| File name: | MCPR.exe |
| Full analysis: | https://app.any.run/tasks/7d7e45ea-3c52-4efe-80bb-c50f1079b558 |
| Verdict: | Malicious activity |
| Analysis date: | March 28, 2019, 11:01:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 12A889049EFBA4253F88E408360DB335 |
| SHA1: | 18D24100BA5C4CEBF5A3FF02ADDA0C2BFE74A4B6 |
| SHA256: | FC9E46FC6A022A8D647419955B3E14D15183E20FF72C55C8100B4D6B455EF09B |
| SSDEEP: | 196608:H0v73NH39AejbER1PrYnAZd6V+ZZbd8TeUEQHD7qg0t0AJ1SzSnAy:HE3VMR1PrmAZd6V4Zbdpt0hzSnl |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:12:11 22:50:41+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25088 |
| InitializedDataSize: | 141824 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x32fe |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.2.257.0 |
| ProductVersionNumber: | 10.2.257.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | McAfee, Inc. |
| FileDescription: | McAfee ESD Package |
| FileVersion: | 10.2 |
| LegalCopyRight: | Copyright © 2017 McAfee, Inc |
| OriginalFileName: | coreESD.exe |
| ProductName: | McAfee ESD Package |
| ProductVersion: | 10.2.257.0 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 11-Dec-2016 21:50:41 |
| Detected languages: |
|
| CompanyName: | McAfee, Inc. |
| FileDescription: | McAfee ESD Package |
| FileVersion: | 10.2 |
| LegalCopyRight: | Copyright © 2017 McAfee, Inc |
| OriginalFilename: | coreESD.exe |
| ProductName: | McAfee ESD Package |
| ProductVersion: | 10.2.257.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000C8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 11-Dec-2016 21:50:41 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0000608D | 0x00006200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4239 |
.rdata | 0x00008000 | 0x000013A4 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.16231 |
.data | 0x0000A000 | 0x000202F8 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.89813 |
.ndata | 0x0002B000 | 0x00012000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x0003D000 | 0x00006320 | 0x00006400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.01191 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.28747 | 841 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 3.83176 | 4264 | UNKNOWN | English - United States | RT_ICON |
3 | 3.49878 | 3752 | UNKNOWN | English - United States | RT_ICON |
4 | 4.21536 | 2216 | UNKNOWN | English - United States | RT_ICON |
5 | 4.56083 | 1384 | UNKNOWN | English - United States | RT_ICON |
6 | 4.44358 | 1128 | UNKNOWN | English - United States | RT_ICON |
103 | 2.69913 | 90 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.66174 | 256 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.88094 | 284 | UNKNOWN | English - United States | RT_DIALOG |
111 | 2.48825 | 96 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | sc stop mfeavsvc | C:\Windows\SysWOW64\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 244 | net stop "mcnasvc" | C:\Windows\SysWOW64\net.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 244 | net stop "McAfee WebAdvisor" | C:\Windows\SysWOW64\net.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 280 | C:\Windows\system32\net1 stop "mcpltsvc" | C:\Windows\SysWOW64\net1.exe | — | net.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 280 | mfeamcin.exe -u -x mfeavsinst_lam.xml -l amcore_lam_uninstall_latest.log | C:\Users\admin\AppData\Local\Temp\MCPR\VS\Casper\latest\64\mfeamcin.exe | cmd.exe | ||||||||||||
User: SYSTEM Company: McAfee LLC. Integrity Level: SYSTEM Description: Anti-Malware Core Installer Exit code: 2 Version: Anti-Malware Core.1.5.0.4334.x64 Modules
| |||||||||||||||
| 284 | "C:\Windows\system32\cmd.exe" /c "regsvr32 /u /s "%ProgramW6432%\McAfee\MSK\PCBApplicationInfo.dll"" | C:\Windows\SysWOW64\cmd.exe | — | mccleanup.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 3 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 340 | net stop "McOobeSv2" | C:\Windows\SysWOW64\net.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 396 | sc delete "McSchedulerSvc" | C:\Windows\SysWOW64\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 396 | "C:\Windows\system32\cmd.exe" /c "net stop "NGI Service"" | C:\Windows\SysWOW64\cmd.exe | — | mccleanup.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 460 | Mfehidin -u LAM_SYSCORE_15_4 -x lam10.xml -l lam15.4.log | C:\Users\admin\AppData\Local\Temp\MCPR\VS\VSCore\5.6\64\mfehidin.exe | cmd.exe | ||||||||||||
User: SYSTEM Company: McAfee, Inc. Integrity Level: SYSTEM Description: McAfee System Core Installer Exit code: 253 Version: SYSCORE.15.6.0.2180 Modules
| |||||||||||||||
| (PID) Process: | (1440) MCPR.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\nsf8654.tmp\McSplash.dll | |||
| (PID) Process: | (2004) McClnUI.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\65\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2004) McClnUI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\ROOT\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70 |
| Operation: | write | Name: | Blob |
Value: 0400000001000000100000001BAA5A0ECD1ED4B64DFBF621DC9044BF0F000000010000002000000061905BC048345D3815587E318FEAAE705D07527F3B5BD1B2A6AF514E29BA46525C000000010000000400000000080000030000000100000014000000E02357FC7708441D4B0BE5F371F4B28961870F70140000000100000014000000ECCD4BA46722CB4F92060701865DDF09D8AF68B41900000001000000100000000FB5FACA274B0EA933E42C34A45C2D5620000000010000006A030000308203663082024EA003020102020900EE1E7E5DC92BCE32300D06092A864886F70D01010B05003048310B30090603550406130241553113301106035504080C0A536F6D652D5374617465310D300B06035504070C044369747931153013060355040A0C0C536F6D6520436F6D70616E79301E170D3137303932393132323035305A170D3230303932383132323035305A3048310B30090603550406130241553113301106035504080C0A536F6D652D5374617465310D300B06035504070C044369747931153013060355040A0C0C536F6D6520436F6D70616E7930820122300D06092A864886F70D01010105000382010F003082010A0282010100C213E403EA7099364CC3D32AE10D85F8364F3874F86A14DAD9972751C9F548F6025F083F3F8BE947523744A631B6E409CF2CEFBC28F5C9F16ACD3C88ABE7BA7A5871A1CBF3562F7A576C3E9FAED296B5B9867651DB238499683B4E9D768FDA49C5BCA2A9928AFAF2EAD01F1FBE679E6D8ECC7BA57BB55DFA44C03A14BF11D36C7F9D654AC6B76DF9E8D83E1D238A1BCFAA22BADF071A9300CBDCC71C58846BD4ECB7F2BA7BBEF630C61B4FB01BC67E022BE89E243B0EF7F6ABBAC502A48E1DE65787B538F842E83652C365E26F2D47BFA5132215B96E2725AC3FD496BAE376D778A2C3C35D0382B89F61961BF6BA08DB4A892B4BCE3FA96FF3990C6066F1E1FF0203010001A3533051301D0603551D0E04160414ECCD4BA46722CB4F92060701865DDF09D8AF68B4301F0603551D23041830168014ECCD4BA46722CB4F92060701865DDF09D8AF68B4300F0603551D130101FF040530030101FF300D06092A864886F70D01010B0500038201010095A081FEE7794AAE6A222E01AD459EB4288CA6DCD8E1A4F5EDF609C4ACB16E19F51B543E8C75E6B833556E22641E3619EE31F26A7F5477CA8AB8F7417BFDAE076DD329D01C490D1551313F6BA132F46CAFB608C0378CBB1F1C019C573824F7758EAB50AACBE52E4D7B2EC5BD50B555CF4EC9A29892E262ED148EEC6C07F8BDD9D3BECE8402498A490A20A7F518A918065213AE11EBAC77BD1504B4E60EB2C928DA2ACE10A2B7BB7398D229D3EC6A1C2C2BE2E9C5B10C62E4012057E62598096315D01E46D8BC72E239374AB31A79CA0FE4BA94A64B3934E5C618DDB3B56089FEA4D8BAF00EC868FEE19ECCD0EA27360E690B838D3AD4DBF5BF6448F4894867E3 | |||
| (PID) Process: | (2004) McClnUI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54 |
| Operation: | write | Name: | Blob |
Value: 0400000001000000100000008EADB501AA4D81E48C1DD1E1140095190F000000010000002000000017FE16F394EC70A5BB0C6784CAB40B1E61025AE9D50ECAA0531D6B4D997BBC590B000000010000006000000056006500720069005300690067006E00200055006E006900760065007200730061006C00200052006F006F0074002000430065007200740069006600690063006100740069006F006E00200041007500740068006F0072006900740079000000090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B0601050507030853000000010000002500000030233021060B6086480186F8450107170630123010060A2B0601040182373C0101030200C06200000001000000200000002399561127A57125DE8CEFEA610DDF2FA078B5C8067F4E828290BFB860E84B3C140000000100000014000000B677FA6948479F5312D5C2EA07327607D19707191D0000000100000010000000439B4D52906DF7A01771D729528723B30300000001000000140000003679CA35668772304D30A5FB873B0FA77BB70D54190000000100000010000000AD6D6FF31B24013151F279E26A8C33242000000001000000BD040000308204B9308203A1A0030201020210401AC46421B31321030EBBE4121AC51D300D06092A864886F70D01010B05003081BD310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303820566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79313830360603550403132F566572695369676E20556E6976657273616C20526F6F742043657274696669636174696F6E20417574686F72697479301E170D3038303430323030303030305A170D3337313230313233353935395A3081BD310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303820566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79313830360603550403132F566572695369676E20556E6976657273616C20526F6F742043657274696669636174696F6E20417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100C761375EB10134DB62D7159BFF585A8C2323D6608E91D79098837AE65819388CC5F6E56485B4A271FBEDBDB9DACD4D00B4C82D73A5C76971951F393CB244079CE80EFA4D4AC421DF29618F32226182C5871F6E8C7C5F16205144D1704F57EAE31CE3CC79EE58D80EC2B34593C02CE79A172B7B00377A413378E133E2F3101A7F872CBEF6F5F742E2E5BF8762895F004BDFC5DDE4754432413A1E716E69CB0B754608D1CAD22B95D0CFFBB9406B648C574DFC13117984ED5E54F6349F0801F3102506174ADAF11D7A666B986066A4D9EFD22E82F1F0EF09EA44C9156AE2036E33D3AC9F5500C7F6086A94B95FDCE033F18460F95B2711B4FC16F2BB566A80258D0203010001A381B23081AF300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106306D06082B0601050507010C0461305FA15DA05B3059305730551609696D6167652F6769663021301F300706052B0E03021A04148FE5D31A86AC8D8E6BC3CF806AD448182C7B192E30251623687474703A2F2F6C6F676F2E766572697369676E2E636F6D2F76736C6F676F2E676966301D0603551D0E04160414B677FA6948479F5312D5C2EA07327607D1970719300D06092A864886F70D01010B050003820101004AF8F8B003E62C677BE4947763CC6E4CF97D0E0DDCC8B935B9704F63FA24FA6C838C479D3B63F39AF976329591B177BCAC9ABEB1E43121C68195565A0EB1C2D4B1A659ACF163CBB84C1D59904AEF9016281F5AAE10FB8150380C6CCCF13DC3F563E3B3E321C92439E9FD156646F41B11D04D73A37D46F93DEDA85F62D4F13FF8E074572B189D81B4C428DA9497A570EBAC1DBE0711F0D5DBDDE58CF0D532B083E657E28FBFBEA1AABF3D1DB5D438EAD7B05C3A4F6A3F8FC0666C63AAE9D9A416F481D195140E7DCD9534D9D28F7073817B9C7EBD9861D845879890C5EB8630C635BFF0FFC35588834BEF05920671F2B89893B7ECCD8261F138E64F97982A5A8D | |||
| (PID) Process: | (2004) McClnUI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54 |
| Operation: | write | Name: | Blob |
Value: 5C000000010000000400000000080000190000000100000010000000AD6D6FF31B24013151F279E26A8C33240300000001000000140000003679CA35668772304D30A5FB873B0FA77BB70D541D0000000100000010000000439B4D52906DF7A01771D729528723B3140000000100000014000000B677FA6948479F5312D5C2EA07327607D19707196200000001000000200000002399561127A57125DE8CEFEA610DDF2FA078B5C8067F4E828290BFB860E84B3C53000000010000002500000030233021060B6086480186F8450107170630123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B000000010000006000000056006500720069005300690067006E00200055006E006900760065007200730061006C00200052006F006F0074002000430065007200740069006600690063006100740069006F006E00200041007500740068006F00720069007400790000000F000000010000002000000017FE16F394EC70A5BB0C6784CAB40B1E61025AE9D50ECAA0531D6B4D997BBC590400000001000000100000008EADB501AA4D81E48C1DD1E1140095192000000001000000BD040000308204B9308203A1A0030201020210401AC46421B31321030EBBE4121AC51D300D06092A864886F70D01010B05003081BD310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303820566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79313830360603550403132F566572695369676E20556E6976657273616C20526F6F742043657274696669636174696F6E20417574686F72697479301E170D3038303430323030303030305A170D3337313230313233353935395A3081BD310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303820566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79313830360603550403132F566572695369676E20556E6976657273616C20526F6F742043657274696669636174696F6E20417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100C761375EB10134DB62D7159BFF585A8C2323D6608E91D79098837AE65819388CC5F6E56485B4A271FBEDBDB9DACD4D00B4C82D73A5C76971951F393CB244079CE80EFA4D4AC421DF29618F32226182C5871F6E8C7C5F16205144D1704F57EAE31CE3CC79EE58D80EC2B34593C02CE79A172B7B00377A413378E133E2F3101A7F872CBEF6F5F742E2E5BF8762895F004BDFC5DDE4754432413A1E716E69CB0B754608D1CAD22B95D0CFFBB9406B648C574DFC13117984ED5E54F6349F0801F3102506174ADAF11D7A666B986066A4D9EFD22E82F1F0EF09EA44C9156AE2036E33D3AC9F5500C7F6086A94B95FDCE033F18460F95B2711B4FC16F2BB566A80258D0203010001A381B23081AF300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106306D06082B0601050507010C0461305FA15DA05B3059305730551609696D6167652F6769663021301F300706052B0E03021A04148FE5D31A86AC8D8E6BC3CF806AD448182C7B192E30251623687474703A2F2F6C6F676F2E766572697369676E2E636F6D2F76736C6F676F2E676966301D0603551D0E04160414B677FA6948479F5312D5C2EA07327607D1970719300D06092A864886F70D01010B050003820101004AF8F8B003E62C677BE4947763CC6E4CF97D0E0DDCC8B935B9704F63FA24FA6C838C479D3B63F39AF976329591B177BCAC9ABEB1E43121C68195565A0EB1C2D4B1A659ACF163CBB84C1D59904AEF9016281F5AAE10FB8150380C6CCCF13DC3F563E3B3E321C92439E9FD156646F41B11D04D73A37D46F93DEDA85F62D4F13FF8E074572B189D81B4C428DA9497A570EBAC1DBE0711F0D5DBDDE58CF0D532B083E657E28FBFBEA1AABF3D1DB5D438EAD7B05C3A4F6A3F8FC0666C63AAE9D9A416F481D195140E7DCD9534D9D28F7073817B9C7EBD9861D845879890C5EB8630C635BFF0FFC35588834BEF05920671F2B89893B7ECCD8261F138E64F97982A5A8D | |||
| (PID) Process: | (2004) McClnUI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\McClientAnalytics |
| Operation: | write | Name: | Analytics.ContextId |
Value: 4D435247010000002700000001000000DB4988AA977E004E8051F1B75D2C83A8A84F0E4B8EDC72D4907C510E07002860B66AF906C0D332AD6FC4D940AA1F9AFC37F1EFDE706109 | |||
| (PID) Process: | (2004) McClnUI.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2004) McClnUI.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2004) McClnUI.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2004) McClnUI.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\MCPR\McClnUI.exe | executable | |
MD5:— | SHA256:— | |||
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\MCPR\StartCleanup.bat | text | |
MD5:— | SHA256:— | |||
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\MCPR\mccleanup.exe | executable | |
MD5:— | SHA256:— | |||
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\MCPR\StartCleanupDebug.bat | text | |
MD5:— | SHA256:— | |||
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\MCPR\master.ini | text | |
MD5:— | SHA256:— | |||
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\MCPR\FWDriverCleanUP.wse | text | |
MD5:CB5924131DC92ACCEF8DD3D15AB76ABE | SHA256:78D477DD7E2D49F5226609FC366EA6ADBD100D132E9FBD019DD005B2B8E09D2D | |||
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\MCPR\MBKCleanUP.wse | text | |
MD5:CE9D9EA7C88D27F6CB8A215798A52CBA | SHA256:BEEFE21231CE588C2FD737209B536A76C94347AE557A1FF56F105D6991C1CAC1 | |||
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\MCPR\MpfCleanUP.wse | text | |
MD5:133BBF94AD6260B31A42E0079679BC86 | SHA256:76308443A9BC8475879717D470F6522493CECC65E27206CA5AB71CC58C0B89BD | |||
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\nsf8654.tmp\McSplash.bmp | image | |
MD5:4588673F6257394D3827715DFF22A6DA | SHA256:855A0E7C18A2DA2424F94869B627AD84437D00D214E309788EB1AC355B394159 | |||
| 1440 | MCPR.exe | C:\Users\admin\AppData\Local\Temp\MCPR\MasCleanUP.wse | text | |
MD5:3B69BB781DF52990CA64FDB7AC5E1A4F | SHA256:8F6B0F753F7F767FE6E31144346120A8E292B62B2072E33EF92D5C59C98462DF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/SA/Win/CA/Content/1.1/update_dataConfig.xml | NL | xml | 738 b | whitelisted |
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/SA/Win/ca/content/1.1/170/1/legacyConfig.cab | NL | compressed | 7.20 Kb | whitelisted |
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/SA/Win/ca/update_expirydatefix.xml | NL | xml | 750 b | whitelisted |
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/SA/Win/CA/Content/1.1/update_daConfig.xml | NL | xml | 582 b | whitelisted |
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/SA/Win/ca/content/1.1/170/1/daConfig.cab | NL | compressed | 10.7 Kb | whitelisted |
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/sa/pc/update_freemium.xml | NL | xml | 6.87 Kb | whitelisted |
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/SA/Win/ca/content/1.1/170/1/dataConfig.cab | NL | compressed | 102 Kb | whitelisted |
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/SA/pc/update_freemium_vars.xml | NL | xml | 6.77 Kb | whitelisted |
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/SA/Win/CA/Content/1.1/update_legacyConfig.xml | NL | xml | 598 b | whitelisted |
2004 | McClnUI.exe | GET | 200 | 104.111.215.113:443 | https://sadownload.mcafee.com/products/SA/pc/freemium_abtest.xml | NL | xml | 208 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2004 | McClnUI.exe | 104.111.215.113:443 | sadownload.mcafee.com | Akamai International B.V. | NL | whitelisted |
2436 | mfeamcin.exe | 161.69.169.22:443 | cloud.gti.mcafee.com | McAfee, Inc. | US | unknown |
2436 | mfeamcin.exe | 161.69.169.59:443 | cloud.gti.mcafee.com | McAfee, Inc. | US | unknown |
280 | mfeamcin.exe | 161.69.169.22:443 | cloud.gti.mcafee.com | McAfee, Inc. | US | unknown |
2004 | McClnUI.exe | 104.208.16.0:443 | cu1pehnswss01.servicebus.windows.net | Microsoft Corporation | US | unknown |
— | — | 93.184.221.240:80 | ctldl.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2528 | installer.exe | 161.69.169.58:443 | cloud.gti.mcafee.com | McAfee, Inc. | US | unknown |
280 | mfeamcin.exe | 161.69.169.19:443 | cloud.gti.mcafee.com | McAfee, Inc. | US | unknown |
2528 | installer.exe | 161.69.169.16:443 | cloud.gti.mcafee.com | McAfee, Inc. | US | malicious |
Domain | IP | Reputation |
|---|---|---|
sadownload.mcafee.com |
| whitelisted |
cu1pehnswss01.servicebus.windows.net |
| unknown |
cloud.gti.mcafee.com |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
teredo.ipv6.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
mccleanup.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
mccleanup.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\MCPR\mccleanup.exe loading C:\Users\admin\AppData\Local\Temp\MCPR\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
mccleanup.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
mccleanup.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\MCPR\mccleanup.exe loading C:\Users\admin\AppData\Local\Temp\MCPR\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
mccleanup.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
mccleanup.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\MCPR\mccleanup.exe loading C:\Users\admin\AppData\Local\Temp\MCPR\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
mccleanup.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
mccleanup.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\MCPR\mccleanup.exe loading C:\Users\admin\AppData\Local\Temp\MCPR\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
mccleanup.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory |
mccleanup.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\MCPR\mccleanup.exe loading C:\Users\admin\AppData\Local\Temp\MCPR\mfeaaca.dll, WinVerifyTrust failed with 80092003
|