| download: | aulauncher.exe |
| Full analysis: | https://app.any.run/tasks/92fca21c-5361-40ff-b48b-717b91d877b1 |
| Verdict: | Malicious activity |
| Analysis date: | April 11, 2019, 09:57:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 882C9441A2EAA13D24626A77CCC4ADF8 |
| SHA1: | C0C80AC2AFCE222AB6D803CA832EC1CDB0F35E29 |
| SHA256: | C6C445E63639F68AC64D7F1523F5DE7FEE619B6551637E4925AF43D9D6B50051 |
| SSDEEP: | 24576:ViTafTH4PS912GrstnK8nMns8ocg/OD/L3jK8mt0XCGMkL0nPW2EWOmGODBB/3Tk:MKH4eRrWCfg2T/K8mt0XJ4PDJOwdVyzB |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2011:09:26 15:21:33+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 28672 |
| InitializedDataSize: | 445952 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x39e3 |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.6746.47 |
| ProductVersionNumber: | 1.0.6746.47 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| Comments: | SupportAssist |
| CompanyName: | Dell Inc |
| FileDescription: | SupportAssist |
| FileVersion: | 1.0.6746.47 |
| InternalName: | SupportAssist |
| LegalCopyright: | Copyright (C) 2011 |
| ProductName: | SupportAssist |
| ProductVersion: | 1.0.6746.47 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 26-Sep-2011 13:21:33 |
| Detected languages: |
|
| Comments: | SupportAssist |
| CompanyName: | Dell Inc |
| FileDescription: | SupportAssist |
| FileVersion: | 1.0.6746.47 |
| InternalName: | SupportAssist |
| LegalCopyright: | Copyright (C) 2011 |
| ProductName: | SupportAssist |
| ProductVersion: | 1.0.6746.47 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000D0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 26-Sep-2011 13:21:33 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00006F10 | 0x00007000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.49788 |
.rdata | 0x00008000 | 0x00002A92 | 0x00002C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.39389 |
.data | 0x0000B000 | 0x00067EBC | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.47278 |
.ndata | 0x00073000 | 0x00125000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00198000 | 0x000661F8 | 0x00066200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.0078 |
.reloc | 0x001FF000 | 0x00000F8A | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.21712 | 968 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 1.98416 | 67624 | UNKNOWN | English - United States | RT_ICON |
3 | 2.10904 | 38056 | UNKNOWN | English - United States | RT_ICON |
4 | 2.31681 | 16936 | UNKNOWN | English - United States | RT_ICON |
5 | 2.54584 | 9640 | UNKNOWN | English - United States | RT_ICON |
6 | 3.00092 | 4264 | UNKNOWN | English - United States | RT_ICON |
7 | 4.42989 | 1128 | UNKNOWN | English - United States | RT_ICON |
103 | 2.86354 | 104 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.73893 | 514 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.91148 | 248 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 304 | "C:\Users\admin\AppData\Local\Temp\aulauncher.exe" | C:\Users\admin\AppData\Local\Temp\aulauncher.exe | explorer.exe | ||||||||||||
User: admin Company: Dell Inc Integrity Level: HIGH Description: SupportAssist Exit code: 0 Version: 1.0.6746.47 Modules
| |||||||||||||||
| 876 | C:\Windows\system32\MsiExec.exe -Embedding F5CFBADE89C1C7320347A0DF5FBB349F | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1564 | "C:\Users\admin\AppData\Local\Temp\aulauncher.exe" | C:\Users\admin\AppData\Local\Temp\aulauncher.exe | — | explorer.exe | |||||||||||
User: admin Company: Dell Inc Integrity Level: MEDIUM Description: SupportAssist Exit code: 3221226540 Version: 1.0.6746.47 Modules
| |||||||||||||||
| 1700 | "C:\Users\admin\AppData\Roaming\PCDr\Update\Binaries\CSAW.exe" /NA | C:\Users\admin\AppData\Roaming\PCDr\Update\Binaries\CSAW.exe | appupdater.exe | ||||||||||||
User: admin Company: PC-Doctor, Inc. Integrity Level: HIGH Description: Exit code: 0 Version: 6.0.7060.33 Modules
| |||||||||||||||
| 2164 | "C:\ProgramData\PCDr\Installer\tldomxsq.pna\7za.exe" x -o"C:\ProgramData\PCDr\Installer\tldomxsq.pna\Extracted" -y "C:\ProgramData\PCDr\Installer\tldomxsq.pna\SupportAssistInstaller.exe" | C:\ProgramData\PCDr\Installer\tldomxsq.pna\7za.exe | CSAW_Child.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Standalone Console Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
| 2172 | "SupportAssistDownloadManager.exe" https://downloads.dell.com/serviceability/Catalog/SupportAssistx86-3.2.0.90.msp "C:\Windows\TEMP\SupportAssistAgent\LauncherAutoUpdate\SupportAssistx86-3.2.0.90.msp" | C:\ProgramData\PCDr\Installer\tldomxsq.pna\Extracted\SupportAssistDownloadManager.exe | SupportAssistInstaller.exe | ||||||||||||
User: admin Company: Dell Inc. Integrity Level: HIGH Description: DownloadManager Exit code: 0 Version: 3.2.0.0 Modules
| |||||||||||||||
| 2188 | "SupportAssistDownloadManager.exe" https://downloads.dell.com/serviceability/Catalog/SupportAssistx86-3.2.0.90.msi "C:\Windows\TEMP\SupportAssistAgent\LauncherAutoUpdate\SupportAssistx86-3.2.0.90.msi" | C:\ProgramData\PCDr\Installer\tldomxsq.pna\Extracted\SupportAssistDownloadManager.exe | SupportAssistInstaller.exe | ||||||||||||
User: admin Company: Dell Inc. Integrity Level: HIGH Description: DownloadManager Exit code: 0 Version: 3.2.0.0 Modules
| |||||||||||||||
| 2208 | "C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe" | C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe | services.exe | ||||||||||||
User: SYSTEM Company: Dell Inc. Integrity Level: SYSTEM Description: Service Exit code: 0 Version: 3.2.0.90 Modules
| |||||||||||||||
| 3080 | "C:\ProgramData\PCDr\CSAW\CSAW_Child.exe" /child | C:\ProgramData\PCDr\CSAW\CSAW_Child.exe | CSAW.exe | ||||||||||||
User: admin Company: PC-Doctor, Inc. Integrity Level: HIGH Description: Exit code: 0 Version: 6.0.7060.33 Modules
| |||||||||||||||
| 3276 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted |
| Operation: | write | Name: | C:\Users\admin\AppData\Local\Temp\aulauncher.exe |
Value: 1 | |||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | DSC3 updater |
Value: "C:\Users\admin\AppData\Local\Temp\aulauncher.exe" /launchrunonce | |||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\PC-Doctor, Inc.\Certificates\8182A6651D652EA07121A4407EE4833C12FDF466 |
| Operation: | write | Name: | Blob |
Value: 0300000001000000140000008182A6651D652EA07121A4407EE4833C12FDF46620000000010000006B050000308205673082044FA00302010202101A487B5F3B57E6E27197A80CACD658AD300D06092A864886F70D01010505003081B4310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313B3039060355040B13325465726D73206F66207573652061742068747470733A2F2F7777772E766572697369676E2E636F6D2F727061202863293130312E302C06035504031325566572695369676E20436C617373203320436F6465205369676E696E672032303130204341301E170D3133313032383030303030305A170D3135313131333233353935395A3081AA310B3009060355040613025553310E300C060355040813055465786173311330110603550407130A526F756E6420526F636B3111300F060355040A140844656C6C20496E633110300E060355040B14074F532043657274313E303C060355040B13354469676974616C20494420436C6173732033202D204D6963726F736F667420536F6674776172652056616C69646174696F6E2076323111300F0603550403140844656C6C20496E6330820122300D06092A864886F70D01010105000382010F003082010A0282010100C3082FAF27D76CDD945EF00A6EB70949B1EC48E4164FD9195A8AF650C71827EF16198AB99639194CAA08B0EA37BC2F856A89B4129FA97497D6EBE968EAF7943DDF03C89DD2899CE94CE687F0994F67C41853C2DFE941E174940B42CACC32D520D40E986C9C6893F7E50930044A6F42BD90DE43F40713D1AB48F448AD1A2243F84E444DE362B4477B44F410D70C68C0657137CD068D0AFA2EE5EF563F92F6CA2CB66BBBF23242099B056E418441BECD03D02D622D228D17F22CCD4DFBCF9040B62A160C70FA2660034B80F811A3ACFDA044F2D1D00A6CCEABF95C60459CE9267A118C89A79C443D1AC52E70C38D1627A7B2E1124478C17D640B20504596E87CE10203010001A382017B3082017730090603551D1304023000300E0603551D0F0101FF04040302078030130603551D25040C300A06082B0601050507030330440603551D20043D303B3039060B6086480186F84501071703302A302806082B06010505070201161C68747470733A2F2F7777772E766572697369676E2E636F6D2F637073301F0603551D23041830168014CF99A9EA7B26F44BC98E8FD7F00526EFE3D2A79D30400603551D1F043930373035A033A031862F687474703A2F2F637363332D323031302D63726C2E766572697369676E2E636F6D2F435343332D323031302E63726C307106082B0601050507010104653063302406082B060105050730018618687474703A2F2F6F6373702E766572697369676E2E636F6D303B06082B06010505073002862F687474703A2F2F637363332D323031302D6169612E766572697369676E2E636F6D2F435343332D323031302E636572301106096086480186F84201010404030204103016060A2B06010401823702011B040830060101000101FF300D06092A864886F70D01010505000382010100D410DB8BE0BEAFCB79E49D1190BD79632628B8817B84EA9AB62217DF299F6F9AB651DBBB439190100577F1A42D2EAC8CCF466A2210D3E86EF382DCE515890B2EF745A7A7DF06B2FC0580B7D68265679899C8982B8936ED65AEE3E75DAA2E355BC051F8930132F14B5AFA7A11CD2A1844C74CB1384D70FA48631CE89F2D1EF2E28BF605756B71956E7BF4C6A1C34875AE23F5E9690C21A3A0451476BD79AB1D0B1620CC5166E449FCCD6C254ED383BCCED62955E73B9976F39D4A121E9FF4456652561CF02D52A3277E830E58CD706BC10CA8F1AE26EF57AF1B9ADCC205CFE279C58AF56561164E4DC88F22742F28BF920482E1B80E4D08853CE7232619906470 | |||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\PC-Doctor\ReferencedCerts |
| Operation: | write | Name: | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\dell_dellCodeSigning_1a48.cer |
Value: AD58D6AC0CA89771E2E6573B5F7B481A | |||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\PC-Doctor\ReferencedCerts |
| Operation: | write | Name: | Ref: 1a 48 7b 5f 3b 57 e6 e2 71 97 a8 0c ac d6 58 ad |
Value: 01 | |||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\PC-Doctor, Inc.\Certificates\B13B89BABC4F77D681ADEFB714EE6090146079D1 |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000B13B89BABC4F77D681ADEFB714EE6090146079D1200000000100000059050000308205553082043DA003020102021014D4785D09B38EE8D252EBC02FB11EC1300D06092A864886F70D01010505003081B4310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313B3039060355040B13325465726D73206F66207573652061742068747470733A2F2F7777772E766572697369676E2E636F6D2F727061202863293130312E302C06035504031325566572695369676E20436C617373203320436F6465205369676E696E672032303130204341301E170D3134313231343030303030305A170D3138303230353233353935395A308186310B3009060355040613025553310E300C060355040813055465786173311330110603550407130A526F756E6420526F636B31123010060355040A140944656C6C20496E632E312A3028060355040B142150726F647563742047726F75702052656C6561736520456E67696E656572696E67311230100603550403140944656C6C20496E632E30820122300D06092A864886F70D01010105000382010F003082010A0282010100C2083F636F34CFF06D1AD1A26176639E58AAA4EE2C386000BA078621C3F7758353C23E792CD314BF3E6DA3A74CD44A727DB40086C229457B6A1149A0458E790B28598DFEFB6CB254B9263AE4F68186A29FAED9A506F4E6AB585D1AFF1BA7111B85F8685327CC4BA4DCE8EFD6ECB69CA874105A3D290AE261FFF229967E173D51903BAFAA6EF0A80C10E8CE87F2724600631EA48F22A3FF252347CAC07EAFEEC821C8DB029673A09D6E0ADA5E4DDD83C8E3D36233EA12EC31A6B5EC4E91B25B5EE841203CD6C99DBC6087315044E6B1CEC3682ABCE004B1892731CF4B663BAD3E0B0EAE2DABD6F59047521735DC055F388EADE1DC1A8375632CEF42CAA56B8A0B0203010001A382018D3082018930090603551D1304023000300E0603551D0F0101FF040403020780302B0603551D1F042430223020A01EA01C861A687474703A2F2F73662E73796D63622E636F6D2F73662E63726C30660603551D20045F305D305B060B6086480186F84501071703304C302306082B06010505070201161768747470733A2F2F642E73796D63622E636F6D2F637073302506082B0601050507020230190C1768747470733A2F2F642E73796D63622E636F6D2F72706130130603551D25040C300A06082B06010505070303305706082B06010505070101044B3049301F06082B060105050730018613687474703A2F2F73662E73796D63642E636F6D302606082B06010505073002861A687474703A2F2F73662E73796D63622E636F6D2F73662E637274301F0603551D23041830168014CF99A9EA7B26F44BC98E8FD7F00526EFE3D2A79D301D0603551D0E04160414603CAA9DD8E25D31A82804E69965299746FCF3F0301106096086480186F84201010404030204103016060A2B06010401823702011B040830060101000101FF300D06092A864886F70D010105050003820101005FAB40311F3438883120A6869AC84D7D8EB01630D637F6ECA436E9090D55665BE2576C83EBF95DDDC8CB1217135B8491B19B0E2246F2380043C0DFF4530EB9D838DD496BCC93E5BDF72CA2A094ED1108023D39484F729A5FFAD1D385C20B88B60FE4B23C5C2ECC5C2D2DD109AEFCE423A9D5B0B4B54F86F122DBEBEC7C7F102AEFDA87F6EBECDB87A78ADF5E3908FDD0032D9E457FF83BFF1655212E953D7B1DCC0F1BE470EB0CB4C1AF8586752EF088D2F724F6BE69462F96AFBF4811875DB14B235BE30D8DDDA40B9F28609712F2A0F056E22F30C988160297A5F23CB7299B9446B0E0E6AA263525DDBE41946D2EFE1247B0ED10F66F9C0E98F5E208180CB0 | |||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\PC-Doctor\ReferencedCerts |
| Operation: | write | Name: | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\dell_dellCodeSigning_14d4.cer |
Value: C11EB12FC0EB52D2E88EB3095D78D414 | |||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\PC-Doctor\ReferencedCerts |
| Operation: | write | Name: | Ref: 14 d4 78 5d 09 b3 8e e8 d2 52 eb c0 2f b1 1e c1 |
Value: 01 | |||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\PC-Doctor, Inc.\Certificates\95359916FA95D0B523293E11F84CA683AFC9F7EF |
| Operation: | write | Name: | Blob |
Value: 03000000010000001400000095359916FA95D0B523293E11F84CA683AFC9F7EF2000000001000000F7040000308204F3308203DBA003020102021015E43FDB2D440907B8FEF26275D6CACF300D06092A864886F70D01010505003081B6310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313B3039060355040B13325465726D73206F66207573652061742068747470733A2F2F7777772E766572697369676E2E636F6D2F7270612028632930393130302E06035504031327566572695369676E20436C617373203320436F6465205369676E696E6720323030392D32204341301E170D3130303730373030303030305A170D3133303730363233353935395A3081B0310B3009060355040613025553310F300D060355040813064E6576616461310D300B0603550407130452656E6F31183016060355040A140F50432D446F63746F722C20496E632E313E303C060355040B13354469676974616C20494420436C6173732033202D204D6963726F736F667420536F6674776172652056616C69646174696F6E207632310D300B060355040B140433333535311830160603550403140F50432D446F63746F722C20496E632E30819F300D06092A864886F70D010101050003818D0030818902818100A478A9538C27E462F81D34E080F7916CF77ADFD99190A973C40E1B2637C7C047E1054522DD54CBAF67C28506DB0D0D01A3BD63688D65F2F2DB08C35BD2DC80EB08590B0C4E3CBC6D3AEEBD3167AE0C68A19F64A64D2A4D8817F6DC424DCF403845F1A10343AD016A486C07C2AEA3270A3AAFF9DA15EC25A99C772EB4F6E86E990203010001A38201833082017F30090603551D1304023000300E0603551D0F0101FF04040302078030440603551D1F043D303B3039A037A0358633687474703A2F2F637363332D323030392D322D63726C2E766572697369676E2E636F6D2F435343332D323030392D322E63726C30440603551D20043D303B3039060B6086480186F84501071703302A302806082B06010505070201161C68747470733A2F2F7777772E766572697369676E2E636F6D2F72706130130603551D25040C300A06082B06010505070303307506082B0601050507010104693067302406082B060105050730018618687474703A2F2F6F6373702E766572697369676E2E636F6D303F06082B060105050730028633687474703A2F2F637363332D323030392D322D6169612E766572697369676E2E636F6D2F435343332D323030392D322E636572301F0603551D2304183016801497D06BA82670C8A13F941F082DC4359BA4A11EF2301106096086480186F84201010404030204103016060A2B06010401823702011B040830060101000101FF300D06092A864886F70D0101050500038201010053CB3DF0AD5E3682CC1D03C91A74A4DF6F508F0B050F6483CF7599F85A33C4DF0B5DC224CC03289A34AE39574044151EC62550517AB03FF42C5A0C43AD3F9677DCF55B1411FDBD0253247F346883BCE9D1DFD6D782AE6973690E83D9003C657DB04B335EF633455B6025CC289157A0A45FCB3B7082F6A15D11E5FDCBBFED9CC52C1AB40499905A37534B957A759BAE260B8600424059ADC70DF9CC8AD27151F3C30CB986F66D05C5905812CCD888243D21ACE8CF8E514EDE7A1AD712DC6747DAED7E475C3A6910289CE6C9119396E6054644D1FEBE9A5DF8A19B2670057FD0BEB24E7FBBF4A65754060F7E89233F2FFF3D6826E8410C3702E1AC771A7C5B3A82 | |||
| (PID) Process: | (304) aulauncher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\PC-Doctor\ReferencedCerts |
| Operation: | write | Name: | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\pcdcert.cer |
Value: CFCAD67562F2FEB80709442DDB3FE415 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 304 | aulauncher.exe | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\pcdr-plugin.dll | executable | |
MD5:EFEB058471804FB8FE7358E6BD8B338F | SHA256:FA24EF5862C05AD54961B1A3C7946A7FF1A67BCBF60044317B73E09A297D4B6A | |||
| 304 | aulauncher.exe | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\Regex.dll | executable | |
MD5:CFA7A3B2B4BEE545A47FD60A679780E2 | SHA256:994D027553BD113C70335B3E5E5757DFB2EE2FB4EA53F50015EE6BE9CCA773FE | |||
| 304 | aulauncher.exe | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\msvcp120.dll | executable | |
MD5:FD5CABBE52272BD76007B68186EBAF00 | SHA256:87C42CA155473E4E71857D03497C8CBC28FA8FF7F2C8D72E8A1F39B71078F608 | |||
| 304 | aulauncher.exe | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\pcdDellCert1946.cer | der | |
MD5:154DE12CC5FB23A55D9E6D7692D4FB5A | SHA256:32DDDEF7B4C5B248AC5C0AC05C39406FDFFFFCD8720B227EC6F7058FD82DC9A1 | |||
| 304 | aulauncher.exe | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\pcdsrvc.pkms | executable | |
MD5:2DD9D5A9150C7015AC7F215EFA59E44F | SHA256:06A5D8632ECDD64DA4E44DDF3495A62657B513B1139CB8A3A78F641D4E31BF95 | |||
| 304 | aulauncher.exe | C:\Users\admin\AppData\Roaming\PCDr\Installer\Logs\aulauncher.log | text | |
MD5:— | SHA256:— | |||
| 304 | aulauncher.exe | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\dell_certfile.cer | der | |
MD5:6F7E7D787FE9E385440F6FFBB6EFAF2F | SHA256:D62DD1DBA6F1D69024B915B1F20FCC92BD4C50BC91D9C3B54D096F7C6852A768 | |||
| 304 | aulauncher.exe | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\KernelMode.dll | executable | |
MD5:8FAB7459B5008A566DBB2885D7BABCE4 | SHA256:77DC7BA2BD929B8BFDD81C99A183F97CE6A9C2815A150F765AE28AA23438A152 | |||
| 304 | aulauncher.exe | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\Common.dll | executable | |
MD5:6878D1F07F184236EE2532064A875C86 | SHA256:7236F37C47A89C6EC4AD6F7B7A3253D7AC315F7870738028659485DEA82904F9 | |||
| 304 | aulauncher.exe | C:\Users\admin\AppData\Local\Temp\nsc6724.tmp\dell_dellCodeSigning_14d4.cer | der | |
MD5:CA80B16DC6A684CA5EE1EAEFAEBB0E7A | SHA256:6B1302EE6D9632D42FD8BEA58291F36E322D72772538A73B105DB0D94E4AAAE0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3972 | appupdater.exe | GET | 200 | 2.18.232.183:80 | http://content.dellsupportcenter.com/updates/master/master_6746_dsc.xml | unknown | xml | 652 b | suspicious |
3972 | appupdater.exe | GET | 200 | 23.51.123.27:80 | http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D | NL | der | 1.71 Kb | whitelisted |
3972 | appupdater.exe | GET | 200 | 23.51.123.27:80 | http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE%2FlB8ILcQ1m6ShHvICEBXkP9stRAkHuP7yYnXWys8%3D | NL | der | 1.63 Kb | whitelisted |
3972 | appupdater.exe | GET | 200 | 23.51.123.27:80 | http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEH9IjqmlpJ%2BCUCOOr457bEU%3D | NL | der | 1.62 Kb | whitelisted |
3972 | appupdater.exe | GET | 200 | 2.18.232.183:80 | http://content.dellsupportcenter.com/updates/tora/6992/1111/00/rules/rules_dsc_6746_47.xml | unknown | xml | 15.2 Kb | suspicious |
3972 | appupdater.exe | GET | 200 | 2.18.232.183:80 | http://content.dellsupportcenter.com/updates/tora/6992/1111/00/rules/withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip | unknown | compressed | 60.9 Kb | suspicious |
3972 | appupdater.exe | GET | 200 | 2.18.232.183:80 | http://content.dellsupportcenter.com/updates/tora/6992/1111/00/rules/withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip | unknown | compressed | 60.9 Kb | suspicious |
3972 | appupdater.exe | GET | 200 | 23.51.123.27:80 | http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEBTUeF0Js47o0lLrwC%2BxHsE%3D | NL | der | 1.62 Kb | whitelisted |
3972 | appupdater.exe | GET | 200 | 93.184.220.29:80 | http://sf.symcb.com/sf.crt | US | der | 1.51 Kb | whitelisted |
3972 | appupdater.exe | GET | 200 | 93.184.220.29:80 | http://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer | US | text | 1.77 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3972 | appupdater.exe | 2.18.232.183:80 | content.dellsupportcenter.com | Akamai International B.V. | — | whitelisted |
1700 | CSAW.exe | 2.18.232.183:80 | content.dellsupportcenter.com | Akamai International B.V. | — | whitelisted |
1700 | CSAW.exe | 54.239.25.128:443 | firehose.us-east-1.amazonaws.com | Amazon.com, Inc. | US | shared |
3080 | CSAW_Child.exe | 54.239.25.128:443 | firehose.us-east-1.amazonaws.com | Amazon.com, Inc. | US | shared |
3972 | appupdater.exe | 23.51.123.27:80 | ocsp.verisign.com | Akamai Technologies, Inc. | NL | whitelisted |
3080 | CSAW_Child.exe | 2.18.232.183:80 | content.dellsupportcenter.com | Akamai International B.V. | — | whitelisted |
3840 | SupportAssistDownloadManager.exe | 104.111.214.12:443 | downloads.dell.com | Akamai International B.V. | NL | whitelisted |
3336 | SupportAssistInstaller.exe | 23.51.123.27:80 | ocsp.verisign.com | Akamai Technologies, Inc. | NL | whitelisted |
2208 | SupportAssistAgent.exe | 104.111.214.12:443 | downloads.dell.com | Akamai International B.V. | NL | whitelisted |
1700 | CSAW.exe | 13.35.254.54:80 | x.ss2.us | — | US | malicious |
Domain | IP | Reputation |
|---|---|---|
content.dellsupportcenter.com |
| suspicious |
sf.symcb.com |
| whitelisted |
ocsp.verisign.com |
| whitelisted |
sf.symcd.com |
| whitelisted |
csc3-2009-2-aia.verisign.com |
| whitelisted |
csc3-2010-aia.verisign.com |
| whitelisted |
sv.symcb.com |
| whitelisted |
s2.symcb.com |
| whitelisted |
sv.symcd.com |
| shared |
firehose.us-east-1.amazonaws.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
3972 | appupdater.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
Process | Message |
|---|---|
SupportAssistInstaller.exe | log4net:ERROR Could not create Appender [CustomizedFileAppender] of type [Dell.Services.SupportAssist.Logger.CustomizedFileAppender, Logger]. Reported error follows.
|
SupportAssistInstaller.exe | System.IO.FileNotFoundException: Could not load file or assembly 'Logger' or one of its dependencies. The system cannot find the file specified.
File name: 'Logger'
at System.RuntimeTypeHandle.GetTypeByName(String name, Boolean throwOnError, Boolean ignoreCase, Boolean reflectionOnly, StackCrawlMarkHandle stackMark, IntPtr pPrivHostBinder, Boolean loadTypeFromPartialName, ObjectHandleOnStack type)
at System.RuntimeTypeHandle.GetTypeByName(String name, Boolean throwOnError, Boolean ignoreCase, Boolean reflectionOnly, StackCrawlMark& stackMark, IntPtr pPrivHostBinder, Boolean loadTypeFromPartialName)
at System.RuntimeType.GetType(String typeName, Boolean throwOnError, Boolean ignoreCase, Boolean reflectionOnly, StackCrawlMark& stackMark)
at System.Type.GetType(String typeName, Boolean throwOnError, Boolean ignoreCase)
at log4net.Util.SystemInfo.GetTypeFromString(Assembly relativeAssembly, String typeName, Boolean throwOnError, Boolean ignoreCase)
at log4net.Util.SystemInfo.GetTypeFromString(String typeName, Boolean throwOnError, Boolean ignoreCase)
at log4net.Repository.Hierarchy.XmlHierarchyConfigurator.ParseAppender(XmlElement appenderElement)
WRN: Assembly binding logging is turned OFF.
To enable assembly bind failure logging, set the registry value [HKLM\Software\Microsoft\Fusion!EnableLog] (DWORD) to 1.
Note: There is some performance penalty associated with assembly bind failure logging.
To turn this feature off, remove the registry value [HKLM\Software\Microsoft\Fusion!EnableLog].
|
SupportAssistInstaller.exe | log4net:ERROR Appender named [CustomizedFileAppender] not found.
|
SupportAssistInstaller.exe | log4net:ERROR Could not create Appender [CustomizedFileAppender] of type [Dell.Services.SupportAssist.Logger.CustomizedFileAppender, Logger]. Reported error follows.
|
SupportAssistInstaller.exe | log4net:ERROR Appender named [CustomizedFileAppender] not found.
|
SupportAssistInstaller.exe | log4net:ERROR Appender named [CustomizedFileAppender] not found.
|
SupportAssistAgent.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Dell\SupportAssistAgent\bin\x86\sqlite3.dll"...
|