| File name: | CleanSetup.exe |
| Full analysis: | https://app.any.run/tasks/45855c48-0339-45d6-9656-480c36a91252 |
| Verdict: | Malicious activity |
| Analysis date: | November 21, 2023, 22:15:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 5722A538612B57A2BEE3842DF21E1283 |
| SHA1: | 83680B29F3606A870F443C2F2B19321F92971EEC |
| SHA256: | C0938EAE7B15D45F414F54A28101DF5FB1E04CFA91F21E313EA29A8E17432B03 |
| SSDEEP: | 24576:fcvF7xCH6Hnk58PD0xbyCraLC/+8XPdU9Q9qbR9JEHa3il3NlKlsEcnuWS/z9vtk:fct0H6Hk58PINyCraLC/+8XVU9Q9qbRk |
| .exe | | | InstallShield setup (36.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (26.6) |
| .exe | | | Win64 Executable (generic) (23.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2007:10:27 20:00:27+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 40960 |
| InitializedDataSize: | 532480 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4ed1 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.8.0.0 |
| ProductVersionNumber: | 1.8.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build, Special build |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | http://www.SouthBayPC.com |
| CompanyName: | South Bay Software |
| FileDescription: | OmniSetup Installer |
| FileVersion: | 1.8 |
| InternalName: | Setup |
| LegalCopyright: | Copyright © 1999-2005 South Bay Software |
| LegalTrademarks: | |
| OriginalFileName: | Setup.exe |
| PrivateBuild: | |
| ProductName: | OmniSetup |
| ProductVersion: | 1.8 |
| SpecialBuild: |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3384 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3484 | "C:\Users\admin\AppData\Local\Temp\CleanSetup.exe" | C:\Users\admin\AppData\Local\Temp\CleanSetup.exe | — | explorer.exe | |||||||||||
User: admin Company: South Bay Software Integrity Level: MEDIUM Description: OmniSetup Installer Exit code: 3221226540 Version: 1.8 Modules
| |||||||||||||||
| 3512 | "C:\Users\admin\AppData\Local\Temp\CleanSetup.exe" | C:\Users\admin\AppData\Local\Temp\CleanSetup.exe | explorer.exe | ||||||||||||
User: admin Company: South Bay Software Integrity Level: HIGH Description: OmniSetup Installer Exit code: 1 Version: 1.8 Modules
| |||||||||||||||
| 3688 | "C:\Program Files\SuperCleaner\SuperCleaner.exe" /s | C:\Program Files\SuperCleaner\SuperCleaner.exe | CleanSetup.exe | ||||||||||||
User: admin Company: South Bay Software Integrity Level: HIGH Description: SuperCleaner Exit code: 0 Version: 2.96 Modules
| |||||||||||||||
| 4060 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3384) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{627951C3-4EDB-4436-A745-FF833C13693C}\{857FCC3A-00A8-40B3-BF86-E5A324CC6E41} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3384) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{627951C3-4EDB-4436-A745-FF833C13693C} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3384) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{7B3D071F-D581-4596-84AB-25C6800DF61B} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3512) CleanSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3512) CleanSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3512) CleanSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3512) CleanSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3688) SuperCleaner.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3688) SuperCleaner.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3688) SuperCleaner.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3512 | CleanSetup.exe | C:\Users\admin\Desktop\SuperCleaner.lnk | binary | |
MD5:9574BCFEB77F8CA0909414929D61F0A4 | SHA256:36F7C5945876DDE8A04C36EC6CA041D82ECBF2C1FFBDA0B10C6371F58BB0DEAD | |||
| 3512 | CleanSetup.exe | C:\Users\admin\AppData\Local\Temp\osf9678.tmp | binary | |
MD5:1BEBC78B567898E18097A6C59A917A37 | SHA256:33CF0F8A5060F4E6F363199BFF8F3523541BBF4F7648CA81A70A3B830658EC95 | |||
| 3512 | CleanSetup.exe | C:\Program Files\SuperCleaner\click.wav | binary | |
MD5:C2E5A28D15ADA7BBFF5F039C4C55DEA3 | SHA256:D5712A8963EB3E1E181B25649ECFF3080EDE89C96350EB07E7D7CAD429E959EA | |||
| 3512 | CleanSetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SuperCleaner\SuperCleaner Help.lnk | binary | |
MD5:881D393CB589C5030BDE7D0D8A852272 | SHA256:C090DEF87CF100632F298FBB99A43E66711606B6266FE46BC0EC98D4368D2741 | |||
| 3512 | CleanSetup.exe | C:\Users\admin\AppData\Local\Temp\osf96DE.tmp | binary | |
MD5:B3FECF00F02FF7C2046FABC8A7762254 | SHA256:B160F9BFB3758313DB843EC445610273DB90FC7F199808F3B0AA26F1D654A9B9 | |||
| 3512 | CleanSetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SuperCleaner\SuperCleaner.lnk | binary | |
MD5:EAE9A116F399BA898A200F115958ACCE | SHA256:29BBE78BE6045EF0B5AAE87B357E457706B7B8D68E6E15A3963D6ADBFF6A305A | |||
| 3512 | CleanSetup.exe | C:\Program Files\SuperCleaner\osf9679.tmp | executable | |
MD5:EC0CAECE0B5E03D40C675D87D992395D | SHA256:E58BA2E33026FFFC81802CBC970AF32EF7758D4C385E3BAC0729C01350A26359 | |||
| 3512 | CleanSetup.exe | C:\Program Files\SuperCleaner\Uninst.ini | text | |
MD5:E653BEB7D6880728049A152870878593 | SHA256:D961824E5558818560C027D407D967185EF9FA874EABBF6A16428D27771E1795 | |||
| 3512 | CleanSetup.exe | C:\Users\Administrator\Desktop\SuperCleaner.lnk | binary | |
MD5:9574BCFEB77F8CA0909414929D61F0A4 | SHA256:36F7C5945876DDE8A04C36EC6CA041D82ECBF2C1FFBDA0B10C6371F58BB0DEAD | |||
| 3512 | CleanSetup.exe | C:\Program Files\SuperCleaner\SuperCleaner.exe | executable | |
MD5:EC0CAECE0B5E03D40C675D87D992395D | SHA256:E58BA2E33026FFFC81802CBC970AF32EF7758D4C385E3BAC0729C01350A26359 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3688 | SuperCleaner.exe | GET | 200 | 208.112.93.37:80 | http://www.SouthBayPC.com/SuperCleaner/ver.txt | US | text | 4 b | unknown |
— | — | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9cf51b384cb57221 | GB | compressed | 4.66 Kb | unknown |
— | — | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?linkid=44661 | DE | — | — | unknown |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D | US | binary | 471 b | unknown |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAqvpsXKY8RRQeo74ffHUxc%3D | US | binary | 471 b | unknown |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | US | binary | 471 b | unknown |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAqvpsXKY8RRQeo74ffHUxc%3D | US | binary | 471 b | unknown |
— | — | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=129792 | DE | — | — | unknown |
— | — | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=129791 | DE | — | — | unknown |
— | — | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?linkid=68920 | DE | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3688 | SuperCleaner.exe | 208.112.93.37:80 | www.southbaypc.com | LNH-INC | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.southbaypc.com |
| unknown |
ieonline.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
www.msn.com |
| whitelisted |
www.bing.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
rssgov.windows.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
support.microsoft.com |
| whitelisted |