File name:

79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5

Full analysis: https://app.any.run/tasks/8a05f1f6-3353-48d1-bfa9-6bc5290d5649
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 15, 2020, 09:05:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

16682D082192E852B032D9415BB27EA3

SHA1:

F25F43D36CACF7E935A5D8701B3A4706AE7C58DF

SHA256:

79F5F05C63BA0A267271D64376AE752996AD68A29BD70CBA3F2E8FC56C4E9BE5

SSDEEP:

1536:Z4Gyjn/w0kXrC8XHoP8wJBFxtlq2La3StGhVhIdMP52sQ4SvNimKJRD:qGC/7kXrC2HoPJJBFxnq2LyStGWaPlHf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • KzT11N.exe (PID: 3120)
      • RemNPX.exe (PID: 1504)
      • UpdateTrayIcon.exe (PID: 1176)
      • QMCheckNetwork.exe (PID: 316)
      • QMCheckNetwork.exe (PID: 956)
      • InstallUninstallCube.exe (PID: 1488)
      • QMSuperScan.exe (PID: 988)
      • QQPCRTP.exe (PID: 3156)
      • QQPCRTP.exe (PID: 2084)
      • QQPCRTP.exe (PID: 2100)
      • QQPCRTP.exe (PID: 1784)
      • QQPCTray.exe (PID: 1540)
      • QQPCSoftCmd.exe (PID: 2472)
      • QQPCTray.exe (PID: 3988)
      • QQPCTray.exe (PID: 1440)
      • QQTrayMonitor.exe (PID: 2588)
      • QQPCRealTimeSpeedup.exe (PID: 916)
      • 2345Explorer_209411_silence.exe (PID: 3100)
      • VolSnapshot.exe (PID: 2784)
      • qmdl.exe (PID: 2616)
      • QQTrayMonitor.exe (PID: 3332)
      • QMBlueScreenFixSetup_13.3.20244.216__1554802502382.exe (PID: 5988)
      • QMRealTimeSpeedupSetup_13.3.20244.216__1554802502382.exe (PID: 4576)
      • 2345Explorer.exe (PID: 6132)
      • ServiceManager.exe (PID: 5776)
      • Protect_2345Explorer.exe (PID: 5264)
      • 2345SafeCenterInstaller.exe (PID: 5640)
      • 2345SafeCenterSvc.exe (PID: 1988)
      • VolSnapshot.exe (PID: 5540)
      • 2345RTProtect.exe (PID: 5152)
    • Registers / Runs the DLL via REGSVR32.EXE

      • PCMgr_Setup.exe (PID: 2636)
      • QQPCTray.exe (PID: 3988)
      • 2345SafeCenterInstaller.exe (PID: 5640)
    • Loads dropped or rewritten executable

      • QQPCSoftCmd.exe (PID: 2472)
      • QQPCRTP.exe (PID: 3156)
      • regsvr32.exe (PID: 3700)
      • QMSuperScan.exe (PID: 988)
      • regsvr32.exe (PID: 2444)
      • regsvr32.exe (PID: 2104)
      • regsvr32.exe (PID: 1764)
      • QQPCTray.exe (PID: 1540)
      • QQPCRTP.exe (PID: 2084)
      • QMCheckNetwork.exe (PID: 956)
      • QMCheckNetwork.exe (PID: 316)
      • QQPCRTP.exe (PID: 2100)
      • QQPCRTP.exe (PID: 1784)
      • QQPCTray.exe (PID: 3988)
      • QQPCTray.exe (PID: 1440)
      • InstallUninstallCube.exe (PID: 1488)
      • QQTrayMonitor.exe (PID: 2588)
      • QQPCRealTimeSpeedup.exe (PID: 916)
      • 2345Explorer_209411_silence.exe (PID: 3100)
      • regsvr32.exe (PID: 3040)
      • QQTrayMonitor.exe (PID: 3332)
      • VolSnapshot.exe (PID: 2784)
      • explorer.exe (PID: 372)
      • qmdl.exe (PID: 2616)
      • QMBlueScreenFixSetup_13.3.20244.216__1554802502382.exe (PID: 5988)
      • 2345SafeCenterInstaller.exe (PID: 5640)
      • 2345SafeCenterSvc.exe (PID: 1988)
      • VolSnapshot.exe (PID: 5540)
      • 2345RTProtect.exe (PID: 5152)
    • Actions looks like stealing of personal data

      • QQPCTray.exe (PID: 3988)
      • QQPCRTP.exe (PID: 1784)
    • Drops executable file immediately after starts

      • 2345Explorer_209411_silence.exe (PID: 3100)
    • Changes settings of System certificates

      • QQPCTray.exe (PID: 3988)
      • QQPCRTP.exe (PID: 1784)
    • Loads the Task Scheduler COM API

      • QQPCTray.exe (PID: 3988)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe (PID: 2044)
      • PCMgr_Setup.exe (PID: 2636)
      • QQPCTray.exe (PID: 3988)
      • 2345Explorer_209411_silence.exe (PID: 3100)
      • QQPCRealTimeSpeedup.exe (PID: 916)
      • qmdl.exe (PID: 2616)
      • QQPCRTP.exe (PID: 1784)
      • QMBlueScreenFixSetup_13.3.20244.216__1554802502382.exe (PID: 5988)
      • 2345SafeCenterInstaller.exe (PID: 5640)
    • Uses SYSTEMINFO.EXE to read environment

      • 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe (PID: 2044)
    • Executes scripts

      • KzT11N.exe (PID: 3120)
    • Low-level read access rights to disk partition

      • PCMgr_Setup.exe (PID: 2636)
      • QMSuperScan.exe (PID: 988)
      • QQPCRTP.exe (PID: 1784)
      • QQPCTray.exe (PID: 3988)
    • Creates files in the user directory

      • PCMgr_Setup.exe (PID: 2636)
      • QQPCSoftCmd.exe (PID: 2472)
      • QMSuperScan.exe (PID: 988)
      • QQPCTray.exe (PID: 3988)
      • qmdl.exe (PID: 2616)
      • 2345Explorer_209411_silence.exe (PID: 3100)
      • 2345SafeCenterInstaller.exe (PID: 5640)
    • Drops a file with a compile date too recent

      • KzT11N.exe (PID: 3120)
      • PCMgr_Setup.exe (PID: 2636)
      • 2345Explorer_209411_silence.exe (PID: 3100)
    • Drops a file with too old compile date

      • PCMgr_Setup.exe (PID: 2636)
      • QQPCTray.exe (PID: 3988)
      • QMBlueScreenFixSetup_13.3.20244.216__1554802502382.exe (PID: 5988)
      • qmdl.exe (PID: 2616)
      • 2345Explorer_209411_silence.exe (PID: 3100)
    • Changes default file association

      • PCMgr_Setup.exe (PID: 2636)
      • QQPCTray.exe (PID: 3988)
      • 2345Explorer_209411_silence.exe (PID: 3100)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2444)
      • regsvr32.exe (PID: 3700)
      • regsvr32.exe (PID: 2104)
      • regsvr32.exe (PID: 1764)
      • QQPCTray.exe (PID: 3988)
      • regsvr32.exe (PID: 3040)
    • Creates files in the program directory

      • QQPCSoftCmd.exe (PID: 2472)
      • QQPCRTP.exe (PID: 3156)
      • PCMgr_Setup.exe (PID: 2636)
      • InstallUninstallCube.exe (PID: 1488)
      • QQPCTray.exe (PID: 3988)
      • QQPCRTP.exe (PID: 1784)
      • QMSuperScan.exe (PID: 988)
      • QQPCRealTimeSpeedup.exe (PID: 916)
      • 2345Explorer_209411_silence.exe (PID: 3100)
      • qmdl.exe (PID: 2616)
      • QMBlueScreenFixSetup_13.3.20244.216__1554802502382.exe (PID: 5988)
      • QMRealTimeSpeedupSetup_13.3.20244.216__1554802502382.exe (PID: 4576)
      • 2345SafeCenterInstaller.exe (PID: 5640)
    • Creates a software uninstall entry

      • PCMgr_Setup.exe (PID: 2636)
      • 2345Explorer_209411_silence.exe (PID: 3100)
    • Uses NETSH.EXE for network configuration

      • PCMgr_Setup.exe (PID: 2636)
    • Creates or modifies windows services

      • PCMgr_Setup.exe (PID: 2636)
      • QQPCTray.exe (PID: 3988)
      • QQPCRTP.exe (PID: 1784)
      • 2345Explorer_209411_silence.exe (PID: 3100)
      • 2345SafeCenterInstaller.exe (PID: 5640)
    • Creates files in the driver directory

      • PCMgr_Setup.exe (PID: 2636)
      • QQPCTray.exe (PID: 3988)
      • QQPCRTP.exe (PID: 1784)
      • 2345Explorer_209411_silence.exe (PID: 3100)
    • Creates files in the Windows directory

      • PCMgr_Setup.exe (PID: 2636)
      • QQPCRTP.exe (PID: 1784)
      • QQPCTray.exe (PID: 3988)
      • 2345Explorer_209411_silence.exe (PID: 3100)
      • 2345SafeCenterInstaller.exe (PID: 5640)
      • 2345SafeCenterSvc.exe (PID: 1988)
    • Creates a directory in Program Files

      • PCMgr_Setup.exe (PID: 2636)
      • QQPCRTP.exe (PID: 1784)
      • QQPCTray.exe (PID: 3988)
      • 2345Explorer_209411_silence.exe (PID: 3100)
      • QMBlueScreenFixSetup_13.3.20244.216__1554802502382.exe (PID: 5988)
      • 2345SafeCenterInstaller.exe (PID: 5640)
      • QMRealTimeSpeedupSetup_13.3.20244.216__1554802502382.exe (PID: 4576)
    • Drops a file that was compiled in debug mode

      • PCMgr_Setup.exe (PID: 2636)
      • QQPCTray.exe (PID: 3988)
      • 2345Explorer_209411_silence.exe (PID: 3100)
      • QQPCRealTimeSpeedup.exe (PID: 916)
      • QQPCRTP.exe (PID: 1784)
      • QMBlueScreenFixSetup_13.3.20244.216__1554802502382.exe (PID: 5988)
      • 2345SafeCenterInstaller.exe (PID: 5640)
    • Uses REG.EXE to modify Windows registry

      • regsvr32.exe (PID: 3700)
    • Application launched itself

      • QMCheckNetwork.exe (PID: 956)
    • Executed as Windows Service

      • QQPCRTP.exe (PID: 1784)
      • vssvc.exe (PID: 3920)
      • Protect_2345Explorer.exe (PID: 5264)
      • 2345SafeCenterSvc.exe (PID: 1988)
    • Searches for installed software

      • QQPCTray.exe (PID: 3988)
      • QQPCRTP.exe (PID: 1784)
    • Adds / modifies Windows certificates

      • QQPCTray.exe (PID: 3988)
      • QQPCRTP.exe (PID: 1784)
    • Uses ICACLS.EXE to modify access control list

      • qmdl.exe (PID: 2616)
    • Removes files from Windows directory

      • QQPCRTP.exe (PID: 1784)
    • Changes IE settings (feature browser emulation)

      • 2345Explorer_209411_silence.exe (PID: 3100)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • PCMgr_Setup.exe (PID: 2636)
      • QMBlueScreenFixSetup_13.3.20244.216__1554802502382.exe (PID: 5988)
    • Reads settings of System Certificates

      • QQPCTray.exe (PID: 3988)
      • QQPCRTP.exe (PID: 1784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (84.4)
.dll | Win32 Dynamic Link Library (generic) (6.7)
.exe | Win32 Executable (generic) (4.6)
.exe | Generic Win/DOS Executable (2)
.exe | DOS Executable Generic (2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:11:01 13:39:07+01:00
PEType: PE32
LinkerVersion: 6
CodeSize: 73728
InitializedDataSize: 8192
UninitializedDataSize: -
EntryPoint: 0x1cec
OSVersion: 4
ImageVersion: 13
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 13.0.0.9
ProductVersionNumber: 13.0.0.9
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: 纯统计,会自删除,不留任何垃圾
ProductName: 安全调节系统uqt
FileVersion: 13.00.0009
ProductVersion: 13.00.0009
InternalName: xt
OriginalFileName: xt.exe

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 01-Nov-2019 12:39:07
Detected languages:
  • Chinese - PRC
CompanyName: 纯统计,会自删除,不留任何垃圾
ProductName: 安全调节系统uqt
FileVersion: 13.00.0009
ProductVersion: 13.00.0009
InternalName: xt
OriginalFilename: xt.exe

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000C8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 01-Nov-2019 12:39:07
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00011178
0x00012000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.4018
.data
0x00013000
0x00000FC0
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00014000
0x000008E4
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
2.00601

Resources

Title
Entropy
Size
Codepage
Language
Type
1
3.68148
548
Unicode (UTF 16LE)
Chinese - PRC
RT_VERSION
30001
2.57965
304
Unicode (UTF 16LE)
UNKNOWN
RT_ICON
30002
1.76987
744
Unicode (UTF 16LE)
UNKNOWN
RT_ICON
30003
2.07177
296
Unicode (UTF 16LE)
UNKNOWN
RT_ICON

Imports

MSVBVM60.DLL
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
121
Monitored processes
56
Malicious processes
31
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start start download and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe cacls.exe systeminfo.exe no specs kzt11n.exe wscript.exe no specs regedit.exe qqpcmgr_v13.3.20244.216_1100109869_0.exe no specs pcmgr_setup.exe cacls.exe no specs regsvr32.exe no specs qqpcsoftcmd.exe netsh.exe no specs qqpcrtp.exe no specs remnpx.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs qmsuperscan.exe qqpctray.exe no specs qqpcrtp.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs qmchecknetwork.exe qmchecknetwork.exe qqpcrtp.exe no specs qqpcrtp.exe qqpctray.exe qqpctray.exe updatetrayicon.exe no specs installuninstallcube.exe qqtraymonitor.exe 2345explorer_209411_silence.exe qqpcrealtimespeedup.exe regsvr32.exe no specs qmdl.exe volsnapshot.exe explorer.exe qqtraymonitor.exe vssvc.exe no specs icacls.exe no specs qmbluescreenfixsetup_13.3.20244.216__1554802502382.exe qmrealtimespeedupsetup_13.3.20244.216__1554802502382.exe no specs 2345explorer.exe no specs servicemanager.exe no specs protect_2345explorer.exe 2345safecenterinstaller.exe 2345safecentersvc.exe volsnapshot.exe no specs regsvr32.exe no specs 2345rtprotect.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\QMCheckNetwork.exe" /AllChainC:\Program Files\Tencent\QQPCMgr\13.3.20244.216\QMCheckNetwork.exe
QMCheckNetwork.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\tencent\qqpcmgr\13.3.20244.216\qmchecknetwork.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
372C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
492reg add "hkcu\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{29B6CFD5-0064-411A-8C42-9890C83F9921}\iexplore" /v Flags /t reg_dword /d 4 /fC:\Windows\system32\reg.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
916"C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\QQPCRealTimeSpeedup.exe"C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\QQPCRealTimeSpeedup.exe
QQPCTray.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Description:
电脑管家-小火箭
Exit code:
0
Version:
13.3.20244.216
Modules
Images
c:\program files\tencent\qqpcmgr\13.3.20244.216\qqpcrealtimespeedup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\imm32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
952"C:\Windows\System32\cacls.exe" "C:\Program Files\xt" /e /t /p everyone:fC:\Windows\System32\cacls.exe
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956"C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\QMCheckNetwork.exe"C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\QMCheckNetwork.exe
QMSuperScan.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\tencent\qqpcmgr\13.3.20244.216\qmchecknetwork.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
988"C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\\QMSuperScan.exe"C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\QMSuperScan.exe
PCMgr_Setup.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Description:
电脑管家-杀毒
Exit code:
0
Version:
13.3.20244.216
Modules
Images
c:\program files\tencent\qqpcmgr\13.3.20244.216\qmsuperscan.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
1176"C:\Users\admin\AppData\Local\Temp\Tencent\QQPCMgr\~1577aa\UpdateTrayIcon.exe" -t QQPCTray.exe -c 1 -p 1 -d "C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\"C:\Users\admin\AppData\Local\Temp\Tencent\QQPCMgr\~1577aa\UpdateTrayIcon.exePCMgr_Setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225504
Modules
Images
c:\users\admin\appdata\local\temp\tencent\qqpcmgr\~1577aa\updatetrayicon.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1440"C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\QQPCTray.exe" /regrunC:\Program Files\Tencent\QQPCMgr\13.3.20244.216\QQPCTray.exe
PCMgr_Setup.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Description:
电脑管家
Exit code:
3221225547
Version:
13.3.20244.216
Modules
Images
c:\program files\tencent\qqpcmgr\13.3.20244.216\qqpctray.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
1488"C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\\InstallUninstallCube.exe" "/verb=EndInstall" /sync=0000014c /pid=2636 "/temp=C:\Users\admin\AppData\Local\Temp\Tencent\QQPCMgr\~1577aa\" "/version=13.3.20244.216" /silence=1 /result=1C:\Program Files\Tencent\QQPCMgr\13.3.20244.216\InstallUninstallCube.exe
PCMgr_Setup.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Description:
电脑管家-立方体安装、卸载扩展模块
Exit code:
0
Version:
13.3.20244.216
Modules
Images
c:\program files\tencent\qqpcmgr\13.3.20244.216\installuninstallcube.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\tencent\qqpcmgr\13.3.20244.216\common.dll
c:\program files\tencent\qqpcmgr\13.3.20244.216\zlib.dll
c:\program files\tencent\qqpcmgr\13.3.20244.216\vcruntime140.dll
c:\program files\tencent\qqpcmgr\13.3.20244.216\api-ms-win-crt-runtime-l1-1-0.dll
c:\program files\tencent\qqpcmgr\13.3.20244.216\ucrtbase.dll
c:\program files\tencent\qqpcmgr\13.3.20244.216\api-ms-win-core-timezone-l1-1-0.dll
Total events
12 673
Read events
9 436
Write events
3 204
Delete events
33

Modification events

(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\MySQL AB\MySQL Connector/ODBC 3.51
Operation:writeName:Version
Value:
3.51.24
(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ODBC\ODBCINST.INI\MySQL ODBC 3.51 Driver
Operation:writeName:UsageCount
Value:
1
(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ODBC\ODBCINST.INI\MySQL ODBC 3.51 Driver
Operation:writeName:Driver
Value:
C:\WINDOWS\system32\myodbc3.dll
(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ODBC\ODBCINST.INI\MySQL ODBC 3.51 Driver
Operation:writeName:Setup
Value:
C:\WINDOWS\system32\myodbc3s.dll
(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ODBC\ODBCINST.INI\ODBC Drivers
Operation:writeName:MySQL ODBC 3.51 Driver
Value:
Installed
(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2044) 79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
780
Suspicious files
473
Text files
745
Unknown types
183

Dropped files

PID
Process
Filename
Type
3120KzT11N.exeC:\Users\admin\Desktop\1.vbs
MD5:
SHA256:
3120KzT11N.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\qqpcmgr_v13.3.20244.216_1100109869_0[1].exe
MD5:
SHA256:
3120KzT11N.exeC:\Users\admin\Desktop\qqpcmgr_v13.3.20244.216_1100109869_0.exe
MD5:
SHA256:
3260qqpcmgr_v13.3.20244.216_1100109869_0.exeC:\Users\admin\AppData\Local\Temp\PCMgr_Setup.exe
MD5:
SHA256:
3120KzT11N.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\1[1].vbstext
MD5:
SHA256:
204479f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\uqcjjj[1]executable
MD5:
SHA256:
2636PCMgr_Setup.exeC:\Users\admin\AppData\Local\Temp\Tencent\QQPCMgr\~1577aa\setup.xmlxml
MD5:
SHA256:
204479f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\0md5[1].txttext
MD5:
SHA256:
204479f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\0[1].txttext
MD5:
SHA256:
2636PCMgr_Setup.exeC:\ProgramData\Tencent\QQPCMgr\QQPCMgrInstall_20201215090646.Logtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
134
TCP/UDP connections
205
DNS requests
32
Threats
41

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2044
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
GET
200
117.25.156.160:80
http://0.upzxt.com/0md5.txt
CN
text
32 b
malicious
2044
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
GET
200
203.129.88.115:80
http://www.weather.gov.hk/cgi-bin/hko/ntime.pl
HK
html
262 b
suspicious
2044
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
GET
200
117.25.156.160:80
http://0.upzxt.com/0.txt
CN
text
35 b
malicious
2044
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
GET
200
113.96.179.213:80
http://down.lnzbxy.com/jkhhh/uqcjjj
CN
executable
40.0 Kb
suspicious
3120
KzT11N.exe
GET
404
58.215.145.129:80
http://dngj.upzxt.com/1
CN
xml
256 b
whitelisted
3120
KzT11N.exe
GET
200
58.215.145.129:80
http://dngj.upzxt.com/1.vbs
CN
text
223 b
whitelisted
2636
PCMgr_Setup.exe
GET
200
203.205.253.140:80
http://c.gj.qq.com/fcgi-bin/installquery?id=1100109869&guid=QN2U1b7Dzh4Vs2FVXlUssrOjQg4cfuONh3tWObctm28wp8gT3sWzzGrBIfjc6x7h
CN
binary
368 b
suspicious
988
QMSuperScan.exe
POST
219.133.60.246:80
http://www.qq.com/q.cgi
CN
unknown
988
QMSuperScan.exe
POST
200
203.205.239.243:80
http://www.qq.com/q.cgi
CN
abr
1.70 Kb
unknown
1784
QQPCRTP.exe
POST
200
203.205.239.243:80
http://www.qq.com/q.cgi
CN
binary
250 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1784
QQPCRTP.exe
203.205.254.111:36688
connc.gj.qq.com
CN
malicious
3988
QQPCTray.exe
203.205.254.111:36688
connc.gj.qq.com
CN
malicious
1784
QQPCRTP.exe
219.133.60.246:80
China Telecom (Group)
CN
unknown
2044
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
203.129.88.115:80
www.weather.gov.hk
Hutchison Global Crossing Ltd.
HK
unknown
2044
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
117.25.156.160:80
0.upzxt.com
Xiamen
CN
malicious
2044
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
113.96.179.213:80
down.lnzbxy.com
No.31,Jin-rong Street
CN
malicious
3120
KzT11N.exe
58.215.145.129:80
dngj.upzxt.com
AS Number for CHINANET jiangsu province backbone
CN
suspicious
3120
KzT11N.exe
113.96.179.213:80
down.lnzbxy.com
No.31,Jin-rong Street
CN
malicious
2636
PCMgr_Setup.exe
58.251.106.185:443
masterconn11.qq.com
China Unicom Guangdong IP network
CN
malicious
1784
QQPCRTP.exe
203.205.239.243:8000
conna.gj.qq.com
CN
unknown

DNS requests

Domain
IP
Reputation
www.weather.gov.hk
  • 203.129.88.115
suspicious
0.upzxt.com
  • 117.25.156.160
malicious
down.lnzbxy.com
  • 113.96.179.213
suspicious
dngj.upzxt.com
  • 58.215.145.129
whitelisted
masterconn11.qq.com
  • 58.251.106.185
whitelisted
download.2345.cn
  • 218.12.76.150
  • 218.12.76.151
  • 120.52.95.242
  • 120.52.95.243
whitelisted
c.gj.qq.com
  • 203.205.253.140
  • 203.205.253.183
unknown
connc.gj.qq.com
  • 203.205.254.111
unknown
conna.gj.qq.com
  • 203.205.239.243
unknown
connpm.gj.qq.com
  • 203.205.253.186
whitelisted

Threats

PID
Process
Class
Message
3120
KzT11N.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2044
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2044
79f5f05c63ba0a267271d64376ae752996ad68a29bd70cba3f2e8fc56c4e9be5.exe
A Network Trojan was detected
ET CURRENT_EVENTS Likely Evil EXE download from MSXMLHTTP non-exe extension M2
2636
PCMgr_Setup.exe
Generic Protocol Command Decode
SURICATA TLS error message encountered
2636
PCMgr_Setup.exe
Generic Protocol Command Decode
SURICATA Applayer Detect protocol only one direction
2636
PCMgr_Setup.exe
Generic Protocol Command Decode
SURICATA TLS error message encountered
3120
KzT11N.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3120
KzT11N.exe
Misc activity
ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)
2636
PCMgr_Setup.exe
Misc activity
ADWARE [PTsecurity] QQ_games PUP Installer
2636
PCMgr_Setup.exe
Misc activity
ADWARE [PTsecurity] QQ_games PUP Installer
2 ETPRO signatures available at the full report
Process
Message
regedit.exe
REGEDIT: CreateFile failed, GetLastError() = 2
PCMgr_Setup.exe
"cacls" "C:\Program Files\Tencent\QQPCMgr\13.3.20244.216" /t /e /c /g SYSTEM:f
QQPCSoftCmd.exe
=========== mem dump after here is valid ========
PCMgr_Setup.exe
CreateService
PCMgr_Setup.exe
0
PCMgr_Setup.exe
0
PCMgr_Setup.exe
0
PCMgr_Setup.exe
CreateService
PCMgr_Setup.exe
0
PCMgr_Setup.exe
StartService