)
    • Reads the Windows owner or organization settings

      • Driver_Updater_setup.tmp (PID: 6376)
    • Drops 7-zip archiver for unpacking

      • Driver_Updater_setup.tmp (PID: 6376)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 6584)
      • schtasks.exe (PID: 6600)
    • Application launched itself

      • PCHelpSoftDriverUpdater.exe (PID: 6796)
    • Checks Windows Trust Settings

      • PCHelpSoftDriverUpdater.exe (PID: 6796)
      • stub64.exe (PID: 2668)
      • drvinst.exe (PID: 3936)
    • Executes as Windows Service

      • VSSVC.exe (PID: 5980)
    • Searches for installed software

      • dllhost.exe (PID: 6672)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3936)
  • INFO

    • Checks supported languages

      • Driver_Updater_setup.exe (PID: 3996)
      • Driver_Updater_setup.exe (PID: 6340)
      • Driver_Updater_setup.tmp (PID: 3968)
      • Driver_Updater_setup.tmp (PID: 6376)
      • PCHelpSoftDriverUpdater.exe (PID: 6452)
      • PCHelpSoftDriverUpdater.exe (PID: 6796)
      • DriverPro.exe (PID: 6816)
      • PCHelpSoftDriverUpdater.exe (PID: 6948)
      • identity_helper.exe (PID: 5112)
      • stub64.exe (PID: 2668)
      • drvinst.exe (PID: 3936)
      • drvinst.exe (PID: 1768)
    • Create files in a temporary directory

      • Driver_Updater_setup.exe (PID: 3996)
      • Driver_Updater_setup.exe (PID: 6340)
      • Driver_Updater_setup.tmp (PID: 6376)
      • PCHelpSoftDriverUpdater.exe (PID: 6796)
      • stub64.exe (PID: 2668)
    • Creates files in the program directory

      • Driver_Updater_setup.tmp (PID: 6376)
      • DriverPro.exe (PID: 6816)
      • PCHelpSoftDriverUpdater.exe (PID: 6796)
    • Process checks computer location settings

      • Driver_Updater_setup.tmp (PID: 3968)
      • PCHelpSoftDriverUpdater.exe (PID: 6452)
      • PCHelpSoftDriverUpdater.exe (PID: 6948)
      • PCHelpSoftDriverUpdater.exe (PID: 6796)
    • Reads the computer name

      • Driver_Updater_setup.tmp (PID: 6376)
      • PCHelpSoftDriverUpdater.exe (PID: 6452)
      • Driver_Updater_setup.tmp (PID: 3968)
      • PCHelpSoftDriverUpdater.exe (PID: 6796)
      • DriverPro.exe (PID: 6816)
      • PCHelpSoftDriverUpdater.exe (PID: 6948)
      • identity_helper.exe (PID: 5112)
      • stub64.exe (PID: 2668)
      • drvinst.exe (PID: 3936)
      • drvinst.exe (PID: 1768)
    • Creates a software uninstall entry

      • Driver_Updater_setup.tmp (PID: 6376)
    • Reads Environment values

      • PCHelpSoftDriverUpdater.exe (PID: 6452)
      • PCHelpSoftDriverUpdater.exe (PID: 6796)
      • DriverPro.exe (PID: 6816)
      • PCHelpSoftDriverUpdater.exe (PID: 6948)
      • stub64.exe (PID: 2668)
    • Creates files or folders in the user directory

      • PCHelpSoftDriverUpdater.exe (PID: 6452)
      • PCHelpSoftDriverUpdater.exe (PID: 6948)
      • PCHelpSoftDriverUpdater.exe (PID: 6796)
    • Reads Windows Product ID

      • PCHelpSoftDriverUpdater.exe (PID: 6796)
    • Checks proxy server information

      • PCHelpSoftDriverUpdater.exe (PID: 6796)
    • Reads the software policy settings

      • PCHelpSoftDriverUpdater.exe (PID: 6796)
      • stub64.exe (PID: 2668)
      • drvinst.exe (PID: 3936)
    • Application launched itself

      • msedge.exe (PID: 2208)
      • msedge.exe (PID: 7076)
      • msedge.exe (PID: 6512)
    • Manual execution by a user

      • msedge.exe (PID: 7076)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 2208)
      • msedge.exe (PID: 7076)
      • msedge.exe (PID: 6512)
    • Reads the machine GUID from the registry

      • PCHelpSoftDriverUpdater.exe (PID: 6796)
      • stub64.exe (PID: 2668)
      • drvinst.exe (PID: 3936)
    • Reads product name

      • PCHelpSoftDriverUpdater.exe (PID: 6796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 08:09:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 68096
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.1.1290.0
ProductVersionNumber: 7.1.1290.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: PC HelpSoft
FileDescription: PC HelpSoft Driver Updater
FileVersion: 7.1.1290.0
LegalCopyright: PC HelpSoft
OriginalFileName:
ProductName: PC HelpSoft Driver Updater
ProductVersion: 7.1.1290.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
207
Monitored processes
59
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
start driver_updater_setup.exe driver_updater_setup.tmp no specs driver_updater_setup.exe driver_updater_setup.tmp pchelpsoftdriverupdater.exe no specs schtasks.exe no specs schtasks.exe no specs conhost.exe no specs conhost.exe no specs pchelpsoftdriverupdater.exe driverpro.exe no specs pchelpsoftdriverupdater.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs stub64.exe no specs drvinst.exe no specs drvinst.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1060"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2280 --field-trial-handle=2092,i,16039635858461620177,2534678969557453908,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1112"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4544 --field-trial-handle=2092,i,16039635858461620177,2534678969557453908,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1388"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=5064 --field-trial-handle=2092,i,16039635858461620177,2534678969557453908,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1768DrvInst.exe "2" "211" "DISPLAY\DEFAULT_MONITOR\4&77741E3&0&UID0" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:b35215b02a718921:MX279.Install:1.0.0.0:monitor\default_monitor," "73328988f" "00000000000001CC"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1888"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3716 --field-trial-handle=2092,i,16039635858461620177,2534678969557453908,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2060"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=4212 --field-trial-handle=2484,i,2442977518844476807,15546215151716430557,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2128"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4696 --field-trial-handle=2092,i,16039635858461620177,2534678969557453908,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2208"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://store.pchelpsoft.com/clickgate/join.aspx?ref=pchelpsoft.com&ujid=n4l4AdUDqyE%3D&ename=Try&visitorid=39c0982b-e527-99b3-7a5e-9dfe18e011ea&culture=de&referral=www.pchelpsoft.com/static/lp/driver-updater/de/LP19.php&ref=pchelpsoft.com&wid=1593&uid=1020465&cmp=bingads&src=Direct&mkey1=ph_gsc_de_pp_bi_se_du&mkey4=39c0982b-e527-99b3-7a5e-9dfe18e011ea&mkey5=/static/lp/driver-updater/de/LP19.php&mkey6=2a03ccb0-2074-6327-edf4-ef35462d6977_2024-06-02&mkey9=none&qti=2a03ccb0-2074-6327-edf4-ef35462d6977_2024-06-02&partner=none&cid=237392623.1717339967&product=driver-updater&country_iso=DE&ip=84.17.48.96&HostBrowser=ED&software=driverupdater&mkey3=win_scan-reg&mkey6=0&mkey7=NO_TRIALC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2412"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4704 --field-trial-handle=2092,i,16039635858461620177,2534678969557453908,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2668"C:\Program Files (x86)\PC HelpSoft Driver Updater\stub64.exe" install "MONITOR\DEFAULT_MONITOR" "C:\ProgramData\PC HelpSoft Driver Updater\Drivers\69122D35A016ED65B2C48DB81D6E214160EAD841\mx279.inf"C:\Program Files (x86)\PC HelpSoft Driver Updater\stub64.exePCHelpSoftDriverUpdater.exe
User:
admin
Company:
PC HelpSoft
Integrity Level:
HIGH
Description:
PC HelpSoft Driver Updater Helper
Exit code:
0
Version:
7.1.1290
Modules
Images
c:\program files (x86)\pc helpsoft driver updater\stub64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
38 019
Read events
37 434
Write events
541
Delete events
44

Modification events

(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
E8180000144A2D0D18CFDA01
(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
BE9F97B6F6025021273F8DB0C3B45FCDF3228E094C6B9C2E4C51D3B570345CFF
(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\DriverPro.exe
(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
2DB4A8283012ABD1704156A9B604C33E612F83B1036B86A69106223E0FDB6490
(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.HDM_encrypted\OpenWithProgids
Operation:writeName:PCHelpSoftDriverUpdater.HDM_encrypted
Value:
(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\PCHelpSoftDriverUpdater.exe\SupportedTypes
Operation:writeName:.HDM_encrypted
Value:
(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\PC HelpSoft Driver Updater
Operation:writeName:Language
Value:
1
(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\PC HelpSoft Driver Updater
Operation:writeName:DelayedStart
Value:
0
(PID) Process:(6376) Driver_Updater_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\PC HelpSoft Driver Updater
Operation:writeName:SetupName
Value:
C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe
Executable files
27
Suspicious files
138
Text files
168
Unknown types
18

Dropped files

PID
Process
Filename
Type
3996Driver_Updater_setup.exeC:\Users\admin\AppData\Local\Temp\is-5NR68.tmp\Driver_Updater_setup.tmpexecutable
MD5:B244D6E17EC10CEC9C9547B4B1093DBC
SHA256:644E60298D0625584B9A9AF24F1B02D571DFAFD49B6BC7F919F70F185455E8E4
6376Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\unins000.exeexecutable
MD5:B244D6E17EC10CEC9C9547B4B1093DBC
SHA256:644E60298D0625584B9A9AF24F1B02D571DFAFD49B6BC7F919F70F185455E8E4
6376Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\is-KTJ6I.tmpexecutable
MD5:33BEA8D12BB5F49A948B650A882F54FE
SHA256:B82D89D84D2815B550810DCBB7F99E68B793DC152AA3838C8F953A7BE50B750F
6376Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\HDMSchedule.exeexecutable
MD5:33BEA8D12BB5F49A948B650A882F54FE
SHA256:B82D89D84D2815B550810DCBB7F99E68B793DC152AA3838C8F953A7BE50B750F
6376Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\Settings.initext
MD5:C12E324F7BA24C91F31927D7A720294A
SHA256:BAD8F599F3B38B7F67E77E26AEC057FA8849C0CB80B72AC9E7265F9DCB3AF199
6376Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\is-FJQ5E.tmpexecutable
MD5:B244D6E17EC10CEC9C9547B4B1093DBC
SHA256:644E60298D0625584B9A9AF24F1B02D571DFAFD49B6BC7F919F70F185455E8E4
6376Driver_Updater_setup.tmpC:\Users\admin\AppData\Local\Temp\is-S94TG.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6376Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\is-I4VAG.tmptext
MD5:C12E324F7BA24C91F31927D7A720294A
SHA256:BAD8F599F3B38B7F67E77E26AEC057FA8849C0CB80B72AC9E7265F9DCB3AF199
6376Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\is-DJETE.tmpexecutable
MD5:34392941C1918C5639E8C0CBFA64115E
SHA256:C825552C99C321DFBAAE6B16D797F80A6557C555689BD78AF815B0D48B0CCB05
6376Driver_Updater_setup.tmpC:\Program Files (x86)\PC HelpSoft Driver Updater\Extra\Animation.gifimage
MD5:915F2CE934FD4789216B91BF9C2609FD
SHA256:135D81FEEF8BC93E48F3D929D9249ABE56E8B0A566F51964C8CAD28602219250
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
142
DNS requests
98
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2412
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
2824
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
unknown
6796
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
4976
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
4976
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
768
lsass.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
unknown
6796
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
6796
PCHelpSoftDriverUpdater.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4976
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
3164
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3828
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4976
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6796
PCHelpSoftDriverUpdater.exe
99.86.4.112:443
offers.playanext.com
AMAZON-02
US
unknown
6796
PCHelpSoftDriverUpdater.exe
18.245.86.79:80
api.playanext.com
US
unknown
6796
PCHelpSoftDriverUpdater.exe
104.16.148.130:443
partner-tracking.lavasoft.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
drivers.avqtools.com
  • 116.203.251.147
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
api.playanext.com
  • 18.245.86.79
  • 18.245.86.84
  • 18.245.86.105
  • 18.245.86.26
whitelisted
offers.playanext.com
  • 99.86.4.112
  • 99.86.4.23
  • 99.86.4.76
  • 99.86.4.92
unknown
partner-tracking.lavasoft.com
  • 104.16.148.130
  • 104.16.149.130
unknown
collect.avqtools.com
  • 116.203.251.147
unknown
ocsp.rootca1.amazontrust.com
  • 18.245.39.64
shared
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.145
  • 23.48.23.193
  • 23.48.23.176
  • 23.48.23.173
  • 23.48.23.169
  • 23.48.23.177
  • 23.48.23.141
  • 23.48.23.158
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
cloud.pchelpsoft.com
  • 216.239.38.21
  • 216.239.34.21
  • 216.239.36.21
  • 216.239.32.21
unknown

Threats

No threats detected
No debug info