General Info

File name

OneSafe_PC_Cleaner.exe

Full analysis
https://app.any.run/tasks/2c6a3481-9958-4533-9933-b98dfc8a1076
Verdict
Malicious activity
Analysis date
9/11/2019, 09:18:44
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

5b373a3714eb6a3a29fc1f58ccb556da

SHA1

f835d181f42355d6dd543c0f66332790c7f66635

SHA256

83dda10730255f3bb811d39c747281e6fb00cbb648c95212fcc4c4814232ff89

SSDEEP

98304:a/fCmO3Oz04YaW0FqF8FnOe1R2tvlJypLUANlqLxjS:MfwOz04HfFqnaR2tNrA3qLx+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
240 seconds
Additional time used
180 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • OneSafePCCleaner.exe (PID: 3748)
Application was dropped or rewritten from another process
  • OneSafePCCleaner.exe (PID: 3748)
  • OSPCNotifications.exe (PID: 3496)
Loads the Task Scheduler COM API
  • schtasks.exe (PID: 2628)
Uses Task Scheduler to autorun other applications
  • OneSafePCCleaner.exe (PID: 3748)
Reads the cookies of Google Chrome
  • OneSafePCCleaner.exe (PID: 3748)
Creates files in the user directory
  • OneSafePCCleaner.exe (PID: 3748)
Reads the cookies of Mozilla Firefox
  • OneSafePCCleaner.exe (PID: 3748)
Check for Java to be installed
  • OneSafePCCleaner.exe (PID: 3748)
Searches for installed software
  • OneSafePCCleaner.exe (PID: 3748)
Reads internet explorer settings
  • OneSafePCCleaner.exe (PID: 3748)
Reads Microsoft Outlook installation path
  • OneSafePCCleaner.exe (PID: 3748)
Creates files in the program directory
  • OneSafePCCleaner.exe (PID: 3748)
Executable content was dropped or overwritten
  • OneSafe_PC_Cleaner.tmp (PID: 2960)
  • OneSafe_PC_Cleaner.exe (PID: 2344)
  • OneSafe_PC_Cleaner.exe (PID: 3724)
Reads CPU info
  • OneSafePCCleaner.exe (PID: 3748)
Reads the Windows organization settings
  • OneSafe_PC_Cleaner.tmp (PID: 2960)
Reads Windows owner or organization settings
  • OneSafe_PC_Cleaner.tmp (PID: 2960)
Application was dropped or rewritten from another process
  • OneSafe_PC_Cleaner.tmp (PID: 2676)
  • OneSafe_PC_Cleaner.tmp (PID: 2960)
Creates a software uninstall entry
  • OneSafe_PC_Cleaner.tmp (PID: 2960)
Creates files in the program directory
  • OneSafe_PC_Cleaner.tmp (PID: 2960)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable Delphi generic (45.2%)
.dll
|   Win32 Dynamic Link Library (generic) (20.9%)
.exe
|   Win32 Executable (generic) (14.3%)
.exe
|   Win16/32 Executable Delphi generic (6.6%)
.exe
|   Generic Win/DOS Executable (6.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:04:06 16:39:04+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
66560
InitializedDataSize:
53760
UninitializedDataSize:
null
EntryPoint:
0x117dc
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
6.9.9.6
ProductVersionNumber:
6.9.9.6
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
Avanquest Software
FileDescription:
OneSafe PC Cleaner
FileVersion:
6.9.9.6
LegalCopyright:
Avanquest Software
ProductName:
OneSafe PC Cleaner
ProductVersion:
6.9.9.6
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
06-Apr-2016 14:39:04
Detected languages
Dutch - Netherlands
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
Avanquest Software
FileDescription:
OneSafe PC Cleaner
FileVersion:
6.9.9.6
LegalCopyright:
Avanquest Software
ProductName:
OneSafe PC Cleaner
ProductVersion:
6.9.9.6
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
06-Apr-2016 14:39:04
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F244 0x0000F400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.16226
.itext 0x00011000 0x00000F64 0x00001000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.7322
.data 0x00012000 0x00000C88 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.29672
.bss 0x00013000 0x000056BC 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000E04 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.59781
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x0000B200 0x0000B200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.145
Resources
1

2

3

4

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
44
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

+
drop and start start drop and start drop and start drop and start onesafe_pc_cleaner.exe onesafe_pc_cleaner.tmp no specs onesafe_pc_cleaner.exe onesafe_pc_cleaner.tmp ospcnotifications.exe no specs onesafepccleaner.exe schtasks.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3724
CMD
"C:\Users\admin\AppData\Local\Temp\OneSafe_PC_Cleaner.exe"
Path
C:\Users\admin\AppData\Local\Temp\OneSafe_PC_Cleaner.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Avanquest Software
Description
OneSafe PC Cleaner
Version
6.9.9.6
Modules
Image
c:\users\admin\appdata\local\temp\onesafe_pc_cleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-udgda.tmp\onesafe_pc_cleaner.tmp

PID
2676
CMD
"C:\Users\admin\AppData\Local\Temp\is-UDGDA.tmp\OneSafe_PC_Cleaner.tmp" /SL5="$20134,4772668,121344,C:\Users\admin\AppData\Local\Temp\OneSafe_PC_Cleaner.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-UDGDA.tmp\OneSafe_PC_Cleaner.tmp
Indicators
No indicators
Parent process
OneSafe_PC_Cleaner.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-udgda.tmp\onesafe_pc_cleaner.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll

PID
2344
CMD
"C:\Users\admin\AppData\Local\Temp\OneSafe_PC_Cleaner.exe" /SPAWNWND=$20130 /NOTIFYWND=$20134
Path
C:\Users\admin\AppData\Local\Temp\OneSafe_PC_Cleaner.exe
Indicators
Parent process
OneSafe_PC_Cleaner.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Avanquest Software
Description
OneSafe PC Cleaner
Version
6.9.9.6
Modules
Image
c:\users\admin\appdata\local\temp\onesafe_pc_cleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-sai90.tmp\onesafe_pc_cleaner.tmp

PID
2960
CMD
"C:\Users\admin\AppData\Local\Temp\is-SAI90.tmp\OneSafe_PC_Cleaner.tmp" /SL5="$30136,4772668,121344,C:\Users\admin\AppData\Local\Temp\OneSafe_PC_Cleaner.exe" /SPAWNWND=$20130 /NOTIFYWND=$20134
Path
C:\Users\admin\AppData\Local\Temp\is-SAI90.tmp\OneSafe_PC_Cleaner.tmp
Indicators
Parent process
OneSafe_PC_Cleaner.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-sai90.tmp\onesafe_pc_cleaner.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\onesafe pc cleaner\onesafepccleaner.exe
c:\program files\onesafe pc cleaner\unins000.exe
c:\program files\onesafe pc cleaner\ospcnotifications.exe
c:\windows\system32\netutils.dll

PID
3496
CMD
"C:\Program Files\OneSafe PC Cleaner\OSPCNotifications.exe"
Path
C:\Program Files\OneSafe PC Cleaner\OSPCNotifications.exe
Indicators
No indicators
Parent process
OneSafe_PC_Cleaner.tmp
User
admin
Integrity Level
HIGH
Version:
Company
Avanquest Software
Description
OneSafe PC Cleaner automatic scan and notifications
Version
6.9.9.0
Modules
Image
c:\program files\onesafe pc cleaner\ospcnotifications.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crtdll.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\security.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll

PID
3748
CMD
"C:\Program Files\OneSafe PC Cleaner\OneSafePCCleaner.exe"
Path
C:\Program Files\OneSafe PC Cleaner\OneSafePCCleaner.exe
Indicators
Parent process
OneSafe_PC_Cleaner.tmp
User
admin
Integrity Level
HIGH
Version:
Company
Avanquest Software
Description
OneSafe PC Cleaner
Version
6.9.9.0
Modules
Image
c:\program files\onesafe pc cleaner\onesafepccleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\crtdll.dll
c:\windows\system32\winmm.dll
c:\windows\system32\oleacc.dll
c:\program files\onesafe pc cleaner\sqlite3.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\security.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shunimpl.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\idndl.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\mlang.dll
c:\windows\system32\wship6.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ie4uinit.exe
c:\windows\system32\gameux.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\wuapi.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wups.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll

PID
2628
CMD
"C:\Windows\System32\schtasks.exe" /Create /TN "OneSafe PC Cleaner automatic scan and notifications" /TR "\"C:\Program Files\OneSafe PC Cleaner\OSPCNotifications.exe\"" /SC ONLOGON /RL HIGHEST /F
Path
C:\Windows\System32\schtasks.exe
Indicators
No indicators
Parent process
OneSafePCCleaner.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\xmllite.dll

Registry activity

Total events
36725
Read events
36588
Write events
136
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
2960
OneSafe_PC_Cleaner.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
900B0000B8929E2E7168D501
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
B7E640439733A055C66D5B56662241C80789643ECCCEF87D01710777CDC5F3E2
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\OneSafe PC Cleaner\OneSafePCCleaner.exe
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
7FF3E9F8280020E5B49D94117F6D648A0B707C5DC300F24FDFD4A2C469957FFD
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
InstallerName
C:\Users\admin\AppData\Local\Temp\OneSafe_PC_Cleaner.exe
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
PrivacyURL
https://webtools.avanquest.com/redirect.cfm?eredirectId=Avanquest/OneSafe_PC_Cleaner_Privacy_ML.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
EulaURL
https://webtools.avanquest.com/redirect.cfm?eredirectId=Avanquest/OneSafe_PC_Cleaner_EULA_ML.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
AdsAntivirusLink
https://webtools.avanquest.com/redirect.cfm?eredirectId=Avanquest/OneSafe_PC_Cleaner_Antivirus_ML.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
AdsAntivirusName
Adaware
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
AdsDownloadURL
http://webtools.avanquest.com/redirect.cfm?eredirectId=Avanquest/OneSafe_PC_Cleaner_Crossell_Buy_ML.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
UseAds
1
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
BuyNowURL50
https://webtools.avanquest.com/redirect.cfm?redirectId=Avanquest/OneSafe_PC_Cleaner_Buy_50_ML_06.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
BuyNowURL20
https://webtools.avanquest.com/redirect.cfm?redirectId=Avanquest/OneSafe_PC_Cleaner_Buy_20_ML_06.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
PromoOffers
1
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
HideAfterInstallURL
1
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
Phones
1
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ComplementURL
1
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
BuyNowURLCs
http://webtools.avanquest.com/redirect.cfm?eredirectId=Avanquest/OneSafe_PC_Cleaner_Crossell_Buylink_OSPCC_ML.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
UninstallURL
https://webtools.avanquest.com/redirect.cfm?redirectId=Avanquest/OneSafe_PC_Cleaner_UI_ML_06.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
AfterInstallURL
https://webtools.avanquest.com/redirect.cfm?redirectId=Avanquest/OneSafe_PC_Cleaner_Post_Install_ML_06.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
SupportURL
https://webtools.avanquest.com/redirect.cfm?eredirectId=Avanquest/OneSafe_PC_Cleaner_Support_ML.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
RenewURL
https://webtools.avanquest.com/redirect.cfm?redirectId=Avanquest/OneSafe_PC_Cleaner_Renewal_ML.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ProURL
https://webtools.avanquest.com/redirect.cfm?redirectId=Avanquest/OneSafe_PC_Cleaner_Upsell_PRO_ML_V6.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
BuyNowURL
https://webtools.avanquest.com/redirect.cfm?redirectId=Avanquest/OneSafe_PC_Cleaner_Buy_ML_06.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
HomePageURL
https://webtools.avanquest.com/redirect.cfm?eredirectId=Avanquest/OneSafe_PC_Cleaner_Home_ML.htm
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
PartnerID
ONESAFE
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
UpgradeID
ML_OSPCC_63
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
BuildID
OneSafe_PC_Cleaner_ML
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
CreationDate
23/08/2019
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
Cv
Aug2019
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
Language
1
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
Inno Setup: Setup Version
5.5.9 (u)
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
Inno Setup: App Path
C:\Program Files\OneSafe PC Cleaner
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
InstallLocation
C:\Program Files\OneSafe PC Cleaner\
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
Inno Setup: Icon Group
OneSafe PC Cleaner
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
Inno Setup: User
admin
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
Inno Setup: Selected Tasks
desktopicon
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
Inno Setup: Deselected Tasks
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
Inno Setup: Language
en
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
DisplayName
OneSafe PC Cleaner v6.9.9.6
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
DisplayIcon
C:\Program Files\OneSafe PC Cleaner\OneSafePCCleaner.exe,0
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
UninstallString
"C:\Program Files\OneSafe PC Cleaner\unins000.exe"
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
QuietUninstallString
"C:\Program Files\OneSafe PC Cleaner\unins000.exe" /SILENT
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
DisplayVersion
6.9.9.6
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
Publisher
Avanquest Software
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
NoModify
1
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
NoRepair
1
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
InstallDate
20190911
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
MajorVersion
6
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
MinorVersion
9
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
VersionMajor
6
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
VersionMinor
9
2960
OneSafe_PC_Cleaner.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSafe PC Cleaner_is1
EstimatedSize
16608
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
OnWinStartup
0
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
s_SmartEnabled
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
s_SmartMode
0
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
s_SmartDate
A3D52C19CB58E540
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
MonitorNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LastMonitorNotification
A3D52C19EB58E540
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
NewAppNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
NewExtNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
StartupNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
CrashNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
NoAVNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LowDiskSpaceNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LowFreeMemNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
BigCacheSizeNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
UninstallNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
MinFreeDiskSpace
10
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
MinFreeMemory
10
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
MinCacheSize
500
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
CheckUpdates
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LastUpdCheck
43962D19EB58E540
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
SoftwareNotifications
1
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LastSrvNotification
43962D19CB58E540
3496
OSPCNotifications.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LastSrvCheck
43962D19EB58E540
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
BackupDir
C:\Users\admin\AppData\Roaming\OneSafe PC Cleaner\Backup
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
DisplayName
OneSafe PC Cleaner
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
Version
6.9.9
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
InstallationDate
EDE53D19EB58E540
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
TrayAllowed
1
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
s_SmartEnabled
1
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
NLaunches
1
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LogDir
C:\Users\admin\AppData\Roaming\OneSafe PC Cleaner\Log
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
UndoDir
C:\Users\admin\AppData\Roaming\OneSafe PC Cleaner\Undo
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ItemsToRegistryScan
1111111111
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ItemsToPrivacyScan
1111
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ItemsToRecoveryScan
1111
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
UseExclusions
1
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ShowRebootMessage
1
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ShowRecycleBin
1
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
FormSP
1
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ShowTips
1
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASAPI32
EnableFileTracing
0
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASAPI32
EnableConsoleTracing
0
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASAPI32
FileTracingMask
4294901760
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASAPI32
ConsoleTracingMask
4294901760
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASAPI32
MaxFileSize
1048576
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASAPI32
FileDirectory
%windir%\tracing
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASMANCS
EnableFileTracing
0
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASMANCS
EnableConsoleTracing
0
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASMANCS
FileTracingMask
4294901760
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASMANCS
ConsoleTracingMask
4294901760
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASMANCS
MaxFileSize
1048576
3748
OneSafePCCleaner.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSafePCCleaner_RASMANCS
FileDirectory
%windir%\tracing
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3748
OneSafePCCleaner.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\Licenses\b47b460376d661a60e56ba925fabf8d4
Si
1
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LastCleanExecuted
0
3748
OneSafePCCleaner.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@"%windir%\System32\ie4uinit.exe",-738
Start Internet Explorer without ActiveX controls or browser extensions.
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LastScanCanceled
0
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LastScanDate
B4AD2B24EB58E540
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
LastScanFound
475
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ItemsToFix
475
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
ItemsFixed
0
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
SizeToClean
702.81 MB
3748
OneSafePCCleaner.exe
write
HKEY_CURRENT_USER\Software\OneSafe PC Cleaner
SizeToCleanInt
703

Files activity

Executable files
6
Suspicious files
0
Text files
33
Unknown types
9

Dropped files

PID
Process
Filename
Type
3724
OneSafe_PC_Cleaner.exe
C:\Users\admin\AppData\Local\Temp\is-UDGDA.tmp\OneSafe_PC_Cleaner.tmp
executable
MD5: 90fc739c83cd19766acb562c66a7d0e2
SHA256: 821bd11693bf4b4b2b9f3c196036e1f4902abd95fb26873ea6c43e123b8c9431
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\OSPCNotifications.exe
executable
MD5: c945f78400bd24aad737f30ccc8b618a
SHA256: a7ea048e15b00d5f7ed760eb5ba8dd8a034e31e0c0953ae17f5b2da81a5b38c0
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\OneSafePCCleaner.exe
executable
MD5: 12d1ef4e8aa0ab823870e154e4a76aed
SHA256: cb2b98c829c1cdebddbc3afefb5e8c6702b60ee286dfd26308b0fc79ca4e0bde
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\unins000.exe
executable
MD5: 3a85e2d1f0a26f6e8fc804dce9446fa5
SHA256: cf584d62089672fa6e5d9e8c314ae3d99866aebc6958a2f5c86694ad253136eb
2344
OneSafe_PC_Cleaner.exe
C:\Users\admin\AppData\Local\Temp\is-SAI90.tmp\OneSafe_PC_Cleaner.tmp
executable
MD5: 90fc739c83cd19766acb562c66a7d0e2
SHA256: 821bd11693bf4b4b2b9f3c196036e1f4902abd95fb26873ea6c43e123b8c9431
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\sqlite3.dll
executable
MD5: 34a9bad2c68bbcc21075c97e7a156f83
SHA256: 0e86808f00e264b62f7fcdf6d8e8044655eb5c5056088b889af467b7cf3a8f96
3748
OneSafePCCleaner.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\info_48[1]
image
MD5: 49e0ef03e74704089a60c437085db89e
SHA256: caa140523ba00994536b33618654e379216261babaae726164a0f74157bb11ff
3748
OneSafePCCleaner.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\ErrorPageTemplate[1]
text
MD5: f4fe1cb77e758e1ba56b8a8ec20417c5
SHA256: 8d018639281b33da8eb3ce0b21d11e1d414e59024c3689f92be8904eb5779b5f
3748
OneSafePCCleaner.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\errorPageStrings[1]
text
MD5: 1a0563f7fb85a678771450b131ed66fd
SHA256: eb5678de9d8f29ca6893d4e6ca79bd5ab4f312813820fe4997b009a2b1a1654c
3748
OneSafePCCleaner.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\navcancl[1]
html
MD5: 4bcfe9f8db04948cddb5e31fe6a7f984
SHA256: bee0439fcf31de76d6e2d7fd377a24a34ac8763d5bf4114da5e1663009e24228
3748
OneSafePCCleaner.exe
C:\ProgramData\OneSafe PC Cleaner\Cookies.txt
text
MD5: bf6c156441320d21440afc65a6bcf77d
SHA256: 502f9fba9bba2ca5f57a3a0ea7efcee4731c98dcd2ea0fcec21059b11ddbf352
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\unins000.dat
dat
MD5: 24c20fc24982052ddc40a8d1caf0a46a
SHA256: 06907f5705508f61381a690edb1df423096a5a1d33f1bdaa7d8cdac7cafbbe1f
2960
OneSafe_PC_Cleaner.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneSafe PC Cleaner\Uninstall OneSafe PC Cleaner.lnk
lnk
MD5: 2e458573ee11e1273c0e8fde5680318c
SHA256: 9efa2acbdca6720e2802d4ae14bcd33680b562873504b08168bff14e17f5718f
2960
OneSafe_PC_Cleaner.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneSafe PC Cleaner\OneSafe PC Cleaner on the Web.lnk
lnk
MD5: 59dd59c29744e5621397a206c139f241
SHA256: 3ca09eebb9981c7f7ecc0bdec5154cb5a75c9b41487a3c266ca9bc2df7ec6a9c
2960
OneSafe_PC_Cleaner.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneSafe PC Cleaner\Check updates.lnk
lnk
MD5: 03e6f6a3c22d0e76102aa1bb78f3e779
SHA256: e059f47264832bbd3d5c8bb580337848b53dd7ba9f7ff84651c9fa4ff4052d1d
2960
OneSafe_PC_Cleaner.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneSafe PC Cleaner\Help.lnk
lnk
MD5: db8400168b8eb9b54ca6034b9e9ed913
SHA256: 227dc8f3d8212fab80fb57e43144fc6c97775ea357fefc4de2a3cb567d1c12fe
2960
OneSafe_PC_Cleaner.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneSafe PC Cleaner\OneSafe PC Cleaner.lnk
lnk
MD5: b0a66d4d5639e415836cfef13ab0d730
SHA256: 44c86ab9c212dbd61b2a83243efd23f863f71fb8880338af2412cf5177fb99e7
2960
OneSafe_PC_Cleaner.tmp
C:\Users\admin\Desktop\OneSafe PC Cleaner.lnk
lnk
MD5: 06afc51ab8537fc92f1d6f8f096e00d3
SHA256: 6a03cb4fc3b308ab6e114ff326ea354c8fff7ace44b17a96b4a6624579fcd1c0
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\OneSafePCCleaner.chm
chm
MD5: a26b8d479e0ddf460bb0c641f1103aa5
SHA256: cfb613376f62a5bd711b1f1a7dd61db469d7cf12fb95eac0ba0ab151ae042c41
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Turkish.ini
text
MD5: bad84d22610f636f344688bc804c724a
SHA256: 572c841f77fcffd66f90ae8a1d5e580e5c387ef021d1a32d546f364857e33606
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-JB2S1.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-GC66V.tmp
––
MD5:  ––
SHA256:  ––
3748
OneSafePCCleaner.exe
C:\ProgramData\OneSafe PC Cleaner\CookieExclusions.txt
text
MD5: a77eeb70f0aa442727f602787c18b178
SHA256: fe80c405681825377f079014e51bbc29e671ed0f287fab335d30af5e0c78d789
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Swedish.ini
text
MD5: c231d9850dd268e96733b4b665c62086
SHA256: 4f060cc91faf50aa7bd268ed157a6c48ed3cb6487fb30e6bfbdfd871bebbd390
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-2FQRJ.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-UBQVJ.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Spanish.ini
text
MD5: 0a4fc5d4d9a09cca9415d5531566a230
SHA256: 9a81e950d002039919c8084c43cc15f0acca55c1375cae7c2f3fe26081ba818f
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\SList.db
sqlite
MD5: 7b5ca14d6613abe03ee21f5debf6aeca
SHA256: 39ca88c94613efa08238dd1e39f8ed2805524da1de4814d615ddfe192b5a65fb
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\SList.txt
text
MD5: 1e38db7385d386e8ac9555e16202a856
SHA256: 234b968ac0e615edc9f2beb7dbc5f7292ee893cc42d563d3458fe19c09536c81
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-FOSEE.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-L9DB8.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-BPDAL.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Services1.txt
text
MD5: 21bc09207f237dd262112401584e3b8f
SHA256: 95d33968b745174744e07207e8003b8a615e1bc5e10676a2f4e81f3e5abf4980
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Services2.txt
text
MD5: 340b31f1de820e89fdab9cdb659511e9
SHA256: 75fd81f57ad77f15ec5444d736a6b16b48d163c8bf1051c6511662ee50a8fa67
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-BOU80.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-L6NSN.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\SchedTasks.txt
text
MD5: 2f43b8d41173bc488c559ccdec9b5702
SHA256: 7877fcec8728cfc74e6da26971942fc21493dd30fd64760a2cc94216668a7119
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-ST153.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Russian.ini
text
MD5: 8e86c5b5968d821daf81c2739098a6e0
SHA256: 1514e66b960f4a139aacfa3111c6aea31bb7b51b5a8528b871148be6ae3d576e
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-C7F17.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Portuguese.ini
text
MD5: 5cc9b7f61be5fa11437b78ae8e42b455
SHA256: 0c545756a24fbaae2831b9580dc7c2bdc009011377e8ed535a8c7a64925e30dc
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-C69L3.tmp
––
MD5:  ––
SHA256:  ––
3748
OneSafePCCleaner.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Polish.ini
text
MD5: f7e8dce1ff060bf70199f8b59d68c3ff
SHA256: 41f7951ec30e03e57c9f6335141797ad2f0a22115c9eda0055fd59a1f9110dd5
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-OHAF4.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-N5NFP.tmp
––
MD5:  ––
SHA256:  ––
3748
OneSafePCCleaner.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\bullet[1]
image
MD5: 0c4c086dd852704e8eeb8ff83e3b73d1
SHA256: 1cb3b6ea56c5b5decf5e1d487ad51dbb2f62e6a6c78f23c1c81fda1b64f8db16
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-IKFHI.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Norwegian.ini
text
MD5: 80a34bdc805b10cc194d9fe06ed30657
SHA256: c2128f271da4b0dbc77492ce4c53f27736638eb2f360680038d709d6b3d06e27
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Korean.ini
text
MD5: 34b6994cd99a26734677b9bd2582be81
SHA256: 2930cc0df900a23cf02e69edf6d3488503edb1775f876cf4b229260e8ac96a7d
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Japanese.ini
text
MD5: 581a5a10f67dfb6e7123c7c58cce00b7
SHA256: 4629f0e198925a12afe0b355dbe25d223eecf7b968a9d793dbe1c91b4e79f052
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Italian.ini
text
MD5: 0fedefa94389f50f10c50113d4f7083c
SHA256: 771e002829431efbcc49a5f14ad4101f0a2ce66c65b1bf512a10986ec8e3a5f7
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-BRQHU.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-GO546.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-U5SQI.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-LQSHU.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\French.ini
text
MD5: 0e490e90e3deec13c6a4122e0231a135
SHA256: 36a389fa99b9115ea03ceeb8a7a0b98bf8807894c7ab151f7dd35a7e44f02490
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\German.ini
text
MD5: e240e5f4b091a01f34c24642d0be1a75
SHA256: 115c7aa96de4d6c5b432507f86701a2b01bf260dd5b242f2fb68f17f7f3982d2
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Finnish.ini
text
MD5: d37a448f0f66c5c64d844eb969e9d247
SHA256: 9e8cc14a8c6c3228e31c52dde69116961a65115cf58b4df6517c65bf88fcbc7f
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\English.ini
text
MD5: ab5fd604302610c59c3583d6a242ad55
SHA256: 286eaba7ed2a7a7aaf2b57927071822faf20fd8a659277f890db457899e0fcbd
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-REO6E.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-CR1LD.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-6VE8L.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-QQJSH.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Dutch.ini
text
MD5: ece6cfdcd65926ea7ef8f3ca1b20b1c3
SHA256: 690961424b5e47234e171785580fabcf5efad29bc66dcf02d27396878ce6e997
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Brazilian.ini
text
MD5: f83590e40a39104f05d3fd367562f8c2
SHA256: ba3da5e739b77498f43bc7e827eef3fa7e3f451acae4420fe31f4231a642046d
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Danish.ini
text
MD5: 0c2c3e522bf72b62def26a72c1219062
SHA256: f70fabd87018150469e69a8e42746a96a5e955974f451a7c14b828a1f4ffcacc
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Cookies.txt
text
MD5: bf6c156441320d21440afc65a6bcf77d
SHA256: 502f9fba9bba2ca5f57a3a0ea7efcee4731c98dcd2ea0fcec21059b11ddbf352
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-BPEDO.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-4QK15.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-AKJHA.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-IVLFM.tmp
––
MD5:  ––
SHA256:  ––
3748
OneSafePCCleaner.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\background_gradient[1]
image
MD5: 20f0110ed5e4e0d5384a496e4880139b
SHA256: 1471693be91e53c2640fe7baeecbc624530b088444222d93f2815dfce1865d5b
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\Animation.gif
image
MD5: 915f2ce934fd4789216b91bf9c2609fd
SHA256: 135d81feef8bc93e48f3d929d9249abe56e8b0a566f51964c8cad28602219250
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-VTTDJ.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Program Files\OneSafe PC Cleaner\is-C46J7.tmp
––
MD5:  ––
SHA256:  ––
2960
OneSafe_PC_Cleaner.tmp
C:\Users\admin\AppData\Local\Temp\is-DTOVQ.tmp\OSPCSetup.bmp
image
MD5: 12a2716eb69800e28507fc9bbccb9eaa
SHA256: d0425dbe2cabc59296ecd59c08eda7845ac0d52be9feda686cd7e65f9e2f7fff
3748
OneSafePCCleaner.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\httpErrorPagesScripts[1]
text
MD5: e7ca76a3c9ee0564471671d500e3f0f3
SHA256: 58268ca71a28973b756a48bbd7c9dc2f6b87b62ae343e582ce067c725275b63c
3748
OneSafePCCleaner.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite-shm
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
5
DNS requests
4
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3748 OneSafePCCleaner.exe GET 200 94.130.13.79:80 http://stats.smartpctools.com/si?p=OneSafe_PC_Cleaner_ML&b=6.9.9&c=Aug2019 DE
text
unknown
3748 OneSafePCCleaner.exe GET 200 46.4.246.106:80 http://dev.techsupport.smartpcupdate.com/build/ONESAFE/OneSafe_PC_Cleaner_ML DE
––
––
malicious
3748 OneSafePCCleaner.exe GET 302 217.195.25.241:80 http://webtools.avanquest.com/install_success.cfm?redirectId=Avanquest/OneSafe_PC_Cleaner_Buy_ML_06.htm&target=http://onesafe-software.com/Install/cleaner/install_success.cfm&dcid=&paramurl=1&mkey1=DEFAULT_REDIRECT_TRACKING FR
text
unknown

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3748 OneSafePCCleaner.exe 217.195.25.241:443 SPIE Cloud Services SAS FR unknown
3748 OneSafePCCleaner.exe 94.130.13.79:80 Hetzner Online GmbH DE unknown
3748 OneSafePCCleaner.exe 46.4.246.106:80 Hetzner Online GmbH DE malicious
3748 OneSafePCCleaner.exe 217.195.25.241:80 SPIE Cloud Services SAS FR unknown

DNS requests

Domain IP Reputation
webtools.avanquest.com 217.195.25.241
unknown
stats.smartpctools.com 94.130.13.79
unknown
dev.techsupport.smartpcupdate.com 46.4.246.106
malicious
webtools.onesafesoftware.com 217.195.25.241
unknown

Threats

No threats detected.

Debug output strings

No debug info.