File name:

UsbFix.exe

Full analysis: https://app.any.run/tasks/767c74b7-6c41-4c15-b0f1-f9f1d3388332
Verdict: Malicious activity
Analysis date: August 04, 2025, 17:16:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

1AC1FCBB22432215FB1604D397771A65

SHA1:

EACDE8E3F05E58B467D68CD364A541BB077B9259

SHA256:

A9676EEC66B39236D9C48973D0286E261771C55FDA42F558D35B164E87026E99

SSDEEP:

98304:vat/0SdpmYs/Nf4HhSjrckztFmG5Zmy+XerxuU3uvm3A2c8DwRosU/jxKa359bhO:m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Detected use of alternative data streams (AltDS)

      • UsbFix.exe (PID: 3740)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 2108)
      • schtasks.exe (PID: 2712)
      • schtasks.exe (PID: 972)
      • schtasks.exe (PID: 2800)
    • Creates file in the systems drive root

      • UsbFix.exe (PID: 3740)
    • Reads the Internet Settings

      • UsbFix.exe (PID: 3740)
    • Reads settings of System Certificates

      • UsbFix.exe (PID: 3740)
    • Reads security settings of Internet Explorer

      • UsbFix.exe (PID: 3740)
    • There is functionality for taking screenshot (YARA)

      • UsbFix.exe (PID: 3740)
  • INFO

    • Reads mouse settings

      • UsbFix.exe (PID: 3740)
    • The sample compiled with french language support

      • UsbFix.exe (PID: 3740)
    • Checks supported languages

      • UsbFix.exe (PID: 3740)
    • Reads the computer name

      • UsbFix.exe (PID: 3740)
    • Reads the machine GUID from the registry

      • UsbFix.exe (PID: 3740)
    • Reads product name

      • UsbFix.exe (PID: 3740)
    • Creates files in the program directory

      • UsbFix.exe (PID: 3740)
    • Checks proxy server information

      • UsbFix.exe (PID: 3740)
    • Reads Environment values

      • UsbFix.exe (PID: 3740)
    • Creates files or folders in the user directory

      • UsbFix.exe (PID: 3740)
    • Reads the software policy settings

      • UsbFix.exe (PID: 3740)
    • The process uses AutoIt

      • UsbFix.exe (PID: 3740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:10:27 15:38:29+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 581120
InitializedDataSize: 1428992
UninitializedDataSize: -
EntryPoint: 0x27f4a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 10.0.0.22
ProductVersionNumber: 3.3.14.2
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: French
CharacterSet: Unicode
FileVersion: 10.0.0.22
Comments: USB Antivirus
FileDescription: Usb Anti-Malware
ProductVersion: 3.3.14.2
LegalCopyright: Copyright (C) 2013-2019 SOSVirus
Entreprise: SOSVirus
Createdby: El Desaparecido
Email: contact@sosvirus.net
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start usbfix.exe schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs usbfix.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
972schtasks /delete /tn "UsbFix Monitor" /f"C:\Windows\System32\schtasks.exeUsbFix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2108schtasks /delete /tn "UsbFix Boot Scan" /f"C:\Windows\System32\schtasks.exeUsbFix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2276"C:\Users\admin\AppData\Local\Temp\UsbFix.exe" C:\Users\admin\AppData\Local\Temp\UsbFix.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Usb Anti-Malware
Exit code:
3221226540
Version:
10.0.0.22
Modules
Images
c:\users\admin\appdata\local\temp\usbfix.exe
c:\windows\system32\ntdll.dll
2712schtasks /delete /tn "UsbFix Monitor" /f"C:\Windows\System32\schtasks.exeUsbFix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2800schtasks /delete /tn "UsbFix Boot Scan" /f"C:\Windows\System32\schtasks.exeUsbFix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3740"C:\Users\admin\AppData\Local\Temp\UsbFix.exe" C:\Users\admin\AppData\Local\Temp\UsbFix.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Usb Anti-Malware
Version:
10.0.0.22
Modules
Images
c:\users\admin\appdata\local\temp\usbfix.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
Total events
6 570
Read events
6 513
Write events
50
Delete events
7

Modification events

(PID) Process:(3740) UsbFix.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\UsbFix
Operation:writeName:Langage
Value:
EN
(PID) Process:(3740) UsbFix.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\UsbFix
Operation:writeName:AnonymousData
Value:
0
(PID) Process:(3740) UsbFix.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\UsbFix
Operation:writeName:LunchPath
Value:
C:\Users\admin\AppData\Local\Temp\UsbFix.exe
(PID) Process:(3740) UsbFix.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System
Operation:delete valueName:DisableCMD
Value:
(PID) Process:(3740) UsbFix.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings
Operation:writeName:Enabled
Value:
1
(PID) Process:(3740) UsbFix.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
Operation:writeName:Enabled
Value:
1
(PID) Process:(3740) UsbFix.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\UsbFix
Operation:writeName:VaccinAuto
Value:
0
(PID) Process:(3740) UsbFix.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\UsbFix
Operation:writeName:ScanOnStart
Value:
0
(PID) Process:(3740) UsbFix.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\UsbFix
Operation:writeName:UsbMonitor
Value:
0
(PID) Process:(3740) UsbFix.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\UsbFix
Operation:writeName:OptionMakeListing
Value:
1
Executable files
0
Suspicious files
6
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
3740UsbFix.exeC:\Users\admin\Desktop\UsbFix Anti-Malware.lnklnk
MD5:0DD25DAA8DA07E31BEE95DD2C134827C
SHA256:52DA84A5A2D2249E86627B7A8BD19E8838CB97EF23518F1BF8E3916858D714B2
3740UsbFix.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751der
MD5:E192462F281446B5D1500D474FBACC4B
SHA256:F1BA9F1B63C447682EBF9DE956D0DA2A027B1B779ABEF9522D347D3479139A60
3740UsbFix.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:79997FCFB43EC430159527D9A75B067F
SHA256:8210133C793B05133B73C52B706B9C8FA93256D8DFD613CBBAFADAFAE75D528D
3740UsbFix.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\95638E38D3B362AE2E54AD811EA88C35binary
MD5:C8C93C451B05EEC7D8825FE68D1CBCE1
SHA256:2BA0F2EFB8A2DC0F637607651D21AA7CFBD6FEC952BEF2D3F5B259AFAC82C45B
3740UsbFix.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:77B20B5CD41BC6BB475CCA3F91AE6E3C
SHA256:5511A9B9F9144ED7BDE4CCB074733B7C564D918D2A8B10D391AFC6BE5B3B1509
3740UsbFix.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\95638E38D3B362AE2E54AD811EA88C35binary
MD5:EAD709DFBECC47602CC7D3A84E0C3B9F
SHA256:044427251EE43B4BD1A5F77FD1CBA7D9FB33786688D054793BBE5998EF4F670F
3740UsbFix.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\usbfix-free-update[1].htmbinary
MD5:4EAD38A204464D16006FC8102C0A4B1A
SHA256:1D50363762B718DFC5D22C9E3E7D52E6C0F705FB28D51CF1CE3700EB6F688599
3740UsbFix.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:53F39992572918D92943C8C78E70FB87
SHA256:8B5157090A72C97362A94EA3D6EB31935E684402357BF251A26BDD397DB65F38
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
9
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3740
UsbFix.exe
GET
200
23.3.109.48:80
http://x1.c.lencr.org/
unknown
whitelisted
3740
UsbFix.exe
GET
200
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?302fdcaa0a35e41a
unknown
whitelisted
3740
UsbFix.exe
GET
200
104.18.20.213:80
http://r11.c.lencr.org/75.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
3740
UsbFix.exe
109.234.162.139:443
www.usb-antivirus.com
O2switch Sarl
FR
unknown
3740
UsbFix.exe
199.232.210.172:80
ctldl.windowsupdate.com
FASTLY
US
whitelisted
3740
UsbFix.exe
23.3.109.48:80
x1.c.lencr.org
AKAMAI-AS
DE
whitelisted
3740
UsbFix.exe
104.18.20.213:80
r11.c.lencr.org
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
www.usb-antivirus.com
  • 109.234.162.139
unknown
ctldl.windowsupdate.com
  • 199.232.210.172
  • 199.232.214.172
whitelisted
x1.c.lencr.org
  • 23.3.109.48
whitelisted
r11.c.lencr.org
  • 104.18.20.213
  • 104.18.21.213
whitelisted

Threats

No threats detected
No debug info