General Info

File name

aupcsetup.exe

Full analysis
https://app.any.run/tasks/288206e1-afba-43ff-a939-b96f4436811a
Verdict
Malicious activity
Analysis date
1/11/2019, 07:15:06
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

14ac36de703127411d27dbf7b4de5d2f

SHA1

fed3df6843ed1f189c8c789736be0cc1a414dd07

SHA256

e0b157bf9ce29f6cfc26834c69814db7a11fb1fa1b882c42ff70db241a8509f5

SSDEEP

196608:FA3058p032WZbzSbHft8WNc50F6tDdOt1uLTAtHRu5OuIdroeSJG:Fe0K0328zWHl8WNc500ct1gTAtIHGU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • iytr.exe (PID: 3700)
  • iytr.exe (PID: 3924)
  • iytr.exe (PID: 2196)
Loads dropped or rewritten executable
  • iytr.exe (PID: 3924)
Loads the Task Scheduler COM API
  • iytr.exe (PID: 3924)
Reads Windows owner or organization settings
  • aupcsetup.tmp (PID: 2432)
Creates files in the user directory
  • iytr.exe (PID: 3924)
Uses TASKKILL.EXE to kill process
  • aupcsetup.tmp (PID: 2432)
Executable content was dropped or overwritten
  • aupcsetup.exe (PID: 4076)
  • aupcsetup.tmp (PID: 2432)
  • aupcsetup.exe (PID: 3812)
Reads the Windows organization settings
  • aupcsetup.tmp (PID: 2432)
Application was crashed
  • iytr.exe (PID: 2196)
Loads dropped or rewritten executable
  • aupcsetup.tmp (PID: 2432)
Creates files in the program directory
  • aupcsetup.tmp (PID: 2432)
Creates a software uninstall entry
  • aupcsetup.tmp (PID: 2432)
Application was dropped or rewritten from another process
  • aupcsetup.tmp (PID: 2432)
  • aupcsetup.tmp (PID: 2468)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable Delphi generic (57.2%)
.exe
|   Win32 Executable (generic) (18.2%)
.exe
|   Win16/32 Executable Delphi generic (8.3%)
.exe
|   Generic Win/DOS Executable (8%)
.exe
|   DOS Executable Generic (8%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:01:15 09:22:50+01:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
65024
InitializedDataSize:
104448
UninitializedDataSize:
null
EntryPoint:
0x113bc
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
3.0.0.94
ProductVersionNumber:
3.0.0.94
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
FileDescription:
Auto~PC -Care Setup
FileVersion:
3.0.0.94
LegalCopyright:
ProductName:
Auto~PC -Care
ProductVersion:
3.0.0.94
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
15-Jan-2016 08:22:50
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
null
FileDescription:
Auto~PC -Care Setup
FileVersion:
3.0.0.94
LegalCopyright:
null
ProductName:
Auto~PC -Care
ProductVersion:
3.0.0.94
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
15-Jan-2016 08:22:50
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F134 0x0000F200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.39169
.itext 0x00011000 0x00000B44 0x00000C00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.74305
.data 0x00012000 0x00000C88 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.24753
.bss 0x00013000 0x000056B8 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000DD0 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.97188
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x000179C8 0x00017A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.1072
Resources
1

2

3

4

5

6

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
45
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

+
drop and start start drop and start drop and start drop and start aupcsetup.exe aupcsetup.tmp no specs aupcsetup.exe aupcsetup.tmp taskkill.exe no specs iytr.exe iytr.exe iytr.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3812
CMD
"C:\Users\admin\AppData\Local\Temp\aupcsetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\aupcsetup.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Auto~PC -Care Setup
Version
3.0.0.94
Modules
Image
c:\users\admin\appdata\local\temp\aupcsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-7rfpl.tmp\aupcsetup.tmp

PID
2468
CMD
"C:\Users\admin\AppData\Local\Temp\is-7RFPL.tmp\aupcsetup.tmp" /SL5="$30190,7263879,170496,C:\Users\admin\AppData\Local\Temp\aupcsetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-7RFPL.tmp\aupcsetup.tmp
Indicators
No indicators
Parent process
aupcsetup.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-7rfpl.tmp\aupcsetup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll

PID
4076
CMD
"C:\Users\admin\AppData\Local\Temp\aupcsetup.exe" /SPAWNWND=$3019A /NOTIFYWND=$30190
Path
C:\Users\admin\AppData\Local\Temp\aupcsetup.exe
Indicators
Parent process
aupcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Auto~PC -Care Setup
Version
3.0.0.94
Modules
Image
c:\users\admin\appdata\local\temp\aupcsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-ttfj0.tmp\aupcsetup.tmp

PID
2432
CMD
"C:\Users\admin\AppData\Local\Temp\is-TTFJ0.tmp\aupcsetup.tmp" /SL5="$40192,7263879,170496,C:\Users\admin\AppData\Local\Temp\aupcsetup.exe" /SPAWNWND=$3019A /NOTIFYWND=$30190
Path
C:\Users\admin\AppData\Local\Temp\is-TTFJ0.tmp\aupcsetup.tmp
Indicators
Parent process
aupcsetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-ttfj0.tmp\aupcsetup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\profapi.dll
c:\users\admin\appdata\local\temp\is-gqb1c.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\is-gqb1c.tmp\_isetup\_iscrypt.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\auto~pc -care for user-pc\iytr.exe
c:\program files\auto~pc -care for user-pc\unins000.exe
c:\windows\system32\netutils.dll

PID
3620
CMD
"C:\Windows\System32\taskkill.exe" /f /im "iytr.exe"
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
aupcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
3924
CMD
"C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe" getwebparam
Path
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
Indicators
Parent process
aupcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Description
System Cleaner Tool
Version
3.0.0.94
Modules
Image
c:\program files\auto~pc -care for user-pc\iytr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.drawing\dbfe8642a8ed7b2b103ad28e0c96418a\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.windows.forms\3afcd5168c7a6cb02eab99d7fd71e102\system.windows.forms.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\gac_msil\system.windows.forms\2.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\shfolder.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\auto~pc -care for user-pc\microsoft.win32.taskscheduler.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sxs.dll
c:\windows\system32\windowscodecs.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data.dataset#\eae18653a1b39fe484b49963d43480ce\system.data.datasetextensions.ni.dll
c:\program files\auto~pc -care for user-pc\system.data.sqlite.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.transactions\ad18f93fc713db2c4b29b25116c13bd8\system.transactions.ni.dll
c:\windows\assembly\gac_32\system.transactions\2.0.0.0__b77a5c561934e089\system.transactions.dll
c:\program files\auto~pc -care for user-pc\x86\sqlite.interop.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.serviceproce#\20008c75bb41e2febf84d4d4aea5b4e8\system.serviceprocess.ni.dll
c:\program files\auto~pc -care for user-pc\paddlecheckoutsdk.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.servicemodel\e2642bff810609f64343e53dddb6b59c\system.servicemodel.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.runtime.seri#\4a984a9ad59d14063bc6ae64a0c8f62a\system.runtime.serialization.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\diasymreader.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.enterprisese#\887ef2648686aad19feff405eddbffd2\system.enterpriseservices.ni.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\custommarshalers\bf7e7494e75e32979c7824a07570a8a9\custommarshalers.ni.dll
c:\windows\assembly\gac_32\custommarshalers\2.0.0.0__b03f5f7f11d50a3a\custommarshalers.dll
c:\windows\system32\xmllite.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.web\da5da08245467818759aa44c4eb948e1\system.web.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.web.abstract#\3112fe15b1994ff59b169cf7ce997e71\system.web.abstractions.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.web.extensio#\70823ac0d6e6631a11d443bf38987cc9\system.web.extensions.ni.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\normaliz.dll

PID
2196
CMD
"C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe" firstshow
Path
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
Indicators
Parent process
aupcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
3228369022
Version:
Company
Description
System Cleaner Tool
Version
3.0.0.94
Modules
Image
c:\program files\auto~pc -care for user-pc\iytr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3700
CMD
"C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe"
Path
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
System Cleaner Tool
Version
3.0.0.94
Modules
Image
c:\program files\auto~pc -care for user-pc\iytr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

Registry activity

Total events
757
Read events
615
Write events
141
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
800900002A063C0875A9D401
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
309617B4DFADD4337749E203A5C88D788747E893F190201C1FB338132DC35577
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
20D1D2CB8F3F87DB3236D1512918214549AF38D38C604AB7B8250EEA577F1E39
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO
(855)-332-0124
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
ISTELNO
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
apst
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
isshowng
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
issilent
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
affired
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
showwfo
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
ovoffdis
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
playsound
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
wfoset
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
country
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
ipaddrurl
http://www.trkinstl.com/getip/
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
prereg
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
showtn
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
cbkpoff
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
cta
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
showunins
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
delaytime
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
isiunidu
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
isavst
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
isprmjsn
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
runcam
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
runsrc
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
runpixel
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
stdismax
4294967295
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
utm_medium
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
affiliateid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_source
msmsite
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_campaign
msmsite
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_medium
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
affiliateid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
pxl
msmsite
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-at
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-context
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_us
(855)-332-0124
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_uk
0800-031-5066
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_gb
0800-031-5066
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_au
(61)280-733403
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_fr
05 82 84 04 06
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_de
0800 1822 974
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_at
+43 (0)720 902 309
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_ch
+41 (0)44 508 70 37
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_lu
0800 1822 974
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_no
+47 21 95 01 97
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_dk
+45 78 73 09 26
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_nl
+31-08-58882839
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_be
+32-28085306
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_se
+46-08124-10298
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_ja
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_br
+55 21 2391 4319
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_it
+39 069 4802886
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_es
+34 951 203 537
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_ar
+54 11 5236 0324
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_fi
+358 (0)9 4270 4911
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO_pt
+351 70 750 2094
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
pdtm
30
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
PurchaseURL
http://store.mypctool.xyz/aupc/price?
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
RenewURL
http://store.mypctool.xyz/aupc/renewal?
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
WebURL
http://www.mypctool.xyz/
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
EmailURL
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
supporturl
http://www.mypctool.xyz/help/
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC\3.0.0.94
Installstring
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
Installstring
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: Setup Version
5.5.8 (u)
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: App Path
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
InstallLocation
C:\Program Files\Auto~PC -Care for USER-PC\
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: Icon Group
Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: User
admin
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
Inno Setup: Language
en
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
DisplayName
Auto~PC -Care
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
DisplayIcon
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
UninstallString
"C:\Program Files\Auto~PC -Care for USER-PC\unins000.exe"
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
QuietUninstallString
"C:\Program Files\Auto~PC -Care for USER-PC\unins000.exe" /SILENT
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
DisplayVersion
3.0.0.94
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
NoModify
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
NoRepair
1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
InstallDate
20190111
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
MajorVersion
3
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
MinorVersion
0
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE5475FA-5F9F-41B2-B470-AC14D018BABF}_is1
EstimatedSize
18665
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
paramurl
http://trkr.trkinstl.com/ipfiles/
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
plurl
http://pp.trkinstl.com/ProductPrice.svc/
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
buybowinapp
http://store.mypctool.xyz/aupc/plan?
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
InstallString
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
InstallString
C:\Program Files\Auto~PC -Care for USER-PC
2432
aupcsetup.tmp
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
LangCode
en
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
LangCode
en
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_source
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_campaign
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
pxl
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
utm_pubid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
LangCode
en
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-plt
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-var1
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
lpid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
btnid
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-var2
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
x-var3
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
referUrl
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
afterInstallUrl
http://ins.trkinstl.com/install/aupc/?
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
country
it
2432
aupcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr
TELNO
2432
aupcsetup.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\QXV0b35QQyAtQ2FyZQ==\ACT
data
0001000000FFFFFFFF01000000000000000C020000003C697974722C2056657273696F6E3D332E302E302E39342C2043756C747572653D6E65757472616C2C205075626C69634B6579546F6B656E3D6E756C6C0501000000184153456E67696E652E426173652E52656744657461696C73120000000A5F5265675374617475730D5F4973526567697374657265640B5F497345787072697265640E5F44617973496E7374616C6C65640F5F44617973526567697374657265640E5F4461797352656D61696E696E671D3C5265676973746572446174653E6B5F5F4261636B696E674669656C641C3C496E7374616C6C446174653E6B5F5F4261636B696E674669656C64193C56616C69646974793E6B5F5F4261636B696E674669656C64243C4C61737456616C6964697479436865636B65643E6B5F5F4261636B696E674669656C641E3C41637469766174696F6E4B65793E6B5F5F4261636B696E674669656C64183C4B6579547970653E6B5F5F4261636B696E674669656C64223C4973416C726561647950757263686173653E6B5F5F4261636B696E674669656C641A3C55736572456D61696C3E6B5F5F4261636B696E674669656C64183C5A6970436F64653E6B5F5F4261636B696E674669656C641C3C436F756E7472794E616D653E6B5F5F4261636B696E674669656C641C3C436F756E747279436F64653E6B5F5F4261636B696E674669656C641D3C5075726368617365446174653E6B5F5F4261636B696E674669656C64040000000000000000030100000101010100174153456E67696E652E426173652E6552656753746174730200000001010808080D0D087153797374656D2E4E756C6C61626C6560315B5B53797374656D2E4461746554696D652C206D73636F726C69622C2056657273696F6E3D322E302E302E302C2043756C747572653D6E65757472616C2C205075626C69634B6579546F6B656E3D623737613563353631393334653038395D5D08010D0200000005FDFFFFFF174153456E67696E652E426173652E655265675374617473010000000776616C75655F5F0008020000000100000000000000000000000000000000000000000000000000F8D08A378C77D688000000000A0A00000000000A0A0A0A00000000000000000B
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
reg
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
expired
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
EnableFileTracing
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
EnableConsoleTracing
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
FileTracingMask
4294901760
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
ConsoleTracingMask
4294901760
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
MaxFileSize
1048576
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASAPI32
FileDirectory
%windir%\tracing
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
EnableFileTracing
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
EnableConsoleTracing
0
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
FileTracingMask
4294901760
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
ConsoleTracingMask
4294901760
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
MaxFileSize
1048576
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\iytr_RASMANCS
FileDirectory
%windir%\tracing
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
x-ccode
it
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
TELNO
+39 069 4802886
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
country
it
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
x-ip
85_203_20_17
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
x-datetime
3924
iytr.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auto~PC -Care For USER-PC
x-fetch
0
3924
iytr.exe
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
x-ip
85_203_20_17
3924
iytr.exe
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
x-datetime
3924
iytr.exe
write
HKEY_CURRENT_USER\Software\Auto~PC -Care For USER-PC
x-fetch
0

Files activity

Executable files
19
Suspicious files
2
Text files
24
Unknown types
6

Dropped files

PID
Process
Filename
Type
3812
aupcsetup.exe
C:\Users\admin\AppData\Local\Temp\is-7RFPL.tmp\aupcsetup.tmp
executable
MD5: c3a25886bcf185a59e9ec82aae7f085b
SHA256: daa20300c12d9bc7e5e37cb5d953acda2c38552ed6478191f2013f16a0df76ba
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\NAudio.dll
executable
MD5: dec7a04f50c5d0da716ff7825b85fdd9
SHA256: 91b0d98fac0c0f205e61d0fc1916516ccbb2350d7d3f4304960ba3c2a24dab6c
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\TAFactory.IconPack.dll
executable
MD5: 218a3e61af5101c8ebdf50ce97813bec
SHA256: f5cdfcecad9e41b6dba689e36200262f0d217b9e98e26c21fa4966fdbcfad9b2
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\Interop.IWshRuntimeLibrary.dll
executable
MD5: 4b19a4ffb5731994caa4bff9c5f09dcd
SHA256: 3d997f125e97e5ba8c74008bd475b056b71e178c558a0045940cf034fb2024a5
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\Interop.SHDocVw.dll
executable
MD5: 94f77006b40ba98382b04faf2a24200d
SHA256: f4a9e7c846ef7602a6fc1def0771ac355aa74c99cb690ca434377c0ead756517
2432
aupcsetup.tmp
C:\Users\admin\AppData\Local\Temp\is-GQB1C.tmp\_isetup\_iscrypt.dll
executable
MD5: a69559718ab506675e907fe49deb71e9
SHA256: 2f6294f9aa09f59a574b5dcd33be54e16b39377984f3d5658cda44950fa0f8fc
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\x86\SQLite.Interop.dll
executable
MD5: 733be7b463a5e431c2548266c3b8996e
SHA256: 1a0eb6744af1e2f5c50243bf736513fd1a72883333dd93e6dba32d7ce521f995
2432
aupcsetup.tmp
C:\Users\admin\AppData\Local\Temp\is-GQB1C.tmp\_isetup\_shfoldr.dll
executable
MD5: 92dc6ef532fbb4a5c3201469a5b5eb63
SHA256: 9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\System.Data.SQLite.DLL
executable
MD5: ecd0292530bb8a8db9e2924fe2074c5f
SHA256: 7a960a63e430fdc56ae62b6ad1e840f1e881236faa3c2ad42c0867ec04769c57
4076
aupcsetup.exe
C:\Users\admin\AppData\Local\Temp\is-TTFJ0.tmp\aupcsetup.tmp
executable
MD5: c3a25886bcf185a59e9ec82aae7f085b
SHA256: daa20300c12d9bc7e5e37cb5d953acda2c38552ed6478191f2013f16a0df76ba
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\unins000.exe
executable
MD5: c3a25886bcf185a59e9ec82aae7f085b
SHA256: daa20300c12d9bc7e5e37cb5d953acda2c38552ed6478191f2013f16a0df76ba
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\HtmlRenderer.dll
executable
MD5: fe2480ddb520926e3eb541699d7776b8
SHA256: 5b0e4461e31026fcb1100211c0e0fb93f751efe4906fbe9e3d8985f176fc77ad
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\Newtonsoft.Json.dll
executable
MD5: 2e73c8bf4c230ae3b7b96adc3fa7ae12
SHA256: 10d2d0e59825aa0073d68a95400cd6ccfb4157d03c519c99400d4bd9ea2d2144
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\PaddleCheckoutSDK.dll
executable
MD5: 8cc5eae2fb74145c02e3ae6278f32e5d
SHA256: 39cce4e5c3af0ae5ca8dcaf3859c9c72161700d7659590ca37c24b146851d3bd
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\Microsoft.Win32.TaskScheduler.dll
executable
MD5: d231b8d72f304483d29793b8b5195b0d
SHA256: 8bed1c113c90be5120751837c47a1b290e4f10ad17bd60d9cf541f716f207e83
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\HtmlRenderer.WinForms.dll
executable
MD5: 64e7c39f72d25dfb5bd2898ad425bbbd
SHA256: e8bf098532c702234210121369004c2dd26ba5fccb98247d851a256d26db542f
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\gmtrs.dll
executable
MD5: ea119222d70b130e58ba53661dd3da45
SHA256: a8792ce602312868802fc4d8d03d89970f2760ec0ea534d0b19df9b451a7e4ea
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
executable
MD5: 17b8580af0ea42cdfbd15cef9a4b4948
SHA256: e06e3ad45d8aad6d2f3480644a61fd3d48d40da94eda4e646ec0dd9ed0bc07f1
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\x64\SQLite.Interop.dll
executable
MD5: fa55919832ad62509bb0cd02c645790a
SHA256: c154036f3fe1901c764c3c23f02ad31606c6674cc7cc46fe3f0930a86099a0f5
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\x64\is-QR64S.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-MNEUE.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-KN42L.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\japanese_iss.ini
text
MD5: f7d70377ea7885b99d3e0077c6208c32
SHA256: ec4f6682f0474b14ed07af200ad9a2e354a6a5be2ab42cf7a6f7a417c0385e4f
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\german_iss.ini
text
MD5: 4df44ee27089159e1b6b753479b25feb
SHA256: 4e9d48e4134250f81c7d2cb7ab83d2a9c6482175d519cdee50a6b41e0b59802d
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\norwegian_iss.ini
text
MD5: 391fc3ec8b1a605bf9f85990b1fadcbe
SHA256: 2d96d3ae88e5dddfa9e56c2bc83a854ed3141c1d19fc709b3b2e15fea75eb827
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\italian_iss.ini
text
MD5: 705db54c5e9013f59994c517a53104a7
SHA256: 217fac103ddcd5cedb48bf0af8dca9d197cccacc2de30f5abeb3784f9248f7f6
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-VP070.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-8ADH4.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-7QRL0.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-HLRAK.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\French_iss.ini
text
MD5: 75a20bfaa88ec86537004ed2a6c1661f
SHA256: 36249e76f801d3c4d25e5ef36bbcf9ba8af7fac2131de1f16cf458cefb9f4084
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\langs.db
binary
MD5: 85f4f65937c9ffc18205dc01d3b42872
SHA256: 1ab59062288620985d2b044f5664e28ee683b9a6eaffc47410f7fde07ba3fa3e
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\finish_iss.ini
text
MD5: 90768c3a32853850d02d682db9ef0c3c
SHA256: 2689ca0605c941e7768f9f8bec329f2086ac0367e18ff53b7ecabf1ebc2ec47a
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\english_iss.ini
text
MD5: c84ec8943b6f22147510360f34b76d75
SHA256: cb245969cf6571db07ba61c9da2fbc67267b42fbed4d1c80386d15ef67506358
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-E387S.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-3HP16.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-9A5SI.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-GVVCJ.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\ProgramData\Auto~PC -Care for USER-PC\pcspstartrepair_en.mp3
mp3
MD5: 8e356f74ed78a1a59010ca6e0bfd4105
SHA256: 973529b2ffd4a0ec5b3b2f0ecbf94b97a436efff00315b91489f5bd3ae4e236c
2432
aupcsetup.tmp
C:\ProgramData\Auto~PC -Care for USER-PC\is-QV9GJ.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\ProgramData\Auto~PC -Care for USER-PC\mdb.db
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\ProgramData\Auto~PC -Care for USER-PC\is-6322K.tmp
––
MD5:  ––
SHA256:  ––
3924
iytr.exe
C:\Users\admin\AppData\Roaming\Auto~PC -Care For USER-PC\Errorlog.txt
text
MD5: f35cac487ce1fc6fd5d7f054742bb919
SHA256: f45aee85e2a1a0a30fa328223970873f5570c4ec8b12ae6886aed146f6d29903
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-KDVK6.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-EF3G3.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-I9R2R.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-9GQG2.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-L9BQE.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\swedish_iss.ini
text
MD5: b74fd78e5f28ac7b917e470868f31254
SHA256: 201455f63c424b7df8f2bcba5169c51795b1e695e0def7ab955f257963619616
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\x86\is-S45NJ.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\russian_iss.ini
text
MD5: 2e9a5666d17c7e94a83cea44787d9149
SHA256: 40c5a7fb06be16178a66b66818ed0304162c9f128764b53187722b70a75176dd
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-STUGO.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\application.ico
image
MD5: 937631a6185a1d5ab28076c7907dcef5
SHA256: 44aaf29cddcc208c64cc763ec54e5bedd024f34075a43728dfeb694617f30dca
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-IUBBJ.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\portuguese_iss.ini
text
MD5: 1a0d822324666f8d2eb786a22a05fdd0
SHA256: d86ce2d13bc6cec0cf9f68c0e6aafb58f51f718b894de1dd3ee31b0d577529d2
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-SHTNV.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\spanish_iss.ini
text
MD5: 5c15a3a7111178aa5a319f0957b0a678
SHA256: bba9a16cc24d55c61a181eb7dc59a51afa86abc4ba1955961ff145d3b8a25ddf
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-IDRJN.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-U0MM6.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-BMTHG.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\danish_iss.ini
text
MD5: e06be97bce5dcb6042c8a34d55c6ae64
SHA256: 1521c51a83776aa1bcd51dea9e9068f76b6f14c0a78d377049f8ef57d16fec3e
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-FUH94.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\Dutch_iss.ini
text
MD5: 7942dc5eb8dd23687fdaf4b220402178
SHA256: 3ad381cd10581d0474595c8bbc0f31cad31630d52f191dc8bbec397d16535338
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-0RAMG.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto~PC -Care for USER-PC\Auto~PC -Care.lnk
lnk
MD5: 99e2c105d76112c27ee4836f83fa5b55
SHA256: 253f738e97f5bb171620383ca5bea0b3c9d88c578a672a8078215c9cf0fa92c2
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-KVNJ7.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto~PC -Care for USER-PC\Buy Auto~PC -Care.lnk
lnk
MD5: 2211318799d70e57242a8a2310d2c693
SHA256: 579e775ae1dc0b0b32d28e79cb465e04cc442f62c38f050b664cfdbc921f4743
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-D75L7.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-5241L.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto~PC -Care for USER-PC\Uninstall Auto~PC -Care.lnk
lnk
MD5: 2be649beac3e8e34a6a948bdef5f7eb6
SHA256: b31370eea1e2606bfb665579dbe05d9cdc63c9299c3aa55711ebfe8c5dc2f6a6
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-2RLN6.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe.config
xml
MD5: c033936a212e26a50fd4217b9fc8b86b
SHA256: 96fa191b0c403737990de79d64dc24415b75238dc9768fddd2a1fa756b5b4eaf
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-MFOMB.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\unins000.msg
binary
MD5: 5f38274fc51ec35b61e925153e26ef1c
SHA256: 946195c199c2f798ed0ab3dc8ae4511be30ad70e5fb994d677beee0ae249dec8
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-JU337.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-D92VF.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\iytr.exe
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Users\Public\Desktop\Auto~PC -Care.lnk
lnk
MD5: 3f46404b86a6eecb03023310f02990be
SHA256: 06b5088b45bb512585508bb3aa4c5352f56c47f93ceda3087eac3279e05b9a3c
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\is-OD3FB.tmp
––
MD5:  ––
SHA256:  ––
2432
aupcsetup.tmp
C:\Users\admin\AppData\Local\Temp\is-GQB1C.tmp\setup_en.bmp
image
MD5: 201296dbf6350096c191efe1015c8b5d
SHA256: bcb734ab835112c8bb2624b5b648f51c86020fbf6efd94949cc967cce105e6d0
2432
aupcsetup.tmp
C:\Program Files\Auto~PC -Care for USER-PC\unins000.dat
dat
MD5: cb9da1556fa507cb699f003d4941c2d3
SHA256: b09fa681a64b44a948631de1a1b96336a7155c4f33f16c8a9453d4fef32e40f8
3924
iytr.exe
C:\Users\admin\AppData\Roaming\Auto~PC -Care For USER-PC\Errorlog.txt
text
MD5: 63a8097a15c082812d20b27100d7a46d
SHA256: edd695364a006991b372c5d44981b73ae9ee6445dd07a1945ffd19978b349f1b
3924
iytr.exe
C:\Users\admin\AppData\Roaming\Auto~PC -Care For USER-PC\Errorlog.txt
text
MD5: 60f5755ec158b39b64218d68744ec42e
SHA256: b0977a6bf01d1e8a3248d0f1c255fb5ede6d80e1ea6cd4d07ddd762da11e47f3
3924
iytr.exe
C:\Users\admin\AppData\Roaming\Auto~PC -Care For USER-PC\Errorlog.txt
text
MD5: 34d8c9b1e418310ab88914103d514c3d
SHA256: 03da9e4cd8679589e693c0abad074df0310cbcd4b34266b42114bd1415cd7c9f

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
3
DNS requests
3
Threats
1

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3924 iytr.exe GET 200 63.143.46.130:80 http://cc.trkinstl.com/productprice.svc/getcountrycode US
text
malicious
3924 iytr.exe GET 200 63.143.46.130:80 http://www.trkinstl.com/getip/ US
text
malicious
3924 iytr.exe GET 404 87.248.214.129:80 http://trkr.trkinstl.com/ipfiles/85_203_20_17.txt IT
––
––
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3924 iytr.exe 63.143.46.130:80 Limestone Networks, Inc. US malicious
3924 iytr.exe 87.248.214.129:80 Limelight Networks, Inc. IT suspicious

DNS requests

Domain IP Reputation
cc.trkinstl.com 63.143.46.130
malicious
www.trkinstl.com 63.143.46.130
malicious
trkr.trkinstl.com 87.248.214.129
87.248.214.1
malicious

Threats

PID Process Class Message
3924 iytr.exe A Network Trojan was detected SC ADWARE AdWare PUA:Win32/SpeedChecker / MSIL/GT32SupportGeeks

Debug output strings

Process Message
iytr.exe Native library pre-loader failed to get setting "SQLite_ForceLogPrepare" value: System.Xml.XmlException: Root element is missing. at System.Xml.XmlTextReaderImpl.Throw(Exception e) at System.Xml.XmlTextReaderImpl.ThrowWithoutLineInfo(String res) at System.Xml.XmlTextReaderImpl.ParseDocumentContent() at System.Xml.XmlTextReaderImpl.Read() at System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace) at System.Xml.XmlDocument.Load(XmlReader reader) at System.Xml.XmlDocument.Load(String filename) at System.Data.SQLite.UnsafeNativeMethods.GetSettingValue(String name, String default)
iytr.exe Native library pre-loader failed to get setting "SQLite_ForceLogPrepare" value: System.Xml.XmlException: Root element is missing. at System.Xml.XmlTextReaderImpl.Throw(Exception e) at System.Xml.XmlTextReaderImpl.ThrowWithoutLineInfo(String res) at System.Xml.XmlTextReaderImpl.ParseDocumentContent() at System.Xml.XmlTextReaderImpl.Read() at System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace) at System.Xml.XmlDocument.Load(XmlReader reader) at System.Xml.XmlDocument.Load(String filename) at System.Data.SQLite.UnsafeNativeMethods.GetSettingValue(String name, String default)