| File name: | Driver_Updater_setup.exe |
| Full analysis: | https://app.any.run/tasks/6f5c31a1-8c29-47c5-b07e-9b47eeea4404 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | February 04, 2026, 20:24:15 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | F13356AA28DE2DC8DD0DB037F5BB7550 |
| SHA1: | 1242FE9ECCE8793E57E1F3AC5FD55681B545D61C |
| SHA256: | B1897903DE6F882F17118E5ECB43E4A6E56917F972A3A64CA6AA50EAE8ADC4C5 |
| SSDEEP: | 98304:PzlGRVKb+Wn5g6mp2G8pHIoxkUWPdQg2wXo0M7B8ALgHZYB2ZA9CvzfjXr2GStEI:2IoEqB1rGz |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:11:13 09:48:42+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.44 |
| CodeSize: | 3024384 |
| InitializedDataSize: | 6392832 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x275e63 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 9.2.7429.1209 |
| ProductVersionNumber: | 9.2.7429.1209 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Avanquest |
| FileDescription: | PC HelpSoft Driver Updater Installer |
| FileVersion: | 9,2,7429,1209 |
| LegalCopyright: | © Avanquest |
| InternalName: | PC HelpSoft Driver Updater Installer |
| OriginalFileName: | PC HelpSoft Driver Updater Installer.exe |
| ProductName: | PC HelpSoft Driver Updater |
| ProductVersion: | 9,2,7429,1209 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1316 | C:\Windows\syswow64\MsiExec.exe -Embedding A01D897D68E4FB7AE87397036214A32A | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1368 | "C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe" | C:\Users\admin\AppData\Local\Temp\Driver_Updater_setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1784 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:15 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1848 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2824 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3352 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3644 | C:\Windows\System32\MsiExec.exe -Embedding 0B970D502F04EDA1B24A11138D60C7EB | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3696 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SrTasks.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4472 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5148 | "C:\WINDOWS\SysWOW64\taskkill.exe" /F /IM "Driver Updater.exe" | C:\Windows\SysWOW64\taskkill.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (1848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4800000000000000C6333C441496DC013807000054230000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Enter) |
Value: 4800000000000000C6333C441496DC013807000054230000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Leave) |
Value: 4800000000000000B5BA83441496DC013807000054230000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 48000000000000008D1C86441496DC013807000054230000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3352) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4800000000000000171BA5441496DC01180D000008220000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3352) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4800000000000000171BA5441496DC01180D0000A8200000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3352) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4800000000000000171BA5441496DC01180D0000FC1C0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3352) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4800000000000000171BA5441496DC01180D0000D0180000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3352) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3352) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 48000000000000000806AA441496DC01180D0000FC1C0000E80300000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8396 | Driver_Updater_setup.exe | C:\ProgramData\Avanquest\Driver Updater\msi-cache\d13bda68-70c0-4a9d-99c4-b28ccfce7d37.msi | — | |
MD5:— | SHA256:— | |||
| 1848 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 1848 | msiexec.exe | C:\Windows\Installer\1e9ac7.msi | — | |
MD5:— | SHA256:— | |||
| 1848 | msiexec.exe | C:\Windows\Installer\MSIA74B.tmp | — | |
MD5:— | SHA256:— | |||
| 1848 | msiexec.exe | C:\Windows\Temp\~DFB4874C92CCE09624.TMP | binary | |
MD5:3E633A46EB7555802A8C25995E796F2D | SHA256:21327A9F54D2FEB0604552A76FD289442D627BCDDE0F38D18865C13DEABA7321 | |||
| 1848 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{87c0a8a1-ed10-4f87-9213-18701dea1f07}_OnDiskSnapshotProp | binary | |
MD5:3D0261ABCF7E3B40E998FF024A4F9EB8 | SHA256:C8FCC10058C241C82E744AFBFC7D710D9AE62BDBF4B34CB63769C2DC9EC24107 | |||
| 1848 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:3D0261ABCF7E3B40E998FF024A4F9EB8 | SHA256:C8FCC10058C241C82E744AFBFC7D710D9AE62BDBF4B34CB63769C2DC9EC24107 | |||
| 8396 | Driver_Updater_setup.exe | C:\Users\admin\AppData\Local\Temp\72d8859d-1e59-442f-b372-36004065a5f7\sciter.dll | executable | |
MD5:014DD1D0CA3CF45058C1CFF243DE1F64 | SHA256:A99EB6F8B94BB47DB6EDD8DC797D6E24C43C88FF5BE3FBDE83123160892A93C0 | |||
| 8396 | Driver_Updater_setup.exe | C:\ProgramData\Avanquest\Driver Updater\settings\deploy-platform | text | |
MD5:043FCCD6DB0426EA6FC59E809C039DD9 | SHA256:D28055F99A2032A17974B7C8EDD4EC0F045A0D85F0BC6903C92E2BACD50C3C24 | |||
| 1848 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A37B8BA80004D3266CB4D93B2052DC10_EBDB5A7037F08CDFB408DBFC0D44B43D | binary | |
MD5:28825F4B493D0B4EAFB1F34FD1AF0A6D | SHA256:D844656B5A3D1EC734853EDD52670335ACC25604CE8B7E48B3A58A65A7990BC7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
8396 | Driver_Updater_setup.exe | GET | 204 | 172.66.156.90:443 | https://partner-tracking.pchelpsoft.com/api/tracking/du?downloadedDate=2026-02-04T20:24:19.7200098Z | US | — | — | unknown |
356 | svchost.exe | POST | 200 | 40.126.31.1:443 | https://login.live.com/RST2.srf | US | xml | 10.3 Kb | whitelisted |
1848 | msiexec.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCEE5A5DdU7eaMAAAAAFHTlH8%3D | US | binary | 1.52 Kb | unknown |
7244 | svchost.exe | GET | 200 | 23.216.77.15:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 825 b | whitelisted |
1848 | msiexec.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRr2bwARTxMtEy9aspRAZg5QFhagQQUgrrWPZfOn89x6JI3r%2F2ztWk1V88CEDWvt3udNB9q%2FI%2BERqsxNSs%3D | US | binary | 2.19 Kb | unknown |
1848 | msiexec.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.entrust.net/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRp%2BmQDKauE4nIg%2FgknZHuBlLkfKgQUzolPglGqFaKEYsoxI2HSYfv4%2FngCEQChBk9kDrsuRWqhOkBMo90p | US | binary | 766 b | unknown |
6948 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | US | binary | 409 b | whitelisted |
7244 | svchost.exe | GET | 200 | 20.73.194.208:443 | https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2 | US | text | 5.63 Kb | whitelisted |
7736 | Driver Updater Elevated.exe | POST | 200 | 13.226.244.76:80 | http://api.playanext.com/httpapi | US | — | — | unknown |
804 | lsass.exe | GET | 200 | 142.251.141.131:80 | http://c.pki.goog/r/gsr1.crl | US | binary | 1.70 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
7244 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8756 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3412 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
8396 | Driver_Updater_setup.exe | 172.66.156.90:443 | partner-tracking.pchelpsoft.com | CLOUDFLARENET | US | whitelisted |
804 | lsass.exe | 142.251.141.131:80 | c.pki.goog | GOOGLE | US | whitelisted |
356 | svchost.exe | 40.126.31.1:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8396 | Driver_Updater_setup.exe | 104.16.213.94:443 | acdn.adaware.com | CLOUDFLARENET | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
partner-tracking.pchelpsoft.com |
| unknown |
c.pki.goog |
| whitelisted |
login.live.com |
| whitelisted |
acdn.adaware.com |
| unknown |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7736 | Driver Updater Elevated.exe | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] Driver Updater Setup Process |
7736 | Driver Updater Elevated.exe | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] Driver Updater Setup Process |
7736 | Driver Updater Elevated.exe | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] Driver Updater Setup Process |
7736 | Driver Updater Elevated.exe | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] Driver Updater Setup Process |
7736 | Driver Updater Elevated.exe | Possibly Unwanted Program Detected | ADWARE [ANY.RUN] Driver Updater Setup Process |
7736 | Driver Updater Elevated.exe | A Network Trojan was detected | ET HUNTING Suspicious Fake Windows User-Agent in HTTP Header |