File name:

WinlockerVB6Blacksod.exe

Full analysis: https://app.any.run/tasks/fe98b19a-6f6a-4ec1-a010-417e639fe02d
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: May 16, 2025, 16:29:57
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
advancedinstaller
adware
takemyfile
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

DBFBF254CFB84D991AC3860105D66FC6

SHA1:

893110D8C8451565CAA591DDFCCF92869F96C242

SHA256:

68B0E1932F3B4439865BE848C2D592D5174DBDBAAB8F66104A0E5B28C928EE0C

SSDEEP:

49152:6kAG2QGTC5xvMdgpdb1KRHGepUu2cGbqPs9+q2HRPTnFVSLE:6kAjQGTCnvMmpYQqPNRPTnF4Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a new scheduled task via Registry

      • msiexec.exe (PID: 5380)
    • Changes the login/logoff helper path in the registry

      • msiexec.exe (PID: 7720)
    • ADWARE has been detected (SURICATA)

      • msiexec.exe (PID: 8028)
  • SUSPICIOUS

    • ADVANCEDINSTALLER mutex has been found

      • WinlockerVB6Blacksod.exe (PID: 7652)
    • Process drops legitimate windows executable

      • WinlockerVB6Blacksod.exe (PID: 7652)
    • Reads the Windows owner or organization settings

      • WinlockerVB6Blacksod.exe (PID: 7652)
      • msiexec.exe (PID: 7720)
    • Executable content was dropped or overwritten

      • WinlockerVB6Blacksod.exe (PID: 7652)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 8028)
    • Access to an unwanted program domain was detected

      • msiexec.exe (PID: 8028)
  • INFO

    • Create files in a temporary directory

      • WinlockerVB6Blacksod.exe (PID: 7652)
      • msiexec.exe (PID: 8028)
    • Reads Environment values

      • WinlockerVB6Blacksod.exe (PID: 7652)
      • msiexec.exe (PID: 8028)
    • The sample compiled with english language support

      • WinlockerVB6Blacksod.exe (PID: 7652)
      • msiexec.exe (PID: 7720)
    • Checks supported languages

      • WinlockerVB6Blacksod.exe (PID: 7652)
      • msiexec.exe (PID: 7720)
      • msiexec.exe (PID: 5380)
      • msiexec.exe (PID: 8028)
    • Reads the computer name

      • WinlockerVB6Blacksod.exe (PID: 7652)
      • msiexec.exe (PID: 7720)
      • msiexec.exe (PID: 8028)
      • msiexec.exe (PID: 5380)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7720)
    • Checks proxy server information

      • msiexec.exe (PID: 8028)
    • Creates files or folders in the user directory

      • WinlockerVB6Blacksod.exe (PID: 7652)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (78.5)
.exe | Win32 Executable (generic) (11.3)
.exe | Generic Win/DOS Executable (5)
.exe | DOS Executable Generic (5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:09:23 13:36:22+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 1034240
InitializedDataSize: 428544
UninitializedDataSize: -
EntryPoint: 0xc684c
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Windows
FileDescription: This installer database contains the logic and data required to install Error file remover.
FileVersion: 1.0.0.0
InternalName: Error file remover
LegalCopyright: Copyright (C) 2016 Windows
OriginalFileName: Error file remover.exe
ProductName: Error file remover
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winlockervb6blacksod.exe msiexec.exe msiexec.exe no specs #ADWARE msiexec.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
5380C:\Windows\syswow64\MsiExec.exe -Embedding FB7C3E12A41987929C3B6F108C981E35 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7652"C:\Users\admin\AppData\Local\Temp\WinlockerVB6Blacksod.exe" C:\Users\admin\AppData\Local\Temp\WinlockerVB6Blacksod.exe
explorer.exe
User:
admin
Company:
Windows
Integrity Level:
MEDIUM
Description:
This installer database contains the logic and data required to install Error file remover.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\winlockervb6blacksod.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7720C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7876"C:\WINDOWS\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\Windows\Error file remover 1.0.0.0\install\0A01606\Error file remover.msi" AI_SETUPEXEPATH=C:\Users\admin\AppData\Local\Temp\WinlockerVB6Blacksod.exe SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\ EXE_CMD_LINE="/exenoupdates /exelang 0 /noprereqs "C:\Windows\SysWOW64\msiexec.exeWinlockerVB6Blacksod.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
8028C:\Windows\syswow64\MsiExec.exe -Embedding FD6E4968B7331C7AF99427414F343203C:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
1 948
Read events
1 914
Write events
26
Delete events
8

Modification events

(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10ce31.rbs
Value:
31180415
(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10ce31.rbsLow
Value:
(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D45F152E5BE7289449F90D588F84BD5D
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
C:\Program Files (x86)\Windows\Error file remover\Windows Logoff Sound.wav
(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2ED206DB688193B489E86537451F75D7
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
C:\Program Files (x86)\Windows\Error file remover\fatalerror.exe
(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4FEC4D8CE9091D3499C19390B8C387CF
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
02:\Software\Caphyon\Advanced Installer\LZMA\{C452D4E2-DE24-48B6-B5C3-ACB240A01606}\1.0.0.0\AI_ExePath
(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19FD36884EFA5E041805E77DDE0ABD3B
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
02:\Software\Windows\{C452D4E2-DE24-48B6-B5C3-ACB240A01606}\AI_IA_ENABLE
(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08220BA658A8A834AA4408D695C989DF
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
02:\Software\Windows\Error file remover\Version
(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B6D6C8B1B0459D44BBC71CDA2E1D7680
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
01:\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
(PID) Process:(7720) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CF995B7322EB1E4448DD6A5F36E66D37
Operation:writeName:2E4D254C42ED6B845B3CCA2B040A6160
Value:
02:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
Executable files
19
Suspicious files
20
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
7652WinlockerVB6Blacksod.exeC:\Users\admin\AppData\Roaming\Windows\Error file remover 1.0.0.0\install\0A01606\Error file remover.msiexecutable
MD5:27BC9540828C59E1CA1997CF04F6C467
SHA256:05C18698C3DC3B2709AFD3355AD5B91A60B2121A52E5FCC474E4E47FB8E95E2A
7652WinlockerVB6Blacksod.exeC:\Users\admin\AppData\Roaming\Windows\Error file remover 1.0.0.0\install\decoder.dllexecutable
MD5:3531CF7755B16D38D5E9E3C43280E7D2
SHA256:76133E832C15AA5CBC49FB3BA09E0B8DD467C307688BE2C9E85E79D3BF62C089
7652WinlockerVB6Blacksod.exeC:\Users\admin\AppData\Roaming\Windows\Error file remover 1.0.0.0\install\holder0.aiphbinary
MD5:0E7079D29F5BE29C8406DE6F4FD175F2
SHA256:205D938ED0540A568E5F1150CC37A733CB76E7945A17A56CA57715419B9EC87F
7652WinlockerVB6Blacksod.exeC:\Users\admin\AppData\Local\Temp\shiB9AD.tmpexecutable
MD5:CE85F5D941EBCA72DA2A55835B303EB9
SHA256:6CF60B8101CBB475F3803E18617172CC180AFA4BC0CA8CA261C2AB6ED1C93EA1
8028msiexec.exeC:\Users\admin\AppData\Local\Temp\AdvinstAnalytics\Error file remover\1.0.0.0\tracking.initext
MD5:6E50AEBF7F7C81E6BB0A2ECE020C8AD8
SHA256:36A9E0FDDA6794A8F42E45DCA18769E6968EC56076C4DF214218EB5543EE98A6
7720msiexec.exeC:\Windows\Installer\MSID180.tmpexecutable
MD5:4083CB0F45A747D8E8AB0D3E060616F2
SHA256:252B7423B01FF81AEA6FE7B40DE91ABF49F515E9C0C7B95AA982756889F8AC1A
8028msiexec.exeC:\Users\admin\AppData\Local\Temp\AdvinstAnalytics\Error file remover\1.0.0.0\{F88EC141-AA6F-4464-B13C-D733CC9EF38C}.sessiontext
MD5:16EF0CA34BF1F628A25301A999D1246C
SHA256:8191E926C2CA90C1391BF3BE18B9178BF06C4AAF87FC877D077E685C82E189A8
7720msiexec.exeC:\Windows\Installer\MSID15F.tmpexecutable
MD5:D552DD4108B5665D306B4A8BD6083DDE
SHA256:A0367875B68B1699D2647A748278EBCE64D5BE633598580977AA126A81CF57C5
7720msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:329F730D1506D618649498A22B27816D
SHA256:D1BEBDF862D2B28618152CA7C4CFF18E4B78A522B7A6A8616704041DFD641E6A
7720msiexec.exeC:\Windows\Installer\MSID1B0.tmpexecutable
MD5:D552DD4108B5665D306B4A8BD6083DDE
SHA256:A0367875B68B1699D2647A748278EBCE64D5BE633598580977AA126A81CF57C5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
50
DNS requests
15
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
8028
msiexec.exe
POST
404
44.197.1.6:80
http://collect.installeranalytics.com/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
8028
msiexec.exe
44.197.1.6:80
collect.installeranalytics.com
AMAZON-AES
US
whitelisted
5116
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.142
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.3
  • 20.190.160.14
  • 20.190.160.131
  • 20.190.160.20
  • 20.190.160.22
  • 20.190.160.4
  • 20.190.160.64
  • 40.126.32.68
whitelisted
collect.installeranalytics.com
  • 44.197.1.6
  • 3.217.0.227
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
  • 2603:1030:c02:2::284
whitelisted
206.23.85.13.in-addr.arpa
unknown
4.8.2.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.0.2.0.c.0.0.3.0.1.3.0.6.2.ip6.arpa
unknown

Threats

PID
Process
Class
Message
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
8028
msiexec.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] TakeMyFile UA
No debug info