File name:

aso3setup_systweak-default.exe

Full analysis: https://app.any.run/tasks/1f8a34aa-e593-4f27-b5db-37a88c949200
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: June 04, 2024, 12:58:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
loader
banload
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

81E69DE9C32BC382666B875DBD21494D

SHA1:

DDED9A9C15E91D498840E056AACD3D58D664B673

SHA256:

86E1A1BBFF3D733413310CEBA0F12C63F14EA779AC8B0A5F44E611F4F29EE3BC

SSDEEP:

98304:ivN/CRXtYblVLGNU8AdoEr+m5QwG4CUi7+042jA6mKQjE1Y4huIVsW+yeuQqEdUe:A8+uoCs9jBjt14wcyB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • aso3setup_systweak-default.exe (PID: 3968)
      • aso3setup_systweak-default.exe (PID: 928)
      • aso3setup_systweak-default.tmp (PID: 1120)
    • Starts NET.EXE for service management

      • net.exe (PID: 116)
      • KillASOProcesses.exe (PID: 2044)
      • aso3setup_systweak-default.tmp (PID: 1120)
      • net.exe (PID: 1036)
    • Creates a writable file in the system directory

      • aso3setup_systweak-default.tmp (PID: 1120)
    • Banload is detected

      • ASO3.exe (PID: 2280)
      • ASO3.exe (PID: 3008)
      • ASO3.exe (PID: 1840)
      • ASO3.exe (PID: 664)
    • Registers / Runs the DLL via REGSVR32.EXE

      • aso3setup_systweak-default.tmp (PID: 1120)
    • Connects to the CnC server

      • ASO3.exe (PID: 1840)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • aso3setup_systweak-default.exe (PID: 3968)
      • aso3setup_systweak-default.exe (PID: 928)
      • aso3setup_systweak-default.tmp (PID: 1120)
    • Process drops legitimate windows executable

      • aso3setup_systweak-default.tmp (PID: 1120)
    • Reads the Windows owner or organization settings

      • aso3setup_systweak-default.tmp (PID: 1120)
    • Reads the Internet Settings

      • aso3setup_systweak-default.tmp (PID: 1120)
      • RequireAdministrator.exe (PID: 1640)
      • PTBWin7.exe (PID: 2272)
      • RequireAdministrator.exe (PID: 2868)
      • ASO3.exe (PID: 2280)
      • HighestAvailable.exe (PID: 1236)
      • ASO3.exe (PID: 1840)
      • RequireAdministrator.exe (PID: 1244)
    • Reads security settings of Internet Explorer

      • aso3setup_systweak-default.tmp (PID: 1120)
      • RequireAdministrator.exe (PID: 1640)
      • PTBWin7.exe (PID: 2272)
      • RequireAdministrator.exe (PID: 2868)
      • ASO3.exe (PID: 2280)
      • HighestAvailable.exe (PID: 1236)
      • ASO3.exe (PID: 1840)
      • RequireAdministrator.exe (PID: 1244)
    • The process drops C-runtime libraries

      • aso3setup_systweak-default.tmp (PID: 1120)
    • Reads the BIOS version

      • ASO3.exe (PID: 2280)
      • ASO3.exe (PID: 3008)
      • ASO3.exe (PID: 1840)
      • ASO3.exe (PID: 664)
    • Creates/Modifies COM task schedule object

      • ASO3.exe (PID: 2280)
      • regsvr32.exe (PID: 1628)
    • Checks Windows Trust Settings

      • PTBWin7.exe (PID: 2272)
    • Reads settings of System Certificates

      • PTBWin7.exe (PID: 2272)
    • Adds/modifies Windows certificates

      • PTBWin7.exe (PID: 2272)
    • The process executes VB scripts

      • PTBWin7.exe (PID: 2272)
    • Creates a Folder object (SCRIPT)

      • cscript.exe (PID: 2648)
    • Access to an unwanted program domain was detected

      • ASO3.exe (PID: 2280)
      • ASO3.exe (PID: 1840)
  • INFO

    • Checks supported languages

      • aso3setup_systweak-default.tmp (PID: 3984)
      • aso3setup_systweak-default.exe (PID: 928)
      • aso3setup_systweak-default.exe (PID: 3968)
      • aso3setup_systweak-default.tmp (PID: 1120)
      • KillASOProcesses.exe (PID: 2044)
      • RequireAdministrator.exe (PID: 1640)
      • ASO3.exe (PID: 2280)
      • PTBWin7.exe (PID: 2272)
      • RequireAdministrator.exe (PID: 2868)
      • ASO3.exe (PID: 3008)
      • wmpnscfg.exe (PID: 3588)
      • ASO3.exe (PID: 1840)
      • HighestAvailable.exe (PID: 1236)
      • RequireAdministrator.exe (PID: 1244)
      • ASO3.exe (PID: 664)
    • Reads the computer name

      • aso3setup_systweak-default.tmp (PID: 3984)
      • KillASOProcesses.exe (PID: 2044)
      • aso3setup_systweak-default.tmp (PID: 1120)
      • RequireAdministrator.exe (PID: 1640)
      • ASO3.exe (PID: 2280)
      • PTBWin7.exe (PID: 2272)
      • RequireAdministrator.exe (PID: 2868)
      • wmpnscfg.exe (PID: 3588)
      • HighestAvailable.exe (PID: 1236)
      • ASO3.exe (PID: 3008)
      • ASO3.exe (PID: 1840)
      • RequireAdministrator.exe (PID: 1244)
      • ASO3.exe (PID: 664)
    • Create files in a temporary directory

      • aso3setup_systweak-default.exe (PID: 3968)
      • aso3setup_systweak-default.exe (PID: 928)
      • aso3setup_systweak-default.tmp (PID: 1120)
      • PTBWin7.exe (PID: 2272)
      • ASO3.exe (PID: 3008)
      • ASO3.exe (PID: 1840)
      • ASO3.exe (PID: 664)
    • Creates files in the program directory

      • aso3setup_systweak-default.tmp (PID: 1120)
    • Application launched itself

      • msedge.exe (PID: 1552)
      • msedge.exe (PID: 1868)
    • Creates a software uninstall entry

      • aso3setup_systweak-default.tmp (PID: 1120)
    • Creates files or folders in the user directory

      • aso3setup_systweak-default.tmp (PID: 1120)
      • cscript.exe (PID: 2648)
    • Reads the software policy settings

      • PTBWin7.exe (PID: 2272)
    • Manual execution by a user

      • msedge.exe (PID: 1868)
      • RequireAdministrator.exe (PID: 2544)
      • RequireAdministrator.exe (PID: 2868)
      • wmpnscfg.exe (PID: 3588)
      • HighestAvailable.exe (PID: 1236)
      • HighestAvailable.exe (PID: 4064)
      • RequireAdministrator.exe (PID: 1596)
      • RequireAdministrator.exe (PID: 1244)
    • Reads security settings of Internet Explorer

      • cscript.exe (PID: 2648)
    • Reads the machine GUID from the registry

      • PTBWin7.exe (PID: 2272)
      • ASO3.exe (PID: 2280)
      • ASO3.exe (PID: 1840)
    • Checks proxy server information

      • ASO3.exe (PID: 2280)
      • ASO3.exe (PID: 1840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:07:16 13:24:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 53248
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.9.3700.18392
ProductVersionNumber: 3.9.3700.18392
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Systweak Software
FileDescription: Advanced System Optimizer
FileVersion: Advanced System Opti
LegalCopyright: Copyright © 1999 - 2021 Systweak Software, All rights reserved.
ProductName: Advanced System Optimizer
ProductVersion: 3.9.3700.18392
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
107
Monitored processes
44
Malicious processes
13
Suspicious processes
1

Behavior graph

Click at the process to see the details
start aso3setup_systweak-default.exe aso3setup_systweak-default.tmp no specs aso3setup_systweak-default.exe aso3setup_systweak-default.tmp net.exe no specs net1.exe no specs killasoprocesses.exe no specs net.exe no specs net1.exe no specs regsvr32.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs msedge.exe no specs requireadministrator.exe no specs #BANLOAD aso3.exe msedge.exe no specs ptbwin7.exe no specs cscript.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs requireadministrator.exe no specs requireadministrator.exe #BANLOAD aso3.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs highestavailable.exe no specs highestavailable.exe #BANLOAD aso3.exe requireadministrator.exe no specs requireadministrator.exe #BANLOAD aso3.exe

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Windows\system32\net.exe" stop "ASO3DiskOptimizer" /y C:\Windows\System32\net.exeKillASOProcesses.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
124C:\Windows\system32\net1 stop ASO3DiskOptimizer /yC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
312"C:\Windows\System32\schtasks.exe" /delete /tn "advanced-system-protector_startup" /fC:\Windows\System32\schtasks.exeaso3setup_systweak-default.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
664"C:\Program Files\Advanced System Optimizer 3\ASO3.exe" -spcC:\Program Files\Advanced System Optimizer 3\ASO3.exe
RequireAdministrator.exe
User:
admin
Company:
Systweak Software
Integrity Level:
HIGH
Description:
Advanced System Optimizer
Version:
3.9.3700.18392
Modules
Images
c:\windows\system32\winmm.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
676"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xf0,0x6e05f598,0x6e05f5a8,0x6e05f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
928"C:\Users\admin\AppData\Local\Temp\aso3setup_systweak-default.exe" /SPAWNWND=$40130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\aso3setup_systweak-default.exe
aso3setup_systweak-default.tmp
User:
admin
Company:
Systweak Software
Integrity Level:
HIGH
Description:
Advanced System Optimizer
Exit code:
0
Version:
Advanced System Opti
Modules
Images
c:\users\admin\appdata\local\temp\aso3setup_systweak-default.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1036"C:\Windows\system32\net.exe" stop ASO3DiskOptimizer /yC:\Windows\System32\net.exeaso3setup_systweak-default.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
1120"C:\Users\admin\AppData\Local\Temp\is-32U5G.tmp\aso3setup_systweak-default.tmp" /SL5="$2013A,11352888,119296,C:\Users\admin\AppData\Local\Temp\aso3setup_systweak-default.exe" /SPAWNWND=$40130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\is-32U5G.tmp\aso3setup_systweak-default.tmp
aso3setup_systweak-default.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-32u5g.tmp\aso3setup_systweak-default.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1236"C:\Program Files\Advanced System Optimizer 3\HighestAvailable.exe" C:\Program Files\Advanced System Optimizer 3\ASO3.exeC:\Program Files\Advanced System Optimizer 3\HighestAvailable.exe
explorer.exe
User:
admin
Company:
Systweak Software
Integrity Level:
HIGH
Description:
Advanced System Optimizer - UAC Launcher
Exit code:
0
Version:
3.9.3700.18392
Modules
Images
c:\program files\advanced system optimizer 3\highestavailable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1240"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1220 --field-trial-handle=1296,i,15257477111826774554,10403030912060144116,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
24 642
Read events
23 953
Write events
535
Delete events
154

Modification events

(PID) Process:(1120) aso3setup_systweak-default.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
6004000050158BF87EB6DA01
(PID) Process:(1120) aso3setup_systweak-default.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
B6BC7C511F023E9764FD41087F35752CE41F2F9CF1B6A0A2008F382304829055
(PID) Process:(1120) aso3setup_systweak-default.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1120) aso3setup_systweak-default.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1120) aso3setup_systweak-default.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1120) aso3setup_systweak-default.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1120) aso3setup_systweak-default.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2044) KillASOProcesses.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:ASORegistryOptimizer
Value:
(PID) Process:(2044) KillASOProcesses.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Memory Optimizer
Value:
(PID) Process:(2044) KillASOProcesses.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:RightBackup
Value:
Executable files
125
Suspicious files
114
Text files
697
Unknown types
1

Dropped files

PID
Process
Filename
Type
1120aso3setup_systweak-default.tmpC:\Users\admin\AppData\Local\Temp\is-JPQVE.tmp\KillASOProcesses.exeexecutable
MD5:8365F3775085680D69185C938D4AFDFD
SHA256:C0B29198BC4B47F8E274CEB570CB3CCD9D6412C6EDA14C0D806A5F779A9D96DE
1120aso3setup_systweak-default.tmpC:\Program Files\Advanced System Optimizer 3\da\is-CO0EK.tmptext
MD5:4E9A19DE42D01411DCB9F7BBE4D60D7E
SHA256:697B97575E4E8D619264171CFD072D3C4F4E03C04749E68E446C6D5875D9D398
1120aso3setup_systweak-default.tmpC:\Users\admin\AppData\Local\Temp\is-JPQVE.tmp\aso3sys.dllexecutable
MD5:72499463594B4ABCAF507BBA0C5F96FE
SHA256:246BCD3E11ADE3FB5F2655FED97AD39EDD555852379495E188C80A042C1493A5
1120aso3setup_systweak-default.tmpC:\Users\admin\AppData\Local\Temp\is-JPQVE.tmp\zlibwapi.dllexecutable
MD5:F1B0EF23946D1D6CB40DDD8EE93A8053
SHA256:D25F33DFE1BF507D537C56A12E8A486C5B900FB56738180EAE7848B780E9B5D8
1120aso3setup_systweak-default.tmpC:\Users\admin\AppData\Local\Temp\is-JPQVE.tmp\ASEng.dllexecutable
MD5:EF22E41BC9CD11AE18ECC4A4B556296F
SHA256:2A005913A2045EBF37C1855755DE55C527E4574A2002BE47FF8BA786EBD46B5C
1120aso3setup_systweak-default.tmpC:\Program Files\Advanced System Optimizer 3\da\is-GLBV3.tmptext
MD5:50147B9C76296CE725CBB361500E0FFE
SHA256:9ED390880A2FAB0564A6339B53306E6E3F422B6A0DD5259E035C3FE5FB7F52F4
928aso3setup_systweak-default.exeC:\Users\admin\AppData\Local\Temp\is-32U5G.tmp\aso3setup_systweak-default.tmpexecutable
MD5:732AB3A914069E78BF525E9561D3404C
SHA256:10681AFEF258C1EB11B1B3174052A99CF19C9DE838FF49A961D0A13435381971
1120aso3setup_systweak-default.tmpC:\Program Files\Advanced System Optimizer 3\unins000.exeexecutable
MD5:732AB3A914069E78BF525E9561D3404C
SHA256:10681AFEF258C1EB11B1B3174052A99CF19C9DE838FF49A961D0A13435381971
1120aso3setup_systweak-default.tmpC:\Program Files\Advanced System Optimizer 3\da\aso.initext
MD5:4E9A19DE42D01411DCB9F7BBE4D60D7E
SHA256:697B97575E4E8D619264171CFD072D3C4F4E03C04749E68E446C6D5875D9D398
1120aso3setup_systweak-default.tmpC:\Program Files\Advanced System Optimizer 3\is-M24LJ.tmpexecutable
MD5:732AB3A914069E78BF525E9561D3404C
SHA256:10681AFEF258C1EB11B1B3174052A99CF19C9DE838FF49A961D0A13435381971
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
20
DNS requests
21
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2280
ASO3.exe
HEAD
23.108.29.119:80
http://www.systweak.com/getcountrycode.asp?product=aso&pid=2&isReg=1
unknown
unknown
1840
ASO3.exe
POST
200
5.79.122.22:80
http://updateservice1.systweak.com/stgenuinevalidator/STGenuineValidationService.asmx
unknown
unknown
1840
ASO3.exe
HEAD
301
23.108.29.119:80
http://www.systweak.com/getcountrycode.asp?product=aso&pid=2&isReg=1
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1088
svchost.exe
224.0.0.252:5355
unknown
1868
msedge.exe
239.255.255.250:1900
unknown
2424
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2424
msedge.exe
23.108.29.119:443
systweak.com
LEASEWEB-USA-NYC
US
unknown
2424
msedge.exe
13.107.22.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2280
ASO3.exe
23.108.29.119:80
systweak.com
LEASEWEB-USA-NYC
US
unknown
2424
msedge.exe
152.199.21.175:443
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
EDGECAST
DE
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
systweak.com
  • 23.108.29.119
unknown
edge.microsoft.com
  • 13.107.22.239
  • 131.253.33.239
whitelisted
www.systweak.com
  • 23.108.29.119
unknown
www.bing.com
  • 95.100.146.11
  • 95.100.146.18
  • 95.100.146.24
  • 95.100.146.16
  • 95.100.146.17
  • 95.100.146.32
  • 95.100.146.27
  • 95.100.146.19
  • 95.100.146.33
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
watson.microsoft.com
  • 104.208.16.93
whitelisted
updateservice1.systweak.com
  • 5.79.122.22
unknown

Threats

PID
Process
Class
Message
2280
ASO3.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Common Adware Library ISX User Agent Detected
1840
ASO3.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Microsoft-ATL-Native/9.00)
1840
ASO3.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Common Adware Library ISX User Agent Detected
1 ETPRO signatures available at the full report
Process
Message
ASO3.exe
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
ASO3.exe
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
ASO3.exe
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
ASO3.exe
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
ASO3.exe
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
ASO3.exe
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
ASO3.exe
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
ASO3.exe
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s