General Info Watch the FULL Interactive Analysis at ANY.RUN!

File name

aupcsetup.exe

Verdict
Malicious activity
Analysis date
1/11/2019, 07:15:06
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

14ac36de703127411d27dbf7b4de5d2f

SHA1

fed3df6843ed1f189c8c789736be0cc1a414dd07

SHA256

e0b157bf9ce29f6cfc26834c69814db7a11fb1fa1b882c42ff70db241a8509f5

SSDEEP

196608:FA3058p032WZbzSbHft8WNc50F6tDdOt1uLTAtHRu5OuIdroeSJG:Fe0K0328zWHl8WNc500ct1gTAtIHGU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • iytr.exe (PID: 3924)
Application was dropped or rewritten from another process
  • iytr.exe (PID: 2196)
  • iytr.exe (PID: 3700)
  • iytr.exe (PID: 3924)
Loads the Task Scheduler COM API
  • iytr.exe (PID: 3924)
Creates files in the user directory
  • iytr.exe (PID: 3924)
Reads the Windows organization settings
  • aupcsetup.tmp (PID: 2432)
Uses TASKKILL.EXE to kill process
  • aupcsetup.tmp (PID: 2432)
Reads Windows owner or organization settings
  • aupcsetup.tmp (PID: 2432)
Executable content was dropped or overwritten
  • aupcsetup.tmp (PID: 2432)
  • aupcsetup.exe (PID: 4076)
  • aupcsetup.exe (PID: 3812)
Creates files in the program directory
  • aupcsetup.tmp (PID: 2432)
Application was crashed
  • iytr.exe (PID: 2196)
Loads dropped or rewritten executable
  • aupcsetup.tmp (PID: 2432)
Creates a software uninstall entry
  • aupcsetup.tmp (PID: 2432)
Application was dropped or rewritten from another process
  • aupcsetup.tmp (PID: 2432)
  • aupcsetup.tmp (PID: 2468)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable Delphi generic (57.2%)
.exe
|   Win32 Executable (generic) (18.2%)
.exe
|   Win16/32 Executable Delphi generic (8.3%)
.exe
|   Generic Win/DOS Executable (8%)
.exe
|   DOS Executable Generic (8%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:01:15 09:22:50+01:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
65024
InitializedDataSize:
104448
UninitializedDataSize:
null
EntryPoint:
0x113bc
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
3.0.0.94
ProductVersionNumber:
3.0.0.94
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
FileDescription:
Auto~PC -Care Setup
FileVersion:
3.0.0.94
LegalCopyright:
ProductName:
Auto~PC -Care
ProductVersion:
3.0.0.94
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
15-Jan-2016 08:22:50
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
null
FileDescription:
Auto~PC -Care Setup
FileVersion:
3.0.0.94
LegalCopyright:
null
ProductName:
Auto~PC -Care
ProductVersion:
3.0.0.94
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
15-Jan-2016 08:22:50
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F134 0x0000F200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.39169
.itext 0x00011000 0x00000B44 0x00000C00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.74305
.data 0x00012000 0x00000C88 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.24753
.bss 0x00013000 0x000056B8 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000DD0 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.97188
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x000179C8 0x00017A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.1072
Resources
1

2

3

4

5

6

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
45
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

+
drop and start start drop and start drop and start drop and start aupcsetup.exe aupcsetup.tmp no specs aupcsetup.exe aupcsetup.tmp taskkill.exe no specs iytr.exe iytr.exe iytr.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3812
CMD
"C:\Users\admin\AppData\Local\Temp\aupcsetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\aupcsetup.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Auto~PC -Care Setup
Version
3.0.0.94
Modules
Image
c:\users\admin\appdata\local\temp\aupcsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-7rfpl.tmp\aupcsetup.tmp

PID
2468
CMD
"C:\Users\admin\AppData\Local\Temp\is-7RFPL.tmp\aupcsetup.tmp" /SL5="$30190,7263879,170496,C:\Users\admin\AppData\Local\Temp\aupcsetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-7RFPL.tmp\aupcsetup.tmp
Indicators
No indicators
Parent process
aupcsetup.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-7rfpl.tmp\aupcsetup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll

PID
4076
CMD
"C:\Users\admin\AppData\Local\Temp\aupcsetup.exe" /SPAWNWND=$3019A /NOTIFYWND=$30190
Path
C:\Users\admin\AppData\Local\Temp\aupcsetup.exe
Indicators
Parent process
aupcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Auto~PC -Care Setup
Version
3.0.0.94
Modules
Image
c:\users\admin\appdata\local\temp\aupcsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-ttfj0.tmp\aupcsetup.tmp

PID
2432
CMD
"C:\Users\admin\AppData\Local\Temp\is-TTFJ0.tmp\aupcsetup.tmp" /SL5="$40192,7263879,170496,C:\Users\admin\AppData\Local\Temp\aupcsetup.exe" /SPAWNWND=$3019A /NOTIFYWND=$30190
Path
C:\Users\admin\AppData\Local\Temp\is-TTFJ0.tmp\aupcsetup.tmp
Indicators
Parent process
aupcsetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-ttfj0.tmp\aupcsetup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\profapi.dll
c:\users\admin\appdata\local\temp\is-gqb1c.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\is-gqb1c.tmp\_isetup\_iscrypt.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\auto~pc -care for user-pc\iytr.exe
c:\program files\auto~pc -care for user-pc\unins000.exe
c:\windows\system32\netutils.dll

PID
3620
CMD
"C:\Windows\System32\taskkill.exe" /f /im "iytr.exe"
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
aupcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
3924
CMD
"C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe" getwebparam
Path
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
Indicators
Parent process
aupcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Description
System Cleaner Tool
Version
3.0.0.94
Modules
Image
c:\program files\auto~pc -care for user-pc\iytr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.drawing\dbfe8642a8ed7b2b103ad28e0c96418a\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.windows.forms\3afcd5168c7a6cb02eab99d7fd71e102\system.windows.forms.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\gac_msil\system.windows.forms\2.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\shfolder.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\auto~pc -care for user-pc\microsoft.win32.taskscheduler.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sxs.dll
c:\windows\system32\windowscodecs.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data.dataset#\eae18653a1b39fe484b49963d43480ce\system.data.datasetextensions.ni.dll
c:\program files\auto~pc -care for user-pc\system.data.sqlite.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.transactions\ad18f93fc713db2c4b29b25116c13bd8\system.transactions.ni.dll
c:\windows\assembly\gac_32\system.transactions\2.0.0.0__b77a5c561934e089\system.transactions.dll
c:\program files\auto~pc -care for user-pc\x86\sqlite.interop.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.serviceproce#\20008c75bb41e2febf84d4d4aea5b4e8\system.serviceprocess.ni.dll
c:\program files\auto~pc -care for user-pc\paddlecheckoutsdk.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.servicemodel\e2642bff810609f64343e53dddb6b59c\system.servicemodel.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.runtime.seri#\4a984a9ad59d14063bc6ae64a0c8f62a\system.runtime.serialization.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\diasymreader.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.enterprisese#\887ef2648686aad19feff405eddbffd2\system.enterpriseservices.ni.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\custommarshalers\bf7e7494e75e32979c7824a07570a8a9\custommarshalers.ni.dll
c:\windows\assembly\gac_32\custommarshalers\2.0.0.0__b03f5f7f11d50a3a\custommarshalers.dll
c:\windows\system32\xmllite.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.web\da5da08245467818759aa44c4eb948e1\system.web.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.web.abstract#\3112fe15b1994ff59b169cf7ce997e71\system.web.abstractions.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.web.extensio#\70823ac0d6e6631a11d443bf38987cc9\system.web.extensions.ni.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\normaliz.dll

PID
2196
CMD
"C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe" firstshow
Path
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
Indicators
Parent process
aupcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
3228369022
Version:
Company
Description
System Cleaner Tool
Version
3.0.0.94
Modules
Image
c:\program files\auto~pc -care for user-pc\iytr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3700
CMD
"C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe"
Path
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
System Cleaner Tool
Version
3.0.0.94
Modules
Image
c:\program files\auto~pc -care for user-pc\iytr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

Registry activity

Total events
757
Read events
615
Write events
141
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
800900002A063C0875A9D401
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
309617B4DFADD4337749E203A5C88D788747E893F190201C1FB338132DC35577
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
20D1D2CB8F3F87DB3236D1512918214549AF38D38C604AB7B8250EEA577F1E39
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO
(855)-332-0124
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
ISTELNO
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
apst
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
isshowng
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
issilent
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
affired
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
showwfo
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
ovoffdis
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
playsound
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
wfoset
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
country
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
ipaddrurl
http://www.trkinstl.com/getip/
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
prereg
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
showtn
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
cbkpoff
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
cta
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
showunins
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
delaytime
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
isiunidu
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
isavst
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
isprmjsn
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
runcam
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
runsrc
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
runpixel
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
stdismax
4294967295
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
utm_medium
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
affiliateid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_source
msmsite
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_campaign
msmsite
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_medium
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
affiliateid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
pxl
msmsite
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-at
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-context
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_us
(855)-332-0124
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_uk
0800-031-5066
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_gb
0800-031-5066
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_au
(61)280-733403
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_fr
05 82 84 04 06
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_de
0800 1822 974
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_at
+43 (0)720 902 309
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_ch
+41 (0)44 508 70 37
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_lu
0800 1822 974
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_no
+47 21 95 01 97
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_dk
+45 78 73 09 26
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_nl
+31-08-58882839
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_be
+32-28085306
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_se
+46-08124-10298
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_ja
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_br
+55 21 2391 4319
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_it
+39 069 4802886
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_es
+34 951 203 537
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_ar
+54 11 5236 0324
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_fi
+358 (0)9 4270 4911
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_pt
+351 70 750 2094
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
pdtm
30
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
PurchaseURL
http://store.mypctool.xyz/aupc/price?
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
RenewURL
http://store.mypctool.xyz/aupc/renewal?
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
WebURL
http://www.mypctool.xyz/
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
EmailURL
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
supporturl
http://www.mypctool.xyz/help/
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC\3.0.0.94
Installstring
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
Installstring
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: Setup Version
5.5.8 (u)
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: App Path
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
InstallLocation
C:\Program Files\Auto~PC -Care for USER-PC\
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: Icon Group
Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: User
admin
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: Language
en
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
DisplayName
Auto~PC -Care
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
DisplayIcon
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
UninstallString
"C:\Program Files\Auto~PC -Care for USER-PC\unins000.exe"
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
QuietUninstallString
"C:\Program Files\Auto~PC -Care for USER-PC\unins000.exe" /SILENT
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
DisplayVersion
3.0.0.94
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
NoModify
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
NoRepair
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
InstallDate
20190111
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
MajorVersion
3
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
MinorVersion
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
EstimatedSize
18665
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
paramurl
http://trkr.trkinstl.com/ipfiles/
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
plurl
http://pp.trkinstl.com/ProductPrice.svc/
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
buybowinapp
http://store.mypctool.xyz/aupc/plan?
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
InstallString
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
InstallString
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
LangCode
en
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
LangCode
en
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_source
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_campaign
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
pxl
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_pubid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
LangCode
en
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-plt
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-var1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
lpid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
btnid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-var2
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-var3
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
referUrl
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
afterInstallUrl
http://ins.trkinstl.com/install/aupc/?
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
country
it
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
TELNO
2432
aupcsetup.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\QXV0b35QQyAtQ2FyZQ==\ACT
data
0001000000FFFFFFFF01000000000000000C020000003C697974722C2056657273696F6E3D332E302E302E39342C2043756C747572653D6E65757472616C2C205075626C69634B6579546F6B656E3D6E756C6C0501000000184153456E67696E652E426173652E52656744657461696C73120000000A5F5265675374617475730D5F4973526567697374657265640B5F497345787072697265640E5F44617973496E7374616C6C65640F5F44617973526567697374657265640E5F4461797352656D61696E696E671D3C5265676973746572446174653E6B5F5F4261636B696E674669656C641C3C496E7374616C6C446174653E6B5F5F4261636B696E674669656C64193C56616C69646974793E6B5F5F4261636B696E674669656C64243C4C61737456616C6964697479436865636B65643E6B5F5F4261636B696E674669656C641E3C41637469766174696F6E4B65793E6B5F5F4261636B696E674669656C64183C4B6579547970653E6B5F5F4261636B696E674669656C64223C4973416C726561647950757263686173653E6B5F5F4261636B696E674669656C641A3C55736572456D61696C3E6B5F5F4261636B696E674669656C64183C5A6970436F64653E6B5F5F4261636B696E674669656C641C3C436F756E7472794E616D653E6B5F5F4261636B696E674669656C641C3C436F756E747279436F64653E6B5F5F4261636B696E674669656C641D3C5075726368617365446174653E6B5F5F4261636B696E674669656C64040000000000000000030100000101010100174153456E67696E652E426173652E6552656753746174730200000001010808080D0D087153797374656D2E4E756C6C61626C6560315B5B53797374656D2E4461746554696D652C206D73636F726C69622C2056657273696F6E3D322E302E302E302C2043756C747572653D6E65757472616C2C205075626C69634B6579546F6B656E3D623737613563353631393334653038395D5D08010D0200000005FDFFFFFF174153456E67696E652E426173652E655265675374617473010000000776616C75655F5F0008020000000100000000000000000000000000000000000000000000000000F8D08A378C77D688000000000A0A00000000000A0A0A0A00000000000000000B
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
reg
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
expired
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
EnableFileTracing
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
EnableConsoleTracing
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
FileTracingMask
4294901760
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
ConsoleTracingMask
4294901760
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
MaxFileSize
1048576
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
FileDirectory
%windir%\tracing
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
EnableFileTracing
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
EnableConsoleTracing
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
FileTracingMask
4294901760
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
ConsoleTracingMask
4294901760
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
MaxFileSize
1048576
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
FileDirectory
%windir%\tracing
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
x-ccode
it
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO
+39 069 4802886
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
country
it
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
x-ip
85_203_20_17
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
x-datetime
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
x-fetch
0
3924
iytr.exe
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
x-ip
85_203_20_17
3924
iytr.exe
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
x-datetime
3924
iytr.exe
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
x-fetch
0

Files activity

Executable files
19
Suspicious files
2
Text files
24
Unknown types
6

Dropped files

PID Process Filename Type
3812 aupcsetup.exe C:\Users\admin\AppData\Local\Temp\is-7RFPL.tmp\aupcsetup.tmp executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\Microsoft.Win32.TaskScheduler.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\gmtrs.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\Newtonsoft.Json.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\unins000.exe executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\System.Data.SQLite.DLL executable
2432 aupcsetup.tmp C:\Users\admin\AppData\Local\Temp\is-GQB1C.tmp\_isetup\_shfoldr.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\HtmlRenderer.WinForms.dll executable
2432 aupcsetup.tmp C:\Users\admin\AppData\Local\Temp\is-GQB1C.tmp\_isetup\_iscrypt.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\PaddleCheckoutSDK.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\HtmlRenderer.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\x64\SQLite.Interop.dll executable
4076 aupcsetup.exe C:\Users\admin\AppData\Local\Temp\is-TTFJ0.tmp\aupcsetup.tmp executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\NAudio.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\Interop.SHDocVw.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\TAFactory.IconPack.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\Interop.IWshRuntimeLibrary.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\x86\SQLite.Interop.dll executable
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-MNEUE.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-STUGO.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-KN42L.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\german_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\japanese_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\italian_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\norwegian_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-VP070.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-8ADH4.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-7QRL0.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-HLRAK.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\langs.db binary
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\finish_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\French_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\english_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-E387S.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-3HP16.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-9A5SI.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-GVVCJ.tmp ––
2432 aupcsetup.tmp C:\ProgramData\Auto~PC -Care for USER-PC\pcspstartrepair_en.mp3 mp3
2432 aupcsetup.tmp C:\ProgramData\Auto~PC -Care for USER-PC\is-QV9GJ.tmp ––
2432 aupcsetup.tmp C:\ProgramData\Auto~PC -Care for USER-PC\mdb.db ––
2432 aupcsetup.tmp C:\ProgramData\Auto~PC -Care for USER-PC\is-6322K.tmp ––
3924 iytr.exe C:\Users\admin\AppData\Roaming\Auto~PC -Care For USER-PC\Errorlog.txt text
3924 iytr.exe C:\Users\admin\AppData\Roaming\Auto~PC -Care For USER-PC\Errorlog.txt text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-EF3G3.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-I9R2R.tmp ––
3924 iytr.exe C:\Users\admin\AppData\Roaming\Auto~PC -Care For USER-PC\Errorlog.txt text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-L9BQE.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\unins000.dat dat
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\x86\is-S45NJ.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\unins000.msg binary
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\x64\is-QR64S.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\application.ico image
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-IUBBJ.tmp ––
2432 aupcsetup.tmp C:\Users\Public\Desktop\Auto~PC -Care.lnk lnk
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-SHTNV.tmp ––
2432 aupcsetup.tmp C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto~PC -Care for USER-PC\Uninstall Auto~PC -Care.lnk lnk
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-IDRJN.tmp ––
2432 aupcsetup.tmp C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto~PC -Care for USER-PC\Buy Auto~PC -Care.lnk lnk
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-BMTHG.tmp ––
2432 aupcsetup.tmp C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto~PC -Care for USER-PC\Auto~PC -Care.lnk lnk
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-FUH94.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\danish_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-0RAMG.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\Dutch_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-KVNJ7.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-U0MM6.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-D75L7.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-5241L.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\portuguese_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-2RLN6.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe.config xml
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-MFOMB.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\spanish_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-JU337.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-D92VF.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\swedish_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-OD3FB.tmp ––
2432 aupcsetup.tmp C:\Users\admin\AppData\Local\Temp\is-GQB1C.tmp\setup_en.bmp image
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\russian_iss.ini text
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-9GQG2.tmp ––
2432 aupcsetup.tmp C:\Program Files\Auto~PC -Care for USER-PC\is-KDVK6.tmp ––
3924 iytr.exe C:\Users\admin\AppData\Roaming\Auto~PC -Care For USER-PC\Errorlog.txt text

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
3
DNS requests
3
Threats
1

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3924 iytr.exe GET 200 63.143.46.130:80 http://cc.trkinstl.com/productprice.svc/getcountrycode US
text
malicious
3924 iytr.exe GET 200 63.143.46.130:80 http://www.trkinstl.com/getip/ US
text
malicious
3924 iytr.exe GET 404 87.248.214.129:80 http://trkr.trkinstl.com/ipfiles/85_203_20_17.txt IT
––
––
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3924 iytr.exe 63.143.46.130:80 Limestone Networks, Inc. US malicious
3924 iytr.exe 87.248.214.129:80 Limelight Networks, Inc. IT suspicious

DNS requests

Domain IP Reputation
cc.trkinstl.com 63.143.46.130
malicious
www.trkinstl.com 63.143.46.130
malicious
trkr.trkinstl.com 87.248.214.129
87.248.214.1
malicious

Threats

PID Process Class Message
3924 iytr.exe A Network Trojan was detected SC ADWARE AdWare PUA:Win32/SpeedChecker / MSIL/GT32SupportGeeks

Debug output strings

Process Message
iytr.exe Native library pre-loader failed to get setting "SQLite_ForceLogPrepare" value: System.Xml.XmlException: Root element is missing. at System.Xml.XmlTextReaderImpl.Throw(Exception e) at System.Xml.XmlTextReaderImpl.ThrowWithoutLineInfo(String res) at System.Xml.XmlTextReaderImpl.ParseDocumentContent() at System.Xml.XmlTextReaderImpl.Read() at System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace) at System.Xml.XmlDocument.Load(XmlReader reader) at System.Xml.XmlDocument.Load(String filename) at System.Data.SQLite.UnsafeNativeMethods.GetSettingValue(String name, String default)
iytr.exe Native library pre-loader failed to get setting "SQLite_ForceLogPrepare" value: System.Xml.XmlException: Root element is missing. at System.Xml.XmlTextReaderImpl.Throw(Exception e) at System.Xml.XmlTextReaderImpl.ThrowWithoutLineInfo(String res) at System.Xml.XmlTextReaderImpl.ParseDocumentContent() at System.Xml.XmlTextReaderImpl.Read() at System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace) at System.Xml.XmlDocument.Load(XmlReader reader) at System.Xml.XmlDocument.Load(String filename) at System.Data.SQLite.UnsafeNativeMethods.GetSettingValue(String name, String default)