File name:

Driver_Updater_setup.exe

Full analysis: https://app.any.run/tasks/6f5c31a1-8c29-47c5-b07e-9b47eeea4404
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: February 04, 2026, 20:24:15
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
adware
auto
generic
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

F13356AA28DE2DC8DD0DB037F5BB7550

SHA1:

1242FE9ECCE8793E57E1F3AC5FD55681B545D61C

SHA256:

B1897903DE6F882F17118E5ECB43E4A6E56917F972A3A64CA6AA50EAE8ADC4C5

SSDEEP:

98304:PzlGRVKb+Wn5g6mp2G8pHIoxkUWPdQg2wXo0M7B8ALgHZYB2ZA9CvzfjXr2GStEI:2IoEqB1rGz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GENERIC has been found (auto)

      • msiexec.exe (PID: 1848)
    • Changes the autorun value in the registry

      • Driver_Updater_setup.exe (PID: 8396)
    • ADWARE has been detected (SURICATA)

      • Driver Updater Elevated.exe (PID: 7736)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Driver_Updater_setup.exe (PID: 8396)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3352)
      • Driver Updater Service.exe (PID: 8764)
    • Uses TASKKILL.EXE to kill process

      • msiexec.exe (PID: 1316)
    • Application launched itself

      • msiexec.exe (PID: 1848)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 1848)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 1848)
    • Process drops SQLite DLL files

      • msiexec.exe (PID: 1848)
    • Access to an unwanted program domain was detected

      • Driver Updater Elevated.exe (PID: 7736)
  • INFO

    • The sample compiled with english language support

      • Driver_Updater_setup.exe (PID: 8396)
      • msiexec.exe (PID: 1848)
    • Create files in a temporary directory

      • Driver_Updater_setup.exe (PID: 8396)
      • Driver Updater Elevated.exe (PID: 7736)
    • Checks supported languages

      • Driver_Updater_setup.exe (PID: 8396)
      • msiexec.exe (PID: 1848)
      • msiexec.exe (PID: 1316)
      • msiexec.exe (PID: 3644)
      • msiexec.exe (PID: 7292)
      • Driver Updater.exe (PID: 9068)
      • Driver Updater Elevated.exe (PID: 7736)
      • Driver Updater Service.exe (PID: 8764)
    • Reads the computer name

      • Driver_Updater_setup.exe (PID: 8396)
      • msiexec.exe (PID: 1848)
      • msiexec.exe (PID: 1316)
      • msiexec.exe (PID: 3644)
      • msiexec.exe (PID: 7292)
      • Driver Updater Service.exe (PID: 8764)
      • Driver Updater Elevated.exe (PID: 7736)
      • Driver Updater.exe (PID: 9068)
    • Checks proxy server information

      • Driver_Updater_setup.exe (PID: 8396)
      • slui.exe (PID: 2824)
    • Creates files in the program directory

      • Driver_Updater_setup.exe (PID: 8396)
      • Driver Updater.exe (PID: 9068)
      • Driver Updater Elevated.exe (PID: 7736)
      • Driver Updater Service.exe (PID: 8764)
    • Creates files or folders in the user directory

      • Driver_Updater_setup.exe (PID: 8396)
    • Manages system restore points

      • SrTasks.exe (PID: 1784)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1848)
    • Launching a file from a Registry key

      • Driver_Updater_setup.exe (PID: 8396)
    • There is functionality for taking screenshot (YARA)

      • Driver_Updater_setup.exe (PID: 8396)
    • Manual execution by a user

      • Driver Updater.exe (PID: 9068)
    • Reads Environment values

      • Driver Updater Service.exe (PID: 8764)
    • Reads the machine GUID from the registry

      • Driver Updater Service.exe (PID: 8764)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:11:13 09:48:42+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.44
CodeSize: 3024384
InitializedDataSize: 6392832
UninitializedDataSize: -
EntryPoint: 0x275e63
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 9.2.7429.1209
ProductVersionNumber: 9.2.7429.1209
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Avanquest
FileDescription: PC HelpSoft Driver Updater Installer
FileVersion: 9,2,7429,1209
LegalCopyright: © Avanquest
InternalName: PC HelpSoft Driver Updater Installer
OriginalFileName: PC HelpSoft Driver Updater Installer.exe
ProductName: PC HelpSoft Driver Updater
ProductVersion: 9,2,7429,1209
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
15
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start driver_updater_setup.exe #GENERIC msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs taskkill.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs driver updater.exe no specs driver updater service.exe #ADWARE driver updater elevated.exe slui.exe driver_updater_setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1316C:\Windows\syswow64\MsiExec.exe -Embedding A01D897D68E4FB7AE87397036214A32AC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1368"C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe" C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\driver_updater_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1784C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:15C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1848C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2824C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3352C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3644C:\Windows\System32\MsiExec.exe -Embedding 0B970D502F04EDA1B24A11138D60C7EBC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3696\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4472\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5148"C:\WINDOWS\SysWOW64\taskkill.exe" /F /IM "Driver Updater.exe"C:\Windows\SysWOW64\taskkill.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
Total events
9 115
Read events
8 950
Write events
153
Delete events
12

Modification events

(PID) Process:(1848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000C6333C441496DC013807000054230000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000C6333C441496DC013807000054230000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000B5BA83441496DC013807000054230000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000008D1C86441496DC013807000054230000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3352) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000171BA5441496DC01180D000008220000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3352) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000171BA5441496DC01180D0000A8200000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3352) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000171BA5441496DC01180D0000FC1C0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3352) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000171BA5441496DC01180D0000D0180000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3352) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(3352) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Leave)
Value:
48000000000000000806AA441496DC01180D0000FC1C0000E80300000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
110
Suspicious files
107
Text files
16
Unknown types
2

Dropped files

PID
Process
Filename
Type
8396Driver_Updater_setup.exeC:\ProgramData\Avanquest\Driver Updater\msi-cache\d13bda68-70c0-4a9d-99c4-b28ccfce7d37.msi
MD5:
SHA256:
1848msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1848msiexec.exeC:\Windows\Installer\1e9ac7.msi
MD5:
SHA256:
1848msiexec.exeC:\Windows\Installer\MSIA74B.tmp
MD5:
SHA256:
1848msiexec.exeC:\Windows\Temp\~DFB4874C92CCE09624.TMPbinary
MD5:3E633A46EB7555802A8C25995E796F2D
SHA256:21327A9F54D2FEB0604552A76FD289442D627BCDDE0F38D18865C13DEABA7321
1848msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{87c0a8a1-ed10-4f87-9213-18701dea1f07}_OnDiskSnapshotPropbinary
MD5:3D0261ABCF7E3B40E998FF024A4F9EB8
SHA256:C8FCC10058C241C82E744AFBFC7D710D9AE62BDBF4B34CB63769C2DC9EC24107
1848msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:3D0261ABCF7E3B40E998FF024A4F9EB8
SHA256:C8FCC10058C241C82E744AFBFC7D710D9AE62BDBF4B34CB63769C2DC9EC24107
8396Driver_Updater_setup.exeC:\Users\admin\AppData\Local\Temp\72d8859d-1e59-442f-b372-36004065a5f7\sciter.dllexecutable
MD5:014DD1D0CA3CF45058C1CFF243DE1F64
SHA256:A99EB6F8B94BB47DB6EDD8DC797D6E24C43C88FF5BE3FBDE83123160892A93C0
8396Driver_Updater_setup.exeC:\ProgramData\Avanquest\Driver Updater\settings\deploy-platformtext
MD5:043FCCD6DB0426EA6FC59E809C039DD9
SHA256:D28055F99A2032A17974B7C8EDD4EC0F045A0D85F0BC6903C92E2BACD50C3C24
1848msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A37B8BA80004D3266CB4D93B2052DC10_EBDB5A7037F08CDFB408DBFC0D44B43Dbinary
MD5:28825F4B493D0B4EAFB1F34FD1AF0A6D
SHA256:D844656B5A3D1EC734853EDD52670335ACC25604CE8B7E48B3A58A65A7990BC7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
77
TCP/UDP connections
77
DNS requests
42
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8396
Driver_Updater_setup.exe
GET
204
172.66.156.90:443
https://partner-tracking.pchelpsoft.com/api/tracking/du?downloadedDate=2026-02-04T20:24:19.7200098Z
US
unknown
356
svchost.exe
POST
200
40.126.31.1:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
1848
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCEE5A5DdU7eaMAAAAAFHTlH8%3D
US
binary
1.52 Kb
unknown
7244
svchost.exe
GET
200
23.216.77.15:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
1848
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRr2bwARTxMtEy9aspRAZg5QFhagQQUgrrWPZfOn89x6JI3r%2F2ztWk1V88CEDWvt3udNB9q%2FI%2BERqsxNSs%3D
US
binary
2.19 Kb
unknown
1848
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.entrust.net/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRp%2BmQDKauE4nIg%2FgknZHuBlLkfKgQUzolPglGqFaKEYsoxI2HSYfv4%2FngCEQChBk9kDrsuRWqhOkBMo90p
US
binary
766 b
unknown
6948
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
US
binary
409 b
whitelisted
7244
svchost.exe
GET
200
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.63 Kb
whitelisted
7736
Driver Updater Elevated.exe
POST
200
13.226.244.76:80
http://api.playanext.com/httpapi
US
unknown
804
lsass.exe
GET
200
142.251.141.131:80
http://c.pki.goog/r/gsr1.crl
US
binary
1.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
7244
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8756
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3412
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
8396
Driver_Updater_setup.exe
172.66.156.90:443
partner-tracking.pchelpsoft.com
CLOUDFLARENET
US
whitelisted
804
lsass.exe
142.251.141.131:80
c.pki.goog
GOOGLE
US
whitelisted
356
svchost.exe
40.126.31.1:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8396
Driver_Updater_setup.exe
104.16.213.94:443
acdn.adaware.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
self.events.data.microsoft.com
  • 20.189.173.23
whitelisted
google.com
  • 142.251.140.174
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
partner-tracking.pchelpsoft.com
  • 172.66.156.90
  • 104.20.32.206
unknown
c.pki.goog
  • 142.251.141.131
whitelisted
login.live.com
  • 40.126.31.1
  • 20.190.159.2
  • 20.190.159.131
  • 40.126.31.67
  • 40.126.31.128
  • 20.190.159.75
  • 40.126.31.71
  • 20.190.159.4
whitelisted
acdn.adaware.com
  • 104.16.213.94
  • 104.16.212.94
unknown
ocsp.digicert.com
  • 162.159.142.9
  • 172.66.2.5
  • 23.54.109.203
whitelisted
crl.microsoft.com
  • 23.216.77.15
  • 23.216.77.35
  • 23.216.77.38
  • 23.216.77.13
  • 23.216.77.42
  • 23.216.77.32
  • 23.216.77.31
  • 23.216.77.41
  • 23.216.77.8
  • 23.216.77.27
  • 23.216.77.19
  • 23.216.77.21
  • 23.216.77.30
  • 23.216.77.17
  • 23.216.77.28
  • 23.216.77.25
  • 23.216.77.29
  • 23.216.77.22
whitelisted

Threats

PID
Process
Class
Message
7736
Driver Updater Elevated.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7736
Driver Updater Elevated.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7736
Driver Updater Elevated.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7736
Driver Updater Elevated.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7736
Driver Updater Elevated.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Driver Updater Setup Process
7736
Driver Updater Elevated.exe
A Network Trojan was detected
ET HUNTING Suspicious Fake Windows User-Agent in HTTP Header
No debug info