General Info

File name

hpset_2017.11.14.02.exe

Full analysis
https://app.any.run/tasks/2c56959b-205d-4b9d-999b-2c77fa3d030d
Verdict
Malicious activity
Analysis date
12/2/2019, 20:40:07
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5

a45b8a7bbf6726919f6cb5d7e759b124

SHA1

f0ffd294c750cfbcba221ff2bbfaaf43ddff2d20

SHA256

a95317f599b2c6731be91507b6a0bc3929dd0eb8d8f05118079b10daed8a286c

SSDEEP

6144:VBe6xLkJm4GAwhsvVKfxdr93f2+kT1EODC5yJ8cZzzq41zhfggbebeROiu:Z1kJm4Fw+v8xxZ2+LODVacdJ260

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
  • Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • YSearchSetTool.exe (PID: 1972)
  • nsAD93.tmp (PID: 1404)
  • nsA71A.tmp (PID: 1268)
  • webExt_DL.exe (PID: 3836)
Loads dropped or rewritten executable
  • hpset_2017.11.14.02.exe (PID: 2364)
  • YSearchSetTool.exe (PID: 1972)
  • webExt_DL.exe (PID: 3836)
Runs PING.EXE for delay simulation
  • cmd.exe (PID: 2784)
Changes the started page of IE
  • YSearchSetTool.exe (PID: 1972)
Starts application with an unusual extension
  • hpset_2017.11.14.02.exe (PID: 2364)
Creates files in the user directory
  • hpset_2017.11.14.02.exe (PID: 2364)
  • YSearchSetTool.exe (PID: 1972)
Executable content was dropped or overwritten
  • hpset_2017.11.14.02.exe (PID: 2364)
  • webExt_DL.exe (PID: 3836)
Starts CMD.EXE for commands execution
  • wscript.exe (PID: 2424)
Executes scripts
  • nsAD93.tmp (PID: 1404)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (67.4%)
.dll
|   Win32 Dynamic Link Library (generic) (14.2%)
.exe
|   Win32 Executable (generic) (9.7%)
.exe
|   Generic Win/DOS Executable (4.3%)
.exe
|   DOS Executable Generic (4.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:12:11 22:50:38+01:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
24064
InitializedDataSize:
118272
UninitializedDataSize:
1024
EntryPoint:
0x316d
OSVersion:
4
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
2017.11.14.2
ProductVersionNumber:
2017.11.14.2
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Windows, Latin1
CompanyName:
Yahoo! Inc.
FileDescription:
Yahoo homepage Set Setup
FileVersion:
2017.11.14.02
LegalCopyright:
Copyright (c) 2012 Yahoo! Inc.
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
11-Dec-2016 21:50:38
Detected languages
English - United States
CompanyName:
Yahoo! Inc.
FileDescription:
Yahoo homepage Set Setup
FileVersion:
2017.11.14.02
LegalCopyright:
Copyright (c) 2012 Yahoo! Inc.
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000D8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
11-Dec-2016 21:50:38
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00005CEF 0x00005E00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.44129
.rdata 0x00007000 0x00001246 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.00503
.data 0x00009000 0x0001A7F8 0x00000400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 5.1145
.ndata 0x00024000 0x0000E000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x00032000 0x00002168 0x00002200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.5358
Resources
1

2

103

105

106

111

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
44
Monitored processes
8
Malicious processes
2
Suspicious processes
1

Behavior graph

+
drop and start drop and start drop and start start hpset_2017.11.14.02.exe ysearchsettool.exe nsa71a.tmp no specs webext_dl.exe nsad93.tmp no specs wscript.exe no specs cmd.exe no specs ping.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2364
CMD
"C:\Users\admin\AppData\Local\Temp\hpset_2017.11.14.02.exe"
Path
C:\Users\admin\AppData\Local\Temp\hpset_2017.11.14.02.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Yahoo! Inc.
Description
Yahoo homepage Set Setup
Version
2017.11.14.02
Modules
Image
c:\users\admin\appdata\local\temp\hpset_2017.11.14.02.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsca6ab.tmp\system.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\yahoo\yset\ysearchsettool.exe
c:\users\admin\appdata\local\temp\nsca6ab.tmp\nsexec.dll
c:\users\admin\appdata\local\temp\nsca6ab.tmp\nsa71a.tmp
c:\users\admin\appdata\local\temp\nsca6ab.tmp\nsad93.tmp
c:\users\admin\appdata\local\temp\nsca6ab.tmp\inetc.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
1972
CMD
"C:\Users\admin\AppData\Local\Yahoo\yset\YSearchSetTool.exe" /partner=external-ie-installer /yfrc_ie=yset_ie_syc_hp /yfrc_ff=yset_ffbndl_syc_hp /yhspart_ff=mozilla /yhsimp_ff=yhs-102 /yfrc_chr=yset_chrbndl_syc_hp /ytc=oo_hpset /ytchp=oo_hpset /intl=us /setie /setchr /setff
Path
C:\Users\admin\AppData\Local\Yahoo\yset\YSearchSetTool.exe
Indicators
Parent process
hpset_2017.11.14.02.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Yahoo Inc.
Description
YSearchSetTool
Version
2017, 11, 14, 02
Modules
Image
c:\users\admin\appdata\local\yahoo\yset\ysearchsettool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\users\admin\appdata\local\yahoo\yset\ysearchutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\msxml3.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll

PID
1268
CMD
"C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\nsA71A.tmp" webExt_DL.exe
Path
C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\nsA71A.tmp
Indicators
No indicators
Parent process
hpset_2017.11.14.02.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nsca6ab.tmp\nsa71a.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yahoo\yset\webext_dl.exe

PID
3836
CMD
webExt_DL.exe
Path
C:\Users\admin\AppData\Local\Yahoo\yset\webExt_DL.exe
Indicators
Parent process
nsA71A.tmp
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\yahoo\yset\webext_dl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsia89f.tmp\inetc.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
1404
CMD
"C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\nsAD93.tmp" wscript.exe invisible.vbs checksets.bat
Path
C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\nsAD93.tmp
Indicators
No indicators
Parent process
hpset_2017.11.14.02.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nsca6ab.tmp\nsad93.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wscript.exe
c:\windows\system32\apphelp.dll

PID
2424
CMD
wscript.exe invisible.vbs checksets.bat
Path
C:\Windows\system32\wscript.exe
Indicators
No indicators
Parent process
nsAD93.tmp
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft ® Windows Based Script Host
Version
5.8.7600.16385
Modules
Image
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\scrobj.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sspicli.dll

PID
2784
CMD
cmd /c ""C:\Users\admin\AppData\Local\Yahoo\yset\checksets.bat" "
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
wscript.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll

PID
3432
CMD
PING 127.0.0.1 -n 1800
Path
C:\Windows\system32\PING.EXE
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
TCP/IP Ping Command
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\ping.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll

Registry activity

Total events
1308
Read events
1192
Write events
116
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2364
hpset_2017.11.14.02.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
clientID
{6E7CA2A3-5DD5-A648-A45D-ECD3DB5D9622}
2364
hpset_2017.11.14.02.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
firstRun
1
2364
hpset_2017.11.14.02.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
INSTDIR
C:\Users\admin\AppData\Local\Yahoo\yset
2364
hpset_2017.11.14.02.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
checkSetParams
/partner=external-ie-installer /yfrc_ie=yset_ie_syc_hp /yfrc_ff=yset_ffbndl_syc_hp /yhspart_ff=mozilla /yhsimp_ff=yhs-102 /yfrc_chr=yset_chrbndl_syc_hp /ytc=oo_hpset /ytchp=oo_hpset /intl=us
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASAPI32
EnableFileTracing
0
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASAPI32
EnableConsoleTracing
0
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASAPI32
FileTracingMask
4294901760
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASAPI32
ConsoleTracingMask
4294901760
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASAPI32
MaxFileSize
1048576
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASAPI32
FileDirectory
%windir%\tracing
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASMANCS
EnableFileTracing
0
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASMANCS
EnableConsoleTracing
0
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASMANCS
FileTracingMask
4294901760
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASMANCS
ConsoleTracingMask
4294901760
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASMANCS
MaxFileSize
1048576
2364
hpset_2017.11.14.02.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\hpset_2017_RASMANCS
FileDirectory
%windir%\tracing
2364
hpset_2017.11.14.02.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2364
hpset_2017.11.14.02.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000094000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2364
hpset_2017.11.14.02.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2364
hpset_2017.11.14.02.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2364
hpset_2017.11.14.02.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
checkSetParams
/partner=external-ie-installer /yfrc_ie=yset_ie_syc_hp /yfrc_ff=yset_ffbndl_syc_hp /yhspart_ff=mozilla /yhsimp_ff=yhs-102 /yfrc_chr=yset_chrbndl_syc_hp /ytc=oo_hpset /ytchp=oo_hpset /intl=us
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
intl
us
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASAPI32
EnableFileTracing
0
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASAPI32
EnableConsoleTracing
0
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASAPI32
FileTracingMask
4294901760
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASAPI32
ConsoleTracingMask
4294901760
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASAPI32
MaxFileSize
1048576
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASAPI32
FileDirectory
%windir%\tracing
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASMANCS
EnableFileTracing
0
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASMANCS
EnableConsoleTracing
0
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASMANCS
FileTracingMask
4294901760
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASMANCS
ConsoleTracingMask
4294901760
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASMANCS
MaxFileSize
1048576
1972
YSearchSetTool.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\YSearchSetTool_RASMANCS
FileDirectory
%windir%\tracing
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1972
YSearchSetTool.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
1972
YSearchSetTool.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\system32\p2pcollab.dll,-8042
Peer to Peer Trust
1972
YSearchSetTool.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
System Health Authentication
1972
YSearchSetTool.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\system32\dnsapi.dll,-103
Domain Name System (DNS) Server Trust
1972
YSearchSetTool.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
BitLocker Drive Encryption
1972
YSearchSetTool.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
BitLocker Data Recovery Agent
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
origSP_chr
https://www.google.com/
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\nainnfflonnhibbafliliaekinjbcgci
update_url
https://clients2.google.com/service/update2/crx
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
chromeExtID
nainnfflonnhibbafliliaekinjbcgci
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
origSP_ff
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
origSP_ie
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{773B240C-15B7-4CCF-A0E9-B22652980875}
DisplayName
Yahoo Search
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{773B240C-15B7-4CCF-A0E9-B22652980875}
URL
https://search.yahoo.com/search?p={searchTerms}&intl=us&fr=yset_ie_syc_hp&type=oo_hpset
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{773B240C-15B7-4CCF-A0E9-B22652980875}
OSDFileURL
file:///C:/Users/admin/AppData/Roaming/Yahoo/search.xml
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{773B240C-15B7-4CCF-A0E9-B22652980875}
FaviconURL
https://search.yahoo.com/favicon.ico
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{773B240C-15B7-4CCF-A0E9-B22652980875}
FaviconPath
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{773B240C-15B7-4CCF-A0E9-B22652980875}.ico
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Start Page
https://www.yahoo.com/?fr=yset_ie_syc_hp&type=oo_hpset
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
NewTabPageShow
1
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
pendingExtActivates
chr;ff;
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
pendingExtActivateParams
"C:\Users\admin\AppData\Local\Yahoo\yset\YSearchSetTool.exe" /partner=external-ie-installer /yfrc_ie=yset_ie_syc_hp /yfrc_ff=yset_ffbndl_syc_hp /yhspart_ff=mozilla /yhsimp_ff=yhs-102 /yfrc_chr=yset_chrbndl_syc_hp /ytc=oo_hpset /ytchp=oo_hpset /intl=us /setie /setchr /setff
1972
YSearchSetTool.exe
write
HKEY_CURRENT_USER\Software\Yahoo\ss
successfulSets
chr;ff;ie;
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASAPI32
EnableFileTracing
0
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASAPI32
EnableConsoleTracing
0
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASAPI32
FileTracingMask
4294901760
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASAPI32
ConsoleTracingMask
4294901760
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASAPI32
MaxFileSize
1048576
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASAPI32
FileDirectory
%windir%\tracing
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASMANCS
EnableFileTracing
0
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASMANCS
EnableConsoleTracing
0
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASMANCS
FileTracingMask
4294901760
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASMANCS
ConsoleTracingMask
4294901760
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASMANCS
MaxFileSize
1048576
3836
webExt_DL.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\webExt_DL_RASMANCS
FileDirectory
%windir%\tracing
3836
webExt_DL.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3836
webExt_DL.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000093000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3836
webExt_DL.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3836
webExt_DL.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3836
webExt_DL.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
3836
webExt_DL.exe
write
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions
C:\Users\admin\AppData\Local\Yahoo\yset\[email protected]
3836
webExt_DL.exe
write
HKEY_CURRENT_USER\Software\Mozilla\ManagedStorage\[email protected]
C:\Users\admin\AppData\Local\Yahoo\yset\[email protected]
2424
wscript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2424
wscript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1

Files activity

Executable files
11
Suspicious files
2
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\System.dll
executable
MD5: 3f176d1ee13b0d7d6bd92e1c7a0b9bae
SHA256: fa4ab1d6f79fd677433a31ada7806373a789d34328da46ccb0449bbf347bd73e
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Yahoo\yset\unset.exe
executable
MD5: 123c7afac8985a90a25e58c7bb4dd301
SHA256: 63fa11cc14cafce8fa7e746e5807b7cacb4b0a515facc13d1bfe1a041558c28f
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Yahoo\yset\YSearchSetTool.exe
executable
MD5: 1b064b826e502af4cfe61abe825bf261
SHA256: 6e76b973643ef6a46287111abf01f5302772143df39b8c41bb4b243656dcc23b
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Yahoo\yset\YSearchUtil.dll
executable
MD5: 6862afdee2883ef96a6e5dbfb7a4d32a
SHA256: a07723f4a5d659e636d34a2c19755feb0d620111029a332ea69c8b1e77cfd90a
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\nsAD93.tmp
executable
MD5: 37707a29bd8efbeb912019737bb2b584
SHA256: 4751809ef6fd3ced738392e7c5df6d4e3938d85711daa0b52b045b5092913c27
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Yahoo\yset\ypanel.exe
executable
MD5: bd1555789b5707c7d9c146c871eb04ac
SHA256: e57bd4ef9805c680a47bbb47c6862dfba37fd95a7e33bcdaeb26c24ef72de451
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\nsA71A.tmp
executable
MD5: 37707a29bd8efbeb912019737bb2b584
SHA256: 4751809ef6fd3ced738392e7c5df6d4e3938d85711daa0b52b045b5092913c27
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\nsExec.dll
executable
MD5: b5a1f9dc73e2944a388a61411bdd8c70
SHA256: 288100583f65a2b7acfc0c7e231c0e268c58d3067675543f627c01e82f6fd884
3836
webExt_DL.exe
C:\Users\admin\AppData\Local\Temp\nsiA89F.tmp\inetc.dll
executable
MD5: 92ec4dd8c0ddd8c4305ae1684ab65fb0
SHA256: 5520208a33e6409c129b4ea1270771f741d95afe5b048c2a1e6a2cc2ad829934
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\inetc.dll
executable
MD5: 92ec4dd8c0ddd8c4305ae1684ab65fb0
SHA256: 5520208a33e6409c129b4ea1270771f741d95afe5b048c2a1e6a2cc2ad829934
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Yahoo\yset\webExt_DL.exe
executable
MD5: 68ac0846c5982a9a0ba36d838ba78a10
SHA256: 533a1a41dc780064f0d46dee194a7a56bc4174abf43576a3460ae173463b0c7e
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
text
MD5: 0351517e9615efadd0e0b31f9312d012
SHA256: eb217ac61f25cee6b03593dd88fa318cb120759dcadf53f61dfe119f1ff6fe3b
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Temp\nscA6AB.tmp\nsqAFC6.tmp.htm
––
MD5:  ––
SHA256:  ––
1972
YSearchSetTool.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 67d433ea7663ffbd0f58513482a1dd67
SHA256: 9f9fb79466844b9c89a98e7ab6bc21826281e1ec86c7df38ba36bf3e7d63bc53
1972
YSearchSetTool.exe
C:\Users\admin\AppData\Roaming\Yahoo\search.xml
xml
MD5: 2796c2e79bc90181b81e0a597f06eec9
SHA256: 016ef19a0797e25b2ac42be35808fd1015aa1342b748d4185d09a654aff9835e
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Yahoo\yset\checksets.bat
text
MD5: 53136b74d9ae0821c34cf0f0ea545032
SHA256: 2081d047667212399fc1369dc47c3a1e19f896ec68428b6fa48c3a52d3c0c044
3836
webExt_DL.exe
C:\Users\admin\AppData\Local\Yahoo\yset\[email protected]
text
MD5: f7a5b3b7a3f68113095ca823b9ed661a
SHA256: 20aa817f71d4163a8c7d1d2f1b4565260fa8d71d346a9b4890ce7bad99e2dbfc
1972
YSearchSetTool.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
image
MD5: 3a07174943f82046370997254100d870
SHA256: c6f7ee2cadae2e121342a8c4245141175bfe887776206deb17149d46cf3aa827
1972
YSearchSetTool.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{773B240C-15B7-4CCF-A0E9-B22652980875}.ico
image
MD5: 3a07174943f82046370997254100d870
SHA256: c6f7ee2cadae2e121342a8c4245141175bfe887776206deb17149d46cf3aa827
3836
webExt_DL.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\yahoo_homepage-1.5.2-fx[1].xpi
compressed
MD5: 932ff4ba098232adf882e69f4a4052ec
SHA256: 0c70ff6c1117af5d8670ae411a52c6997a26a071da813a015661df8fa2130db7
3836
webExt_DL.exe
C:\Users\admin\AppData\Local\Yahoo\yset\[email protected]
compressed
MD5: 932ff4ba098232adf882e69f4a4052ec
SHA256: 0c70ff6c1117af5d8670ae411a52c6997a26a071da813a015661df8fa2130db7
2364
hpset_2017.11.14.02.exe
C:\Users\admin\AppData\Local\Yahoo\yset\invisible.vbs
text
MD5: c578d9653b22800c3eb6b6a51219bbb8
SHA256: 20a98a7e6e137bb1b9bd5ef6911a479cb8eac925b80d6db4e70b19f62a40cce2

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
4
Threats
0

HTTP requests

No HTTP requests.

Connections

PID Process IP ASN CN Reputation
1972 YSearchSetTool.exe 188.125.72.139:443 CH unknown
3836 webExt_DL.exe 34.215.211.225:443 Amazon.com, Inc. US unknown
1972 YSearchSetTool.exe 212.82.100.137:443 Yahoo! UK Services Limited CH shared
3836 webExt_DL.exe 99.86.4.60:443 AT&T Services, Inc. US suspicious
2364 hpset_2017.11.14.02.exe 188.125.72.139:443 CH unknown

DNS requests

Domain IP Reputation
geo.yahoo.com 188.125.72.139
whitelisted
addons.mozilla.org 34.215.211.225
54.71.96.255
52.27.14.112
54.148.223.52
35.163.110.240
35.162.74.127
whitelisted
search.yahoo.com 212.82.100.137
whitelisted
addons.cdn.mozilla.net 99.86.4.60
whitelisted

Threats

No threats detected.

Debug output strings

Process Message
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail
YSearchSetTool.exe 12-2-2019 19:40:25.454[1972,1796]: SUCCESS: CYSearchSetIE::prvSetYahooNewTab succeeded in setting new tab page to Yahoo because of search set fail