General Info

File name

osc.exe.bin

Full analysis
https://app.any.run/tasks/3b4b9130-052d-47b5-82b2-ff4eed04ac25
Verdict
Malicious activity
Analysis date
3/14/2019, 12:57:21
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

d14d9fa1de10211e5a7cb8a32b2fc960

SHA1

8489b5e26b42930a27579c7a4e29fcfb560eccba

SHA256

cd4aa43403e69d55b34ae91b8847c7404c9738836d73dc4e0d27c8a9ec6f29b5

SSDEEP

98304:uKL+1tLnQIzgnhdDM5Z/9CPLhbizxhe4ezJdf5L8lwfIgopkC5JHo4saIDB:7GLnQFnhFM5Z1CKxh1uJdh8qfIgopkOM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Connects to CnC server
  • OneSystemCare.exe (PID: 1148)
  • osc.exe.bin.tmp (PID: 3588)
  • osc.exe.bin.tmp (PID: 3084)
Application was dropped or rewritten from another process
  • OneSystemCare.exe (PID: 1148)
  • OneSystemCare.exe (PID: 2312)
  • _iu14D2N.tmp (PID: 2892)
  • OneSystemCare.exe (PID: 2336)
  • unins000.exe (PID: 4020)
Loads the Task Scheduler DLL interface
  • OneSystemCare.exe (PID: 1148)
Loads dropped or rewritten executable
  • _iu14D2N.tmp (PID: 2892)
Loads the Task Scheduler COM API
  • schtasks.exe (PID: 2836)
  • schtasks.exe (PID: 2676)
Uses Task Scheduler to run other applications
  • osc.exe.bin.tmp (PID: 3588)
Application launched itself
  • OneSystemCare.exe (PID: 2336)
Creates files in the Windows directory
  • OneSystemCare.exe (PID: 1148)
Creates files in the user directory
  • OneSystemCare.exe (PID: 1148)
  • osc.exe.bin.tmp (PID: 3588)
Starts CMD.EXE for commands execution
  • osc.exe.bin.tmp (PID: 3084)
  • osc.exe.bin.tmp (PID: 3588)
Creates a software uninstall entry
  • OneSystemCare.exe (PID: 2312)
  • _iu14D2N.tmp (PID: 2892)
  • OneSystemCare.exe (PID: 1148)
Starts application with an unusual extension
  • unins000.exe (PID: 4020)
Executable content was dropped or overwritten
  • _iu14D2N.tmp (PID: 2892)
  • unins000.exe (PID: 4020)
  • osc.exe.bin.exe (PID: 2988)
  • osc.exe.bin.tmp (PID: 3588)
  • osc.exe.bin.tmp (PID: 3084)
  • osc.exe.bin.exe (PID: 2412)
  • osc.exe.bin.exe (PID: 3916)
Starts itself from another location
  • unins000.exe (PID: 4020)
Reads Windows owner or organization settings
  • _iu14D2N.tmp (PID: 2892)
  • osc.exe.bin.tmp (PID: 3588)
  • osc.exe.bin.tmp (PID: 3084)
Reads the Windows organization settings
  • _iu14D2N.tmp (PID: 2892)
  • osc.exe.bin.tmp (PID: 3588)
  • osc.exe.bin.tmp (PID: 3084)
Loads dropped or rewritten executable
  • osc.exe.bin.tmp (PID: 3588)
  • osc.exe.bin.tmp (PID: 3084)
Application was dropped or rewritten from another process
  • osc.exe.bin.tmp (PID: 3588)
  • osc.exe.bin.tmp (PID: 3084)
  • osc.exe.bin.tmp (PID: 2784)
Dropped object may contain Bitcoin addresses
  • osc.exe.bin.tmp (PID: 3588)
Creates files in the program directory
  • osc.exe.bin.tmp (PID: 3588)
Creates a software uninstall entry
  • osc.exe.bin.tmp (PID: 3084)
  • osc.exe.bin.tmp (PID: 3588)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable Delphi generic (57.2%)
.exe
|   Win32 Executable (generic) (18.2%)
.exe
|   Win16/32 Executable Delphi generic (8.3%)
.exe
|   Generic Win/DOS Executable (8%)
.exe
|   DOS Executable Generic (8%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:04:06 16:39:04+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
66560
InitializedDataSize:
83456
UninitializedDataSize:
null
EntryPoint:
0x117dc
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
0.0.0.0
ProductVersionNumber:
0.0.0.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
06-Apr-2016 14:39:04
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
null
FileDescription:
null
FileVersion:
null
LegalCopyright:
null
ProductName:
null
ProductVersion:
null
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
06-Apr-2016 14:39:04
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F244 0x0000F400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.37521
.itext 0x00011000 0x00000F64 0x00001000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.7322
.data 0x00012000 0x00000C88 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.29672
.bss 0x00013000 0x000056BC 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000E04 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.59781
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x00012500 0x00012600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.02502
Resources
1

2

3

4

5

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
67
Monitored processes
25
Malicious processes
8
Suspicious processes
3

Behavior graph

+
drop and start start drop and start drop and start drop and start drop and start drop and start osc.exe.bin.exe osc.exe.bin.tmp no specs osc.exe.bin.exe osc.exe.bin.tmp osc.exe.bin.exe osc.exe.bin.tmp unins000.exe _iu14d2n.tmp onesystemcare.exe no specs schtasks.exe no specs schtasks.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs onesystemcare.exe no specs onesystemcare.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3916
CMD
"C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe"
Path
C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1000
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\osc.exe.bin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-murbb.tmp\osc.exe.bin.tmp

PID
2784
CMD
"C:\Users\admin\AppData\Local\Temp\is-MURBB.tmp\osc.exe.bin.tmp" /SL5="$2011C,5350603,151040,C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-MURBB.tmp\osc.exe.bin.tmp
Indicators
No indicators
Parent process
osc.exe.bin.exe
User
admin
Integrity Level
MEDIUM
Exit code
1000
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-murbb.tmp\osc.exe.bin.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll

PID
2412
CMD
"C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe" /SPAWNWND=$20118 /NOTIFYWND=$2011C
Path
C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe
Indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
1000
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\osc.exe.bin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-smisj.tmp\osc.exe.bin.tmp

PID
3084
CMD
"C:\Users\admin\AppData\Local\Temp\is-SMISJ.tmp\osc.exe.bin.tmp" /SL5="$20120,5350603,151040,C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe" /SPAWNWND=$20118 /NOTIFYWND=$2011C
Path
C:\Users\admin\AppData\Local\Temp\is-SMISJ.tmp\osc.exe.bin.tmp
Indicators
Parent process
osc.exe.bin.exe
User
admin
Integrity Level
HIGH
Exit code
1000
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-smisj.tmp\osc.exe.bin.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\is-t7ibr.tmp\_isetup\_iscrypt.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\temp\is-t7ibr.tmp\ykgg.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\users\admin\appdata\local\temp\osc.exe.bin.exe

PID
2988
CMD
C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe /VERYSILENT /SL5="$20120,5350603,151040,C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe" /SPAWNWND=$20118 /NOTIFYWND=$2011C
Path
C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe
Indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
1000
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\osc.exe.bin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-kngkv.tmp\osc.exe.bin.tmp

PID
3588
CMD
"C:\Users\admin\AppData\Local\Temp\is-KNGKV.tmp\osc.exe.bin.tmp" /SL5="$10130,5350603,151040,C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe" /VERYSILENT /SL5="$20120,5350603,151040,C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe" /SPAWNWND=$20118 /NOTIFYWND=$2011C
Path
C:\Users\admin\AppData\Local\Temp\is-KNGKV.tmp\osc.exe.bin.tmp
Indicators
Parent process
osc.exe.bin.exe
User
admin
Integrity Level
HIGH
Exit code
1000
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-kngkv.tmp\osc.exe.bin.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\is-mucc4.tmp\_isetup\_iscrypt.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\temp\is-mucc4.tmp\ykgg.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\qmgrprxy.dll
c:\windows\system32\bitsprx4.dll
c:\windows\system32\bitsprx2.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\onesystemcare\onesystemcare.exe
c:\program files\onesystemcare\unins000.exe
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\netutils.dll

PID
4020
CMD
"C:\Program Files\OneSystemCare\unins000.exe" /sn=4CT8wtuL3nRATcqhks49i0TxDt2hvnVVGr_QFQ9sYt8ZpWBla4LhQp0xwQzzNpS5aZY9Q-piHIVDlQboIizkcmcFWnu463giF7GEw1O8t8CbtU64WwCwG1oSr9i4KP18xA5FabSHi_9D6Zr67uyT3Xx9oLJGCbnV_IxTW7qROzivkjdX1LUEbW_UUmHETmd03Uqn06K3iLx-5CS8y5XbcGHkNL9ElYgd8Nqmq_O88uXd_F6Oyoda5GuQ55qv0FUMhvTs-wfSy9yojhHD89wzZllh3CAEiluJHaHL4W3bASYLfvg0VYzE-lwx-VFZj6veo9iQqS8U1Tvj1AYNyV4oclsclQWxLh_BkQrN1BqQSnpRHsFBG1tW40J5yj9zOPczejJFVdg-tT8YGbd8qDfKnQBo7NVX1DaQsID05vRI9FI9GEzAQvjrCGg36qj-yWf5CtVuQS7mGuJpdSkzlcZDKv-1ZgrGhrdnPhUZWmb3xXqdVc2wSSiAXtPuaCS5QGMZsKYGE0bObaYkwtF5ac79KrzkrzHHf_uNue59V-qU7XnFqMS2eBaR40-duKnT2j_No3JO2baRbCtOQjjYV7QLocEU
Path
C:\Program Files\OneSystemCare\unins000.exe
Indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\program files\onesystemcare\unins000.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\users\admin\appdata\local\temp\_iu14d2n.tmp

PID
2892
CMD
"C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp" /SECONDPHASE="C:\Program Files\OneSystemCare\unins000.exe" /FIRSTPHASEWND=$10180 /sn=4CT8wtuL3nRATcqhks49i0TxDt2hvnVVGr_QFQ9sYt8ZpWBla4LhQp0xwQzzNpS5aZY9Q-piHIVDlQboIizkcmcFWnu463giF7GEw1O8t8CbtU64WwCwG1oSr9i4KP18xA5FabSHi_9D6Zr67uyT3Xx9oLJGCbnV_IxTW7qROzivkjdX1LUEbW_UUmHETmd03Uqn06K3iLx-5CS8y5XbcGHkNL9ElYgd8Nqmq_O88uXd_F6Oyoda5GuQ55qv0FUMhvTs-wfSy9yojhHD89wzZllh3CAEiluJHaHL4W3bASYLfvg0VYzE-lwx-VFZj6veo9iQqS8U1Tvj1AYNyV4oclsclQWxLh_BkQrN1BqQSnpRHsFBG1tW40J5yj9zOPczejJFVdg-tT8YGbd8qDfKnQBo7NVX1DaQsID05vRI9FI9GEzAQvjrCGg36qj-yWf5CtVuQS7mGuJpdSkzlcZDKv-1ZgrGhrdnPhUZWmb3xXqdVc2wSSiAXtPuaCS5QGMZsKYGE0bObaYkwtF5ac79KrzkrzHHf_uNue59V-qU7XnFqMS2eBaR40-duKnT2j_No3JO2baRbCtOQjjYV7QLocEU
Path
C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp
Indicators
Parent process
unins000.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\_iu14d2n.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\is-h0oi5.tmp\ykgg.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll

PID
2312
CMD
"C:\Program Files\OneSystemCare\OneSystemCare.exe" /sn=bG6DK1vhwsW5eknSD8w7TUZVIYmnDzDhmqpAQu1vCQer8q_IqqNzACytZCaNyZDR1tAiM496z7eGT__zZiLcXh5rNHg-qE-JeWjGCA3z2xHP21k7pGBPE60hOOKVp9iBvDNzSHnzmbLRlpo_HJ4KYwMrjQlAa409WcIxRcJAGF_V5Kfo4G3A3Fiyj1YwGZpRn82MhcurZeIiEeT1Jscs2JZYQO1sv_afykfY62BxrsXVQ2VKDVv4jDrTnJvZb1ppnBeN079dvruoSDFl6oMEhwFr4AfjI_qBPmO0CexYUA8qTNN4J-5LF_zaxl-JJU9mEWPOEThgRShf25lhGHY8YFe7KzfMGxw5LysxzIeNFC6fOfSENUuuB8C1COvNEbLrQit5sh1W2YFpZdgGIcupDoqU24GGwMRoMJ-qUR0H0dfXn66k4EuFmO0iVakqBL21J18Xl-rRghzipzAgJJsxhCHvx1bi4q923eNtx3fD8ppB-qSPtMm2H4Bdo5TP0wjDDU1uXhsUu53jETiiShnn1tyvael7j5PQhBUex1wV73EtHKxZIE0E5pJZ3D2amQfxIwzQ6Kiy3JJAHQCNHOzyaXtwv5JmUurTWS0q9H_luGonEmqy
Path
C:\Program Files\OneSystemCare\OneSystemCare.exe
Indicators
No indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\onesystemcare\onesystemcare.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll

PID
2676
CMD
"C:\Windows\System32\schtasks.exe" /Create /TR "'C:\Program Files\OneSystemCare\OneSystemCare.exe' --scan" /sc ONCE /st 12:03 /sd 03/14/2019 /TN "One System Care Delayed" /F /RL HIGHEST
Path
C:\Windows\System32\schtasks.exe
Indicators
No indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\xmllite.dll

PID
2836
CMD
"C:\Windows\System32\schtasks.exe" /Create /TR "'C:\Program Files\OneSystemCare\CleanupConsole.exe' -Notify" /sc onlogon /TN "One System Care Monitor" /F /RL HIGHEST
Path
C:\Windows\System32\schtasks.exe
Indicators
No indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\xmllite.dll

PID
2636
CMD
cmd /c for /l %x in (1, 1, 2) do del /Q "C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe" & timeout /t 5
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\timeout.exe

PID
2708
CMD
cmd /c for /l %x in (1, 1, 2) do rmdir /S /Q "C:\Users\admin\AppData\Local\Temp\is-MUCC4.tmp" & timeout /t 5
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\timeout.exe

PID
2120
CMD
cmd /c for /l %x in (1, 1, 2) do del /Q "C:\Users\admin\AppData\Local\Temp\osc.exe.bin.exe" & timeout /t 5
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\timeout.exe

PID
3216
CMD
cmd /c for /l %x in (1, 1, 2) do rmdir /S /Q "C:\Users\admin\AppData\Local\Temp\is-T7IBR.tmp" & timeout /t 5
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
osc.exe.bin.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll

PID
3312
CMD
timeout /t 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2900
CMD
timeout /t 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2512
CMD
timeout /t 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3088
CMD
timeout /t 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2788
CMD
timeout /t 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2684
CMD
timeout /t 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2760
CMD
timeout /t 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2764
CMD
timeout /t 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2336
CMD
"C:\Program Files\OneSystemCare\OneSystemCare.exe"
Path
C:\Program Files\OneSystemCare\OneSystemCare.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Description
Version
Modules
Image
c:\program files\onesystemcare\onesystemcare.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mpr.dll

PID
1148
CMD
"C:\Program Files\OneSystemCare\OneSystemCare.exe"
Path
C:\Program Files\OneSystemCare\OneSystemCare.exe
Indicators
Parent process
OneSystemCare.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\program files\onesystemcare\onesystemcare.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\qmgrprxy.dll
c:\windows\system32\profapi.dll
c:\windows\system32\mstask.dll
c:\windows\system32\mpr.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\linkinfo.dll

Registry activity

Total events
1562
Read events
1454
Write events
104
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-2B74-063D-5B11-194B70507868}
cd77f991
01331CF9740500010000004000000040000000B7BB00E46D3825E900F6802CAF0437FD205B4D007BEE93AE7D9D34A820837ABE860C76B24DF96AF244C206AC6F8F4AE05323311BC14DF34D56DD22789710B933713F879F661947C10A33C163517DE5E3
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
cd77f991
0138FA75F50500010000004000000040000000101577C9E865D15D3331B64DF2414CB521420166CE3DC98E52A3B422713B6C87483515F9C2E134C51934CB2F21426311F2D03B66606B35BA150F630E3C697985F7BE076E3E03A4222F41673D28FD97F4
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
cd77f991
0133528710050001000000400000004000000027253515063330C208514AF2C0C72F94A1C1B250C684B289CFA9E2947C96E285D08DE350BB9A5C622DE1FBB3E07D970EABB9BD7E875636F0FB1375B85C74138792E7070541E4D53F5DD87F6FE5DED2E5
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
cd77f991
010F2B3E5D0500010000004000000040000000D498D8858FFB1C3A8D0701252CEBA3902BFC1F8CA7736CF725ADC5BD3CA6617DB23BE110AD1D3FE68AC30046E02D67C27A1A5FF6DD1AB7A4814686350F98E782B54B12CF0EF00D20861375947574B0D7
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
8344092e
01369851D10500010000001C0000001C0000001343C8B1A03BE2A75FDFAA77EC37BBE82C0628D5C07593FCE9F17EFF70BD90130C091FCDD34923DC99EA2D41
1148
OneSystemCare.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
1148
OneSystemCare.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@%SystemRoot%\system32\powrprof.dll,-11
Power saver
1148
OneSystemCare.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@%SystemRoot%\system32\powrprof.dll,-10
Saves energy by reducing your computer’s performance where possible.
1148
OneSystemCare.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@%SystemRoot%\system32\powrprof.dll,-13
High performance
1148
OneSystemCare.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@%SystemRoot%\system32\powrprof.dll,-12
Favors performance, but may use more energy.
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASAPI32
EnableFileTracing
0
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASAPI32
EnableConsoleTracing
0
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASAPI32
FileTracingMask
4294901760
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASAPI32
ConsoleTracingMask
4294901760
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASAPI32
MaxFileSize
1048576
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASAPI32
FileDirectory
%windir%\tracing
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASMANCS
EnableFileTracing
0
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASMANCS
EnableConsoleTracing
0
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASMANCS
FileTracingMask
4294901760
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASMANCS
ConsoleTracingMask
4294901760
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASMANCS
MaxFileSize
1048576
1148
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OneSystemCare_RASMANCS
FileDirectory
%windir%\tracing
1148
OneSystemCare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
1148
OneSystemCare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
1148
OneSystemCare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1148
OneSystemCare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1148
OneSystemCare.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@%SystemRoot%\system32\powrprof.dll,-15
Balanced
1148
OneSystemCare.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@%SystemRoot%\system32\powrprof.dll,-14
Automatically balances performance with energy consumption on capable hardware.
3084
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
0C0C0000C00B42205DDAD401
3084
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
EF78FBF029C6ABECFCC2F3EFD96EF7D3F1C9AD89C520E8FF0563C21D730ADF7D
3084
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
3084
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{764DADE4-0F9B-A755-FFFD-7B71A9FBF8E8}
cd77f991
019FF8E97F05000100000040000000400000004111438D19C203FD61238EB58C1C52DDF5486AE09484AF01F049EC75558E6447E9DF8FD2703A900413487225CB3ACF599E0E0E2442071A5ED079975AD37864609D913436BB40A3D28C5128A07E0C02F7
3084
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{764DADE4-0F9B-A755-FFFD-7B71A9FBF8E8}
cd77f991
018B500BA60500010000004000000040000000DEA99E53EB3611C57B707011EECEA397E47E21FFA568DB47161545D2E90E7AA691879A4D653537DC02AFE7FECC4D03EB18D611EFF5950E27F33EF429151193503D93A17F7E1ACC714AF2E2140FA83A62
3084
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{764DADE4-0F9B-A755-FFFD-7B71A9FBF8E8}
7e34172e
01A745CE4D0500010000001C0000001C00000037585A12A259AC69D3A4AC7089D796343E2821C035FF52D3149B3B9709C3FACB2291A684970FFEF0964C3164
3084
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
cd77f991
019BC20A5A050001000000400000004000000083724CBE96CCEC17A8E62272DA5A1A21344263158F7F04261474B4351BE010B97044AAD1300034EA001B9E343F4CA67964E3E4F0D8BC9FC1DF679C181CE0AA48244A42CA277D61BEADA08BBA08651CD6
3084
osc.exe.bin.tmp
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{764DADE4-0F9B-A755-FFFD-7B71A9FBF8E8}
3588
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Owner
040E0000502D6B225DDAD401
3588
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
SessionHash
2025FC4BB897032082C80D4EAD8F01A8782BF68227A047117755986FC58F28A4
3588
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Sequence
1
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{630A120C-71D9-63FC-FAEE-E5AF06129BD1}
cd77f991
016AE895A20500010000004000000040000000D1905F165909CDD0D26CA7FCFC6A84A0EB4E45A373DB402BE2EC2F701A45F2FD749B4AB3E475D9D989A1A59A2E1832B9AB426F787E0AB1063D7934E5B9B9B387E244F6AAA10032583A3C9203C22B23B7
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{630A120C-71D9-63FC-FAEE-E5AF06129BD1}
cd77f991
016958C35D0500010000004000000040000000B2A4C520195D76A27143B110C28C5738100B099C6D6085CE6206432E58F6AFF71B329AA99C45B82017EAA30DDE1AF0DE87A1A8590043D97C0815125BB9A92996F36BBBBFDD805CA220DADE63AA13A820
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{630A120C-71D9-63FC-FAEE-E5AF06129BD1}
7e34172e
011B6FA3580500010000001C0000001C000000820D03D02272D7995BAEFE7752057B011A67A07F9887BB05263C351064CAF9C6E76CC8D8EE2285CCDFB06FEA
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
cd77f991
010D639A9F050001000000400000004000000009B28888E06F9394D374AFCC78195917C48CD7B256A111E4BB345F78E4AE7A059CB02075E0C187723804B4BD07855067B8EF5E1C681FB94B240E20DE586490AE3057ECE2AAD7A6E422D3818D894E15C7
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{630A120C-71D9-63FC-FAEE-E5AF06129BD1}
cd77f991
01DC0A31220500010000004000000040000000D7FC9511114D3BCA0B8E7867474D1129F4AD2A08BE949EFE4350C1BB0E5130AC02F915E46B0DD77422623FF439160E99F59DC8D499F06F6130F32E7D48AF3DC56EB8DD53B9A8E311B5D911E27AE9ABD3
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{630A120C-71D9-63FC-FAEE-E5AF06129BD1}
81c3e8cc
0193CA83E60500010000001C0000001C000000C68531061539D47D70EA414873D891AF8739039E97041807B5F272F0DBE563B18AC37A3F6409CB83D2D0516D
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{763B720B-C28A-5678-B41C-AAFE7D773296}
cd77f991
014176EA780500010000004000000040000000A5969C97941924B19ED4B624DD7BC84E88C935496890B2010AE13834222A4070ADE95009C4003E8C14097718CCBC3BB2331144EF615F778389803E359048282B423FBCC01946617C01269BC250999177
3588
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFiles0000
C:\Program Files\OneSystemCare\ykgg.dll
3588
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFilesHash
0AD72B44F8ACE55521735188CDC8A02CF8CC642B1FDCB7341F459157B203DF6B
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
Inno Setup: Setup Version
5.5.9 (u)
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
Inno Setup: App Path
C:\Program Files\OneSystemCare
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
InstallLocation
C:\Program Files\OneSystemCare\
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
Inno Setup: Icon Group
One System Care
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
Inno Setup: User
admin
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
Inno Setup: Language
en
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
DisplayName
One System Care
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
DisplayIcon
C:\Program Files\OneSystemCare\OneSystemCare.exe
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
UninstallString
"C:\Program Files\OneSystemCare\unins000.exe"
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
QuietUninstallString
"C:\Program Files\OneSystemCare\unins000.exe" /SILENT
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
DisplayVersion
4.4.0.3
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
Publisher
One System Care
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
URLInfoAbout
http://www.onesystemcare.com
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
NoModify
1
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
NoRepair
1
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
InstallDate
20190314
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
MajorVersion
4
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
MinorVersion
4
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
VersionMajor
4
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
VersionMinor
4
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
EstimatedSize
9287
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
InstallDate
20180914
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1
UninstallString
"C:\Program Files\OneSystemCare\unins000.exe" /VERYSILENT
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
cd77f991
01DAC1796F0500010000004000000040000000B51EEAD710D5002D5A53F57439ECF84FE53005B7E7693C81483C0AA2919A195DB41269FC143DF7623CF63708E2BFC81F0E94853D8082AB94B024F17377D99C39968A78B577CC9E14AB7B73B2A069B91A
3588
osc.exe.bin.tmp
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
cd77f991
010099BCCA0500010000004000000040000000D657449687FBA185F18BD934FD828A053F74D0469937A2D3F58DDCD1F2E75A4BB1084558433389307D587F6F7984D15B860E740C20B44D8A0DC2E96F12234926CDD10212AA63ECE8687D32714C7E00C0
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4B4CD726-7EF9-8434-4EEA-5F1DAB018183}
f6057a2d
019782BF0E0503010000004B01000001020000982A5F06B11026CF2E3896A5317C81177F4F296E8FBC14E4ABAA6DD736CED1513A59FDD5F2C20F714A29537672CCA60D2B384BE2C129F558A56FAEBE0D594C2CE8D370759A00F15EA1C2A89521DEC2CDB864EC5462C90BCFA96874CDA1E00791911737082827E2B6D2B0FC1C98E2E1B00EA376B0AB21223BCC7CA130AB87943C3D6098BE8C20BC4814470EB27B4D6FA3E6AD38CE64B767767A5FFF55924B2153DD68280B1ACF652795BD45D9A0BF54AA6EAB2F1D20BE43C1E864837D10FCA327AEABC76396DE700160FB990BEBBDDF90F87E25B87CFCFFA9F580308A60C1F9961E43877811A40FED18445B3626D60C2C2E8D9945019CE58E3115B8E406721B50B260CAEF1D7BFD5841F9099F9A8145EB17320A3E376038571EF3CFCCBCC545F3614BC93CD1DAAD88237940FDDD6CB3F46124413E04EE5FDA119E840D201789FB3C70977DDC55A7F3C797E537EE4F9231E1525B90E2DFB822BEDE2C
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
cd77f991
0158570D140500010000004000000040000000CC2480B2865571A92282ABA639E37D13ED1B32722AB21C0C9C0B65B48A64186CE10CCD62C7E66586969DFCB2D1246C7F4D60F7BD9DFC8669EB3D51300C72F7C665A731E8E50244908A8D61C638C29C58
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{763B720B-C28A-5678-B41C-AAFE7D773296}
f6057a2d
011B0D74070503010000007501000045020000497A7D33A66D53123616BA7E27A192697C75A0C4AFB89CF6881D23413F0A1FD45A1EFA023CE61F1948C89C39FE69C3A73E34CA62D600F43AC1F09310A8F6BA817B019CA83D648C95F0301A4EBFA93CEA5D2A3D67D1CC774476FB377F84FF6F23132D20AADFED230A976BB8D514AA2513250A5B8594B854EAA5E130E5E36E834B9AFF798D515A7B782D1B5E6B2BC6DC6B9D57182166566211A2DA2F9D22F20C695C9073EAC81D403818F99C13B6F55A053FD4CD961C8DBE760E990D70F688F7793E1AEC4E42417140B44E7A2535EE11C5E884703D5E7C50A407EB512B3051CE426C85E3B445543830966862D9DF1626190E0130A22A30E17CA967C329E2A67CFB68010D047051DFC2C45811C026CFC0BF6ACEDA14A08C313B7361EF8665351BF251DF1A27F3E0D8074321C472FEB9F26104CD0A5C941734E1B2EE2385AEB526A0B097B2A1BA4E63ABBD0E839DED2FA1CA97354B09D414165795A17F671E5B6E510044790F0A0ABD25592E67C735BE78CD658360063FC938E5F819E1A72C06DC6B796CBDD354
3588
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3588
osc.exe.bin.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{630A120C-71D9-63FC-FAEE-E5AF06129BD1}
cd77f991
011BEBA0EB05000100000040000000400000007BB9C2697CDFE3F6BD2FC126F58AA85BBB86729C7E8BCF304C9A95A31F3294430C5DD84284A6C6FE0FCC9E979C607958EDD3153CB1A0BCEDE99134A1EEE2317A5E2275ADF8DD2E80BBE0367DA541B36F
3588
osc.exe.bin.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{630A120C-71D9-63FC-FAEE-E5AF06129BD1}
83bc18d2
01FC9938D90500010000001C0000001C000000C1B185AA42E56F1A3F4DAF4CDFB36090DD94A23FF83432F5EF9DD522C6F14B2CBEDC57F9E55483BF4B84D05F
3588
osc.exe.bin.tmp
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{630A120C-71D9-63FC-FAEE-E5AF06129BD1}
4020
unins000.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp
2892
_iu14D2N.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-92EE-193A-D785-47D53FBD1B51}
cd77f991
01CF98301305000100000040000000400000002F96432134E4C6EE9A6D735CCBF1998150509EA8313703F2FEB75EA983F8E7F3063D2F4D04BD35F16A3EB8F185849F7679945B76DB8BCB50F8D73470088481D1134F26F24A61810E1E6D412159D4EEA4
2892
_iu14D2N.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{78664050-9AB2-1511-99CB-3090D8884CE4}
f6057a2d
01DF4E820F05030100000097010000690200005182487AAA2A57AC391E4219FFBA9F014D395A4CDF5B93ABC9471110CAA72DB6ABE168195CAE0E828E80D6E41668DEC32909B8AD0299B967B2C3843681B5EC190079ED4AA571A37AF8DDA3FC54BA724D719779E2D7B0B49EFA2C92AF84F2DB188DC67B473D1D0DC3F2E0F3339F95383E3277EEF0FD96A4EB44CA419809B37762C40627CF91D6C85353D64B52182651767D74A08E868062CA594B945A6694190843F28F1044779B70C4B7BDBC4BF1C416905BAD6B42B4F3378A5D48945125A257BF829759D4A0803D78C5E84858F5074098D9AEC8BE6D216E98137B87D85A5AFBE1BF17F84AA200A755E2867AA4E09846C856A13F1B0389168DBAF4C14A2B53A364A2A40FF977653D9EBC50BE15A3B52DDFF3DD39B8FF1D7EC38872B658FA1C863278623C2027DD182B527A97E489A6A7982D9B3D1DAB448A11E0A3FE18E71171E387DE1B5924F03B1420FD9FE97D52C866F6D38DEEA18D41B749FF282A1A2C3521AAB9058C2004B06420EF5423D71C25B529741B034FEDC9FCA89580D7EEC1B258E2587B6BC0892A9D7D184211B5ACF00B94E183EDE2C9E89CDDB8C9C117CB994CE4672E542BFC
2312
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-2B74-063D-5B11-194B70507868}
cd77f991
01C5DE654105000100000040000000400000004C82F290AF92BCD804C70DA679604D209DCD724897854BC3B1FA5339F4FC6C4C22B72B3D3268629314E6F4C6420FAB49ACB15D0CA506D240FF6C50F7DE1E9D192C4E10D7127DE2DFE6EE3D09CEC8A4F3
2312
OneSystemCare.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-2B74-063D-5B11-194B70507868}
2312
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C332E1D-2B74-063D-5B11-194B70507868}
cd77f991
01D4FAB0120500010000004000000040000000E9317B51133743F9B338F41863FB7C0E24DD2EAA830A0CB6F7CE270C4833ABE72ED7E9354283367F37C3B1CF99E432DB857CAFF52EB5480777A4C1A5E79A3F8A9D56A97B0B11609877672CC0BEE9B5FE
2312
OneSystemCare.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2A270B89-64F5-8783-44CC-B216216394BC}
f6057a2d
0128DF480E050301000000C40100007C0200006424928C0DACC9A8C0BDCC702208128262ABD56A6C19099AEFC6452C2EA9EAABC688CA15F4D3A03973FC5B35A030C4423B4AEDDF5DAA344B9395A187A368982163920C0461FDA7FFE2AAF571E1004F1BCCB8470C36D6B6A3FD7791DEE5E26D200D22408B27A157430CB7BF8581B29249FF3C6684FA0C34B9ADEAECA4F6FF122CE7E55B9B553D0287C01BF5C2C3E30399958A8A22CCF72948F44459CFDF04A35B0DCE44477F3D5B4F896218498804BAC57112DE55C03529F2E876D85B4CA7B4AA3EA31CAB6C384BBB8719FEA32C33CC28E9858AA93D44EDA1E8FB3C5C2EC4313BFE9344390EB702A85C944C5D1A2696C49886507828008ABE1796DDE46DD7A91DA6E2ED3ED4F38BDEACEBC6549B8275B96988E15D79896D5A7FE5607B8840F00B8197F6161117B6F44F1DAE47C1AD74A6B6BA93B0704952A3E3082DC3F59F717B8F3866DBFB371DAB0211ABE66287F2C114DEED25A1423F2F6BB93FDB607523D7E26C1EAF6E4B3232A0700A6F1D46F471C3C06D677CD54D0DFCD886EB667E49341990893E317FBBAE104750DE966F5C3D4B1E93A8BFA2DCA128888ADEADF9B631A414EE34A6549DB05A1E32D868BE68B3255E28723A9C84D0991A9586340CC0CA860F7A160816476A801A1E852B0817E54C8A9C5E
2336
OneSystemCare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2336
OneSystemCare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1

Files activity

Executable files
13
Suspicious files
1
Text files
16
Unknown types
3

Dropped files

PID
Process
Filename
Type
3916
osc.exe.bin.exe
C:\Users\admin\AppData\Local\Temp\is-MURBB.tmp\osc.exe.bin.tmp
executable
MD5: 2df05c426df5d9594fd10eb490f178ad
SHA256: 133f4f998374bbbe3b12b49daf39840095bd703cd67cec7d5cb4b8175df1e757
4020
unins000.exe
C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp
executable
MD5: e9781eebe464ba77596f49cd93d80cc9
SHA256: f13f492348e375138841184dbcef2f61b9bffe9ae9c784a48e94e6f9f1eea294
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Local\Temp\is-MUCC4.tmp\ykgg.dll
executable
MD5: 8113737df29a93652cd47d4f725dd6b0
SHA256: 6402300f6c715ead4c711133d2d5f22757202c83c2cc7fffa2c1064580e74d99
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Local\Temp\is-MUCC4.tmp\_isetup\_iscrypt.dll
executable
MD5: a69559718ab506675e907fe49deb71e9
SHA256: 2f6294f9aa09f59a574b5dcd33be54e16b39377984f3d5658cda44950fa0f8fc
3588
osc.exe.bin.tmp
C:\Program Files\OneSystemCare\ykgg.dll
executable
MD5: 8113737df29a93652cd47d4f725dd6b0
SHA256: 6402300f6c715ead4c711133d2d5f22757202c83c2cc7fffa2c1064580e74d99
3084
osc.exe.bin.tmp
C:\Users\admin\AppData\Local\Temp\is-T7IBR.tmp\ykgg.dll
executable
MD5: 8113737df29a93652cd47d4f725dd6b0
SHA256: 6402300f6c715ead4c711133d2d5f22757202c83c2cc7fffa2c1064580e74d99
3084
osc.exe.bin.tmp
C:\Users\admin\AppData\Local\Temp\is-T7IBR.tmp\_isetup\_iscrypt.dll
executable
MD5: a69559718ab506675e907fe49deb71e9
SHA256: 2f6294f9aa09f59a574b5dcd33be54e16b39377984f3d5658cda44950fa0f8fc
2892
_iu14D2N.tmp
C:\Users\admin\AppData\Local\Temp\is-H0OI5.tmp\ykgg.dll
executable
MD5: 8113737df29a93652cd47d4f725dd6b0
SHA256: 6402300f6c715ead4c711133d2d5f22757202c83c2cc7fffa2c1064580e74d99
2412
osc.exe.bin.exe
C:\Users\admin\AppData\Local\Temp\is-SMISJ.tmp\osc.exe.bin.tmp
executable
MD5: 2df05c426df5d9594fd10eb490f178ad
SHA256: 133f4f998374bbbe3b12b49daf39840095bd703cd67cec7d5cb4b8175df1e757
3588
osc.exe.bin.tmp
C:\Program Files\OneSystemCare\unins000.exe
executable
MD5: e9781eebe464ba77596f49cd93d80cc9
SHA256: f13f492348e375138841184dbcef2f61b9bffe9ae9c784a48e94e6f9f1eea294
3588
osc.exe.bin.tmp
C:\Program Files\OneSystemCare\OneSystemCare.exe
executable
MD5: d79a74a22fd03e3f83cdeb78c0ac0365
SHA256: 93031ffadb6d619724b1ac4d1b19ccd6ead3ff66bd6bb43f31d5ed8bc3e879cb
3588
osc.exe.bin.tmp
C:\Program Files\OneSystemCare\CleanupConsole.exe
executable
MD5: 0d4ef62b38a9ff7c870361fb13a3bf58
SHA256: 3f6f8263ca92c9af4f7fbef9fa8492e678723aa98d93d42fcc08084feec99e9b
2988
osc.exe.bin.exe
C:\Users\admin\AppData\Local\Temp\is-KNGKV.tmp\osc.exe.bin.tmp
executable
MD5: 2df05c426df5d9594fd10eb490f178ad
SHA256: 133f4f998374bbbe3b12b49daf39840095bd703cd67cec7d5cb4b8175df1e757
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-6AHD7.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-T4CPL.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\Italian.json
text
MD5: fa9a1adba0e225de2b67b3e9d4044431
SHA256: a36175fb0461f99c3756e5ec1ea567bdc0f076d889b5b88bd3f2584740b4f411
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\Norwegian.json
text
MD5: 56ba0df225e394736a9a1d1ebfa1e875
SHA256: 88a85b7699ccb357206199c63934f9e1c447ca3ba2c99ffd6df3e784a05d5487
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\German.json
text
MD5: 57a21723826cb6011fd757cfb4d20be0
SHA256: b98668bac92fa953eff61acbb1521dbe9cead3dd012643dd4405f51c10fa250e
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\Parameters.json
text
MD5: edf16921760f499b89226e8a7f9e42dc
SHA256: e1cadab805a5b25c6a6b3d332278412034290c9a8991e089c25c08243ef73915
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-8TNF6.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-B4VEB.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-BAAR7.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\French.json
text
MD5: 32d66dde3d1503daa95a13c5d5d91a6b
SHA256: 81cda2f471956170453322af033955efcfa0bdcaee0ef4e0d4c33db4fa790b6e
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\EnglishPC.json
text
MD5: 301aae525b1b00130e5ff774f20f4efd
SHA256: 3d79643b0364e95a5d2c23414f22d9621f7d4d9abbd0b674f5328d5dd9be5d69
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\English.json
text
MD5: 73628eeb89155df245626ed656035b5a
SHA256: 1cba9726d30faaf69c4a79b0323d422513fb9b107e288d57d23e1562b62ce41b
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-S6NNF.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-3R17B.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-AHTPC.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-NB0QR.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\Dutch.json
text
MD5: 5a7c6d05b752b411be853daaaadb292f
SHA256: d10f63477a7bffd6fc7f68374b5cc240680030177c74ec2f9de6e3ba7041cc23
1148
OneSystemCare.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 893a02f1d5d1e7d5567e0b52e7a1ca84
SHA256: ebc08c476d10cab7e131fa59d02649a901460b405d275995222a4ba888e7dd52
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\Danish.json
text
MD5: ab67c5b4515279386df2e257adab9bf2
SHA256: ca0ae38b726b75d6b79f740904a3478eb7c081f0ae09dcec9e1a115606db5ce7
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-LIU07.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-CD88P.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Program Files\OneSystemCare\is-8B8KI.tmp
––
MD5:  ––
SHA256:  ––
1148
OneSystemCare.exe
C:\Windows\Tasks\One System CarePeriod.job
binary
MD5: 464ce3a6790415bde6a3cf686ea42671
SHA256: 16b51b5897aed5b7747618ccc37ef64c13e8a0ff4e13941f0c322ab154ac2c9c
3588
osc.exe.bin.tmp
C:\Program Files\OneSystemCare\is-44N79.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\Program Files\OneSystemCare\unins000.dat
dat
MD5: 0e463588789b6c08274ed544f02a236d
SHA256: 015ed8029dfcf4e917bec824cbedefdf882361453e8d57315fe5389f1bf423a2
3588
osc.exe.bin.tmp
C:\Program Files\OneSystemCare\is-0H3VS.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care\Launch One System Care.lnk
lnk
MD5: 30db9b337e679aadeffabca34451f193
SHA256: 7bbf24574200ec040d937c3914cb4df43cf35f4400e021b2a84738b68cffc82a
3588
osc.exe.bin.tmp
C:\Program Files\OneSystemCare\is-MSJN1.tmp
––
MD5:  ––
SHA256:  ––
3588
osc.exe.bin.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care\One System Care on the Web.url
text
MD5: 00fdfb5d7526e8e14d08c7f66ef937dc
SHA256: 0c44d6769d3da333faa1b58d36a0c51c93bf0832a7c79389ee29229afff9524a
3588
osc.exe.bin.tmp
C:\Users\admin\Desktop\Launch One System Care.lnk
lnk
MD5: 52ccf52e96669970812cabff58d3543f
SHA256: 3c66f95e4a022ca16c199d8e76ad32c8e7ba23979c44e28e017b55ad3e6e6323
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\Portuguese.json
text
MD5: b3607edd4820386834cff282cb8add70
SHA256: 6524c9b92bf00803cf208323eaf8322c5362e4683057def06bdcc35c5825cbd3
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\Spanish.json
text
MD5: a8be72105f359dd716f980397d126f32
SHA256: e2a6d4d79c09a97f467299db0f9da96ad372fe515958c31d8d17cde98a27ac40
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\Swedish.json
text
MD5: 2c1a0a6ad97feef8386cf0e630a521c4
SHA256: 4a0ab9cccfedc8fe329b848afc21542eeaebdec7566f896e12b27e18cb569208
3588
osc.exe.bin.tmp
C:\Users\admin\AppData\Roaming\One System Care\Languages\is-M8IB7.tmp
––
MD5:  ––
SHA256:  ––
1148
OneSystemCare.exe
C:\Users\admin\AppData\Roaming\One System Care\Languages\tmpLang.json
text
MD5: 76ca06abcd5b5c252bd10fe465993e83
SHA256: 3d997792150da91ac71f443d3f384eead455ab017d7622f0b18e3a6d344fe75a

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
10
TCP/UDP connections
9
DNS requests
8
Threats
6

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3084 osc.exe.bin.tmp POST 200 104.31.92.189:80 http://tm1.onesystemhost.info/ US
text
text
malicious
3588 osc.exe.bin.tmp POST 200 104.31.92.189:80 http://tm1.onesystemhost.info/ US
text
text
malicious
3588 osc.exe.bin.tmp POST 200 104.31.92.189:80 http://ins1.onesystemhost.info/ US
text
text
malicious
3588 osc.exe.bin.tmp POST 200 104.31.93.189:80 http://ins2.onesystemhost.info/ US
text
text
malicious
–– –– HEAD 503 81.171.17.144:80 http://credicalls.info/?ch=oyBXnDLFm1pI_L0YIJ_5mC65YsU5rnCQh8nJ535cAqLm1i_lNtUn2FzMXnRtS3kRx7pG7tAP5D07bSob4I1xN36KNBRWdQvraDYMEyfdSsoBeZgqBEuzPLVIK9JOB9Gsdx5HKhAxeNrn&ac=E96YRresO_rWfbA_hjHKDLFQ6veEZK1_Q3Sa9Tn_e0hXL12ouGkiTO0FYvI6HeSqOF2ux066ATOm2Oj355mhvQWZkpjQcQYJN4Xp9NCGM1ecr6ct8G8RJJZ9LB64zbcJ-R_R-rfoh2XWyByrJfZpbQcTQJBKW3NG8AfzR4MIqk8llr8Sc0wGJIwDQKSgZPSN_0Dp_vbWkaL-53isUGJQii-7nCEgUZEnv4j3EDbFWmReElSkUz1FYUD-pfSOow-EJys_fWQ3uHsEv7c80x3MllHSUxq6pJe6aVdgkQpgzP9DEzvjOM8-L0EXJewtnvvR41_CZz8UiXJrIoJUp80g6gXvDfEyzXD3AV3byJPe2s6yNLGJ8-EcwhL7Gb1fnvHBT3QXSSPNP-DlnDGoO_gj9b5nup9hTvXLuzWUEHLmQUq54fEJkzWm5AgnNwCGxeLItXjE2BpRKHUcfZlGyOKOiaizBgKGLmBR0Ic1KCx2ncXEZOiFu13AF8uXZhC1mnoLHHgzE0eEQYgD_mGry1ogW1w-yU9_jZKe44diKRbvHfd_MgdVAXser3M4mAXxC0pavPrdEkxsgz8IpQWET-4Q508Vsfz6cSwwFuC18CI3HsNyk_KnV8YzBl-RgmhegsCB_Pwe-jwThQvhNHyYjLBeevcJn7x_1GvR-Bv1PZZ40fdSiej145YMcrQeHrzrr7WOnKrOc0itiG-KDlorLPQvjD5ydnQRG0k17Wv1acxK2u0unWFOpPlMp8iPdcNqe4gTMUQ-D0loXR_eyay6pzSu1ogkzk3dwruTMxtuLp1jM6HSYK7_nP7xox6ByMzlv7Z-hP9pLrCcmH0FEwDukmg4nLUqnwWhCARM6Vau7etM1RDLSEhwpZ9h0aRUVq7WVoUsbhtIc-KTJhVo53LJ7H7wEUMXOfVCMfrHG6GbEemDVVvNlU2_NqDCFuXl3ACNSRGQuL-bAjK58l7PhHfCuXh7JoUEqF_EE0D2j0wcfFQZpd93rIhI2K8v3LWrCEq7o-508AIvTG1oAmj31OMEghYLe0CgU96GwNJZgMkFCZ-raCREdKJqDpwv32HyUEKinMsuUrYTlGFfx7x87gu7x1Hai2cJ0RoCNs2XFZJQddgPKPZt&tr=HNR2CKIdImTecJ6ppLue47tZW_5loY4Ykn1okMIFthgdHTZvypq6zhvVwdkbd5b9W0gESrP4e91dch1RXCr6qz_FnMFf684-0J54It3dYM2rrO0oL-9xDC1pC2Y0yYNyocPE2S0vyoV2ckyKrGA7iW-jixwApsuIldSZoAUWGv5UJVLjQR-7Y6QpmNzMbKjGo4Hw_8tKvZ9G94WlNJ7iw-jnt7RaQu1YoJOESH3M5siyDAaiHIvJvWHeZR5eg1wVRc0y62aPbEDsnbNwsxytbyUw_hMTHw8Ygot_6fN_rmX3u-b3Ka031RLtXD0xGpR0G7MX8Vh595M37gFrQYoI NL
––
––
malicious
–– –– HEAD 503 81.171.17.144:80 http://areasons.info/?ch=sQQV5K9n9lFkcA0Q-KWdDB5B6W9YUXwWhQbUIB7nN3vHV_dnZsAn_PaLu7KnzJRobu7uFxr-H4FKJ0Wcf-LeBf95XixQ_nTkh7mimKqi5KV6B7A-lb8M3NJZu7Kn7CIqKOn3goXsmZ_L&ac=StPAahsWcy4XtV7vHHcfPfyYgiohk6o1yeJbh6qCU-3NZJtCEWcRqHWX_GnhFybmeTA-RlvOrYRddK4obV2E71DtkiaXOQzE6aseh6Cb47xObU3FFLHmtH1auEghT9iu1c09U9_H4Lnk0uBrshLc8nCz37wxBexx6KRCXtnV46Fw8YUPZ3LjaqIglTHPpFgx_n5hdCc1rIfHAJ5pI0W8lVt4o4gRPo-z0pcIVjcqmo5ZxhZH6G8chci4SJjcI7NYwaefZxRxK3oSu04LNI17sPnL_DvBsp9MC-ZQENQEGo_7gmZdEoV_zjeebNCKVlGGYe1kFqcbr6SAOpDF6HPAJO83oL4zUaK5cNIUgJ17IcQRpEoO3qBSdoHKa4zmaVDKa7u778olu2hMeyx-bgJYVuh2E4Xv-MfHdHph7vojVKwRp3U6nXen_MDWQ172SAOiPOeIGKel2GyvjMUmYx5TKomoCwW8ylkvxSczgbaXKsingP3TEzZNOHb5KEAHuNXH467tMMSW-jT6amMRjno8XuBN69eiX7grSl8Wcy35eYk9mwgCdX5FXRqv4uxKpA5ryrvajSvV77miHf0GQGH9Y0ZTSIwyxJwtpMR4_02g5_dxvipyu9cBwoEQInpMKmj3DCF1_jY3_E2o1zz6qR9xL1BLFxbiTTo9WVlxdGkHoVKEPPnX3We5CLl2izPIi7t1brnvThXdf26zHExWfYiZPMtF812cJGMblvA0O5M4LS4Nwn5441HIhBjuA1SUkFimJSyV0hn7RNS1QQuLImD2P9g4lqFpo8UVvhdH9Ia1DbK4Leod7QbS9r7AYzVA92nhWBM2GHr_E3mhjOsUgiDNdPVVkG-BTTn4_GgEU6rZBvILBMqVleTSaYWOM2YRuRkun3qc-JPQePg9RPxdmDWLtaaKwN5kBlhEP5CURfsGgJIkcDPMGRnVDaDrSQzlqt6l_j310JnpO56GafvHdhU4vKTz3KMyzB5GW2yOQEpVqb7OfW063qVD7ui5uwXLEz5UpgaDwtDPpcfdHZhoteH1QFq7iJcHKR9n3q0Cpm1SSYgCQngRUCixf-IvFajl622GCdSGqb-AJO2hoPjTtXtnE2uA9ttzfBeR57WcYCLcm5fr&tr=sDOBxOtnnRlkffje4QomsRfNBFzKrzlObZrrNn5t3Gg-DL09Lq5l977_S313t7F-wN3ZL3YOBzm4CEQFrfXlFPPrrKnoPRldD9oKGkBXrO4ewSlJ47SYwIu_2k0DHNiOOqD4CNuKBx68FoamJz66htYw-IVXf14ZTohPkFgHLiwzkBsymtCTPmZkT151SfOOe-Cmy-RKrhI010SGervJudih-cyvx6D5j50wGW746kQcMmjtZRbsAlYpnytNL1OjpW3qt6S7XjWY_xO_yQlgddkxPBtvZVN8aFDG9JUKmC17YmpBE8EiQZ9D6iQ5-j0vlvcBLSiTPG18XnKTmZ_L NL
––
––
malicious
3588 osc.exe.bin.tmp POST 200 104.31.92.189:80 http://inf1.onesystemhost.info/ US
text
text
malicious
1148 OneSystemCare.exe POST 200 104.31.93.189:80 http://act1.onesystemhost.info/ US
text
text
malicious
1148 OneSystemCare.exe GET 200 104.31.4.172:80 http://callbanner.onesystemcare.com/?type=43 US
––
––
shared
1148 OneSystemCare.exe GET 200 104.31.4.172:80 http://callbanner.onesystemcare.com/?type=44 US
––
––
shared

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3084 osc.exe.bin.tmp 104.31.92.189:80 Cloudflare Inc US shared
3588 osc.exe.bin.tmp 104.31.92.189:80 Cloudflare Inc US shared
3588 osc.exe.bin.tmp 104.31.93.189:80 Cloudflare Inc US suspicious
–– –– 81.171.17.144:80 LeaseWeb Netherlands B.V. NL malicious
1148 OneSystemCare.exe 104.31.93.189:80 Cloudflare Inc US suspicious
1148 OneSystemCare.exe 104.31.4.172:80 Cloudflare Inc US shared

DNS requests

Domain IP Reputation
tm1.onesystemhost.info 104.31.92.189
104.31.93.189
malicious
ins1.onesystemhost.info 104.31.92.189
104.31.93.189
malicious
ins2.onesystemhost.info 104.31.93.189
104.31.92.189
malicious
credicalls.info 81.171.17.144
unknown
areasons.info 81.171.17.144
unknown
inf1.onesystemhost.info 104.31.92.189
104.31.93.189
malicious
act1.onesystemhost.info 104.31.93.189
104.31.92.189
malicious
callbanner.onesystemcare.com 104.31.4.172
104.31.5.172
unknown

Threats

No threats detected.

Debug output strings

No debug info.