| File name: | uninstalltool_setup.exe |
| Full analysis: | https://app.any.run/tasks/85c12a07-ab3a-4fbe-bb7a-e1a41c814b4d |
| Verdict: | Malicious activity |
| Analysis date: | May 25, 2025, 08:38:31 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections |
| MD5: | 417161BEF8A9990D7D99CD660042608D |
| SHA1: | 8B319C3EC6CFF5A598F7EE3BE643A1E13AC85A1B |
| SHA256: | 66B696E76AF8E72272883E22E7F5E42E168195C2E42FDDF6D9E4E59C8A003EE4 |
| SSDEEP: | 98304:f+cD4dnWeMKkjdkBAuk9YJiPrBZ5di+yDumsoaU2O0t1B1U3gTie+zr68BFRHooH:Jc5PsqvZBph |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 102912 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.7.4.0 |
| ProductVersionNumber: | 3.7.4.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | CrystalIDEA Software |
| FileDescription: | Uninstall Tool Setup |
| FileVersion: | Uninstall Tool |
| LegalCopyright: | Copyright © CrystalIDEA Software |
| OriginalFileName: | uninstalltool_setup.exe |
| ProductName: | Uninstall Tool |
| ProductVersion: | 3.7.4 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 960 | "C:\Program Files\Uninstall Tool\UninstallTool.exe" /admin /tasksch | C:\Program Files\Uninstall Tool\UninstallTool.exe | svchost.exe | ||||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Uninstall Tool Version: 3.7.4.5725 Modules
| |||||||||||||||
| 3100 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4628 | "C:\Program Files\Uninstall Tool\UninstallToolHelper.exe" /pid:960 | C:\Program Files\Uninstall Tool\UninstallToolHelper.exe | — | UninstallTool.exe | |||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Uninstall Tool Helper Process Version: 1, 1, 17, 5 | |||||||||||||||
| 5492 | C:\WINDOWS\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6112 | "C:\Program Files\Uninstall Tool\UninstallTool.exe" | C:\Program Files\Uninstall Tool\UninstallTool.exe | — | explorer.exe | |||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: MEDIUM Description: Uninstall Tool Exit code: 0 Version: 3.7.4.5725 Modules
| |||||||||||||||
| 6744 | C:\WINDOWS\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09} | C:\Windows\System32\dllhost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7224 | "C:\Program Files\Uninstall Tool\UninstallToolHelper.exe" /pid:8120 | C:\Program Files\Uninstall Tool\UninstallToolHelper.exe | — | UninstallTool.exe | |||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Uninstall Tool Helper Process Exit code: 0 Version: 1, 1, 17, 5 Modules
| |||||||||||||||
| 7440 | "C:\Users\admin\AppData\Local\Temp\uninstalltool_setup.exe" | C:\Users\admin\AppData\Local\Temp\uninstalltool_setup.exe | explorer.exe | ||||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: MEDIUM Description: Uninstall Tool Setup Exit code: 0 Version: Uninstall Tool Modules
| |||||||||||||||
| 7500 | "C:\Users\admin\AppData\Local\Temp\is-NICNJ.tmp\uninstalltool_setup.tmp" /SL5="$50270,4977297,845824,C:\Users\admin\AppData\Local\Temp\uninstalltool_setup.exe" | C:\Users\admin\AppData\Local\Temp\is-NICNJ.tmp\uninstalltool_setup.tmp | — | uninstalltool_setup.exe | |||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 7524 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5492) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:0000000000040352 |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456BFA0DB55E4278845B426357D5B5F97B3 | |||
| (PID) Process: | (5492) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:000000000004028A |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456BFA0DB55E4278845B426357D5B5F97B3 | |||
| (PID) Process: | (7728) uninstalltool_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\CrystalIdea Software\Uninstall Tool |
| Operation: | write | Name: | DriverVersionNum |
Value: 262 | |||
| (PID) Process: | (5492) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop |
| Operation: | write | Name: | IconLayouts |
Value: 00000000000000000000000000000000030001000100010014000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000000D0000000000000053006B007900700065002E006C006E006B003E0020007C000000110000000000000069006E006400650078006200610063006B002E0070006E0067003E002000200000001400000000000000620072006F007700730065006D006500740068006F0064002E007200740066003E002000200000001700000000000000630061006C0065006E0064006100720077006800650074006800650072002E007200740066003E002000200000001300000000000000630061006C006C00740068006F0075006700680074002E0070006E0067003E002000200000001500000000000000650076006500720079006F006E0065006D006F006E00740068002E007200740066003E0020002000000012000000000000006A00610063006B006C0065006E006700740068002E006A00700067003E0020002000000014000000000000006C006F0077006500720077006800650074006800650072002E0070006E0067003E0020002000000015000000000000006F006E006C007900650071007500690070006D0065006E0074002E007200740066003E00200020000000160000000000000072006500730070006F006E00730065007300650072007600650072002E007200740066003E002000200000000F0000000000000073006F006E0067006C00650074002E0070006E0067003E002000200000000F0000000000000073007400650070006100630074002E006A00700067003E00200020000000160000000000000055006E0069006E007300740061006C006C00200054006F006F006C002E006C006E006B003E0020002000000001000000000000000200010000000000000000000100000000000000020001000000000000000000110000000600000001000000140000000000000000000000000000000000000040400000803F13000000803F0000404009000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000400000A040110000004040000000001200000000000000803F0100000000000000004002000000000000004040030000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F07000000803F000000400800 | |||
| (PID) Process: | (5492) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop |
| Operation: | write | Name: | IconNameVersion |
Value: 1 | |||
| (PID) Process: | (5492) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:000000000002022A |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456BFA0DB55E4278845B426357D5B5F97B3 | |||
| (PID) Process: | (5492) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts |
| Operation: | write | Name: | LastUpdate |
Value: 1AD7326800000000 | |||
| (PID) Process: | (7856) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE8E6AD6-DABE-45E1-88C2-48DC4578924C}\InProcServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
| (PID) Process: | (7856) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 18 | |||
| (PID) Process: | (7856) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved |
| Operation: | write | Name: | {FE8E6AD6-DABE-45E1-88C2-48DC4578924C} |
Value: UTShellExt | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7440 | uninstalltool_setup.exe | C:\Users\admin\AppData\Local\Temp\is-NICNJ.tmp\uninstalltool_setup.tmp | executable | |
MD5:8C1451188764F81954E6D4672100433A | SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD | |||
| 7728 | uninstalltool_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-KT0NK.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 5492 | explorer.exe | C:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat | binary | |
MD5:E49C56350AEDF784BFE00E444B879672 | SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E | |||
| 7692 | uninstalltool_setup.exe | C:\Users\admin\AppData\Local\Temp\is-MQ9J6.tmp\uninstalltool_setup.tmp | executable | |
MD5:8C1451188764F81954E6D4672100433A | SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD | |||
| 7728 | uninstalltool_setup.tmp | C:\Program Files\Uninstall Tool\is-3PHE1.tmp | executable | |
MD5:4DE7220115FE537EAF6C5776E83F0064 | SHA256:E87288744CC29C5AB81D9C3FA78653CACD87BC74BF5A3ABC4F38AFCD6A1A5C16 | |||
| 7728 | uninstalltool_setup.tmp | C:\Program Files\Uninstall Tool\is-TKJUQ.tmp | executable | |
MD5:8C1451188764F81954E6D4672100433A | SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD | |||
| 7728 | uninstalltool_setup.tmp | C:\Program Files\Uninstall Tool\PinToTaskbar.exe | executable | |
MD5:4DE7220115FE537EAF6C5776E83F0064 | SHA256:E87288744CC29C5AB81D9C3FA78653CACD87BC74BF5A3ABC4F38AFCD6A1A5C16 | |||
| 7728 | uninstalltool_setup.tmp | C:\Program Files\Uninstall Tool\is-3FVI9.tmp | executable | |
MD5:4C415ADB0750FE1E1D2F52C3902274C0 | SHA256:7D0A990C0B976FF4D99ABFA935EADEBCECE34E7D4E711ED86066AB7845D6A417 | |||
| 7728 | uninstalltool_setup.tmp | C:\Program Files\Uninstall Tool\unins000.exe | executable | |
MD5:8C1451188764F81954E6D4672100433A | SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD | |||
| 7728 | uninstalltool_setup.tmp | C:\Program Files\Uninstall Tool\PinToTaskbarHelper.dll | executable | |
MD5:4C415ADB0750FE1E1D2F52C3902274C0 | SHA256:7D0A990C0B976FF4D99ABFA935EADEBCECE34E7D4E711ED86066AB7845D6A417 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
8120 | UninstallTool.exe | GET | 200 | 2.19.105.127:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
8120 | UninstallTool.exe | GET | 200 | 2.22.242.225:80 | http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgb%2BxzVcNt%2FVHDBxJLsu%2FnGhiQ%3D%3D | unknown | — | — | whitelisted |
7276 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.168.114:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
8120 | UninstallTool.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEQDfD%2FoApQz6Tjifa39Nky1P | unknown | — | — | whitelisted |
8120 | UninstallTool.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D | unknown | — | — | whitelisted |
8120 | UninstallTool.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7276 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2340 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.168.114:80 | crl.microsoft.com | Akamai International B.V. | RU | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.31.73:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crystalidea.com |
| unknown |
ocsp.comodoca.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |