| File name: | PHM Plus! for Windows XP.msi |
| Full analysis: | https://app.any.run/tasks/9f4ddf69-5005-4b5f-93e9-1cf077fc90d6 |
| Verdict: | Malicious activity |
| Analysis date: | June 04, 2025, 19:16:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Create Time/Date: Mon Jun 21 07:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {900E90D0-06EF-46D0-9DC3-BC7D472A5B71}, Title: PHM Plus! for Windows XP, Author: Philippe Majerus, Keywords: PHM Plus! utilities system, Comments: Customization and enhancement utilities for Windows XP, Number of Words: 2, Last Saved Time/Date: Sun Apr 17 14:01:55 2005, Last Printed: Sun Apr 17 14:01:55 2005 |
| MD5: | B0B2EB75E33B29D17A7CB5CAF047FCBE |
| SHA1: | 16A1606EA4704A1B88B398D325E181BFBBC8C9BD |
| SHA256: | A1DC182F56FF411FE185DDEC21761D9DAE845E3773228B8B10667CB0C0176AE5 |
| SSDEEP: | 98304:p9awrh81meNS9HcAqDwahN7YP9octET+nfCuJ/KreqdhczcrI2EBmc1LYZGaHvR+:CdMzfZhcQ |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CreateDate: | 1999:06:21 07:00:00 |
|---|---|
| Software: | Windows Installer |
| Security: | Password protected |
| CodePage: | Windows Latin 1 (Western European) |
| Template: | Intel;1033 |
| Pages: | 200 |
| RevisionNumber: | {900E90D0-06EF-46D0-9DC3-BC7D472A5B71} |
| Title: | PHM Plus! for Windows XP |
| Subject: | - |
| Author: | Philippe Majerus |
| Keywords: | PHM Plus! utilities system |
| Comments: | Customization and enhancement utilities for Windows XP |
| Words: | 2 |
| ModifyDate: | 2005:04:17 14:01:55 |
| LastPrinted: | 2005:04:17 14:01:55 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\DeskBandNote.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1740 | "C:\Program Files\PHM Plus!\Ntoskrnl2bmp.exe" | C:\Program Files\PHM Plus!\Ntoskrnl2bmp.exe | — | explorer.exe | |||||||||||
User: admin Company: Majerus.net Integrity Level: MEDIUM Description: PHM Plus! Ntoskrnl to BMP Converter Exit code: 0 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 2044 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\FilesystemCustomize.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2608 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\FilesystemFlags.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3344 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\DeskBandClock.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3492 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3508 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\PHM Plus! for Windows XP.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3572 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3656 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\ShellFolderCustomize.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3676 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\FolderAppearance.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3492) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 400000000000000098B2F23985D5DB01A40D0000300F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3492) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 400000000000000098B2F23985D5DB01A40D0000300F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000004836783A85D5DB01F40D0000D80C0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000004836783A85D5DB01F40D000008090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000A2987A3A85D5DB01F40D0000C40D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000A2987A3A85D5DB01F40D0000B0030000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3492) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 75 | |||
| (PID) Process: | (3492) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000007823653A85D5DB01A40D0000300F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3492) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D285673A85D5DB01A40D000078060000E8030000010000000000000000000000338C2B31DB676A4297B780EAFE89AF4F0000000000000000 | |||
| (PID) Process: | (3572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000003A0F713A85D5DB01F40D0000B0030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3492 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3492 | msiexec.exe | C:\Windows\Installer\198860.msi | — | |
MD5:— | SHA256:— | |||
| 3492 | msiexec.exe | C:\Windows\System32\PHMWeb.chm | chm | |
MD5:363B8E2D7D5F132E53381437908841E3 | SHA256:7822522CEC3F4F3D53BDE22F46464986511F636A3B70D665A9F95B1858BC012C | |||
| 3492 | msiexec.exe | C:\Program Files\PHM Plus!\Utilities\Boot Media Center.bmp | image | |
MD5:13686AAF1C994EE66E03AF54AE467B25 | SHA256:A6FD4B54620F21D6A4500E0839877FC9E4F4D0BFE654F8411C3A245FB099B514 | |||
| 3492 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF9753BB54408089A9.TMP | gmc | |
MD5:6EC783528657F8C653D656BA5E88BB7B | SHA256:1F838138D7A3F826E896F312C7F76189F94327555F912B68853408F2FE95B85F | |||
| 3492 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:41DD53B970F1C2C7086695800491CC54 | SHA256:39FBCFAD680905C7BE2754BFBAE7F29427BFC2748F8FFA3E032302D2D2A97783 | |||
| 3492 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{312b8c33-67db-426a-97b7-80eafe89af4f}_OnDiskSnapshotProp | binary | |
MD5:41DD53B970F1C2C7086695800491CC54 | SHA256:39FBCFAD680905C7BE2754BFBAE7F29427BFC2748F8FFA3E032302D2D2A97783 | |||
| 3492 | msiexec.exe | C:\Windows\Installer\198861.ipi | binary | |
MD5:41C030A94BDDA690A184E4A025251EF5 | SHA256:09962BAED65D611AF370F328B6F15B4965A2D781C2A4989B886EBF56951F77F2 | |||
| 3492 | msiexec.exe | C:\Windows\Installer\MSI8DBF.tmp | binary | |
MD5:17A1028C063E7287DC3FC820CCA9E967 | SHA256:9A2C8F4D829BC1B85B7F3D5172AA6A3FC15A0A21D524F19EE0C4EF9EAFB24B65 | |||
| 3492 | msiexec.exe | C:\Program Files\PHM Plus!\ShellFolderCustomize.dll | executable | |
MD5:FAD33547C5B13CCFECEA9280B03B3100 | SHA256:7F7E7B29F0062D130AD86450B0C7EECF3962911FB95B048F92F3E43E89FC977E | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |