Windows Analysis Report
SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe

Overview

General Information

Sample name: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe
Analysis ID: 1546907
MD5: 17563cfba0842038f0a8bd7f15c89e2e
SHA1: 34b5dbfe3bfcdd033d256fe66c87864bc3c61aaa
SHA256: 7ef8b3f4ca7db60e350a0b51dd7c284248a94a073735a25a00f85f9072d48143
Tags: AdwareGenericexe
Infos:

Detection

Score: 32
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Yara detected AntiVM3
May drop file containing decryption instructions (likely related to ransomware)
Monitors registry run keys for changes
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
AV process strings found (often used to terminate AV products)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to dynamically determine API calls
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Detected potential crypto function
Drops PE files
Enables security privileges
Found dropped PE file which has not been started or loaded
JA3 SSL client fingerprint seen in connection with other malware
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries the product ID of Windows
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Use Short Name Path in Command Line
Steals Internet Explorer cookies
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Static PE information: certificate valid
Source: unknown HTTPS traffic detected: 116.203.251.147:443 -> 192.168.2.7:49703 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.63.52.39:443 -> 192.168.2.7:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.63.52.39:443 -> 192.168.2.7:49711 version: TLS 1.2
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Microsoft Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Microsoft\Windows Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Microsoft\Windows\History\desktop.ini Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData Jump to behavior
Source: Joe Sandbox View JA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.7:49703 -> 116.203.251.147:443
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.7:49705 -> 178.63.52.39:443
Source: Network traffic Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.7:49711 -> 178.63.52.39:443
Source: Network traffic Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 52.149.20.212:443 -> 192.168.2.7:49730
Source: Network traffic Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.12.23.50:443 -> 192.168.2.7:49947
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /debug.txt HTTP/1.1Connection: Keep-AliveUser-Agent: Embarcadero URI Client/1.0Host: collect.avqtools.com
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: gacy_cookie_access":{},"local_fonts":{},"media_engagement":{},"media_stream_camera":{},"media_stream_mic":{},"midi":{},"midi_sysex":{},"mixed_script":{},"nfc_devices":{},"notification_interactions":{},"notification_permission_review":{},"notifications":{},"password_protection":{},"payment_handler":{},"permission_autoblocking_data":{},"permission_autorevocation_data":{},"popups":{},"private_network_chooser_data":{},"private_network_guard":{},"protected_media_identifier":{},"protocol_handler":{},"reduced_accept_language":{},"safe_browsing_url_check_data":{},"sensors":{},"serial_chooser_data":{},"serial_guard":{},"site_engagement":{},"sound":{},"ssl_cert_decisions":{},"storage_access":{},"subresource_filter":{},"subresource_filter_data":{},"third_party_storage_partitioning":{},"top_level_storage_access":{},"unused_site_permissions":{},"usb_chooser_data":{},"usb_guard":{},"vr":{},"webid_api":{},"webid_auto_reauthn":{},"window_placement":{}},"pref_version":1},"created_by_version":"117.0.5938.134","creation_time":"13340965310820162","exit_type":"normal","icon_version":10,"managed":{"banner_state":2},"managed_user_id":"","name":"person 1","password_account_storage_settings":{}},"protection":{"macs":{}},"safebrowsing":{"enabled":false,"enhanced":false,"event_timestamps":{},"metrics_last_log_time":"13340965310"},"sessions":{"event_log":[{"crashed":false,"time":"13340965310874395","type":0},{"did_schedule_command":true,"first_session_service":true,"tab_count":1,"time":"13340965314121830","type":2,"window_count":1},{"crashed":false,"time":"13340965340486488","type":0},{"did_schedule_command":true,"first_session_service":true,"tab_count":1,"time":"13340965347697726","type":2,"window_count":1},{"crashed":false,"time":"13340965894520000","type":0},{"did_schedule_command":false,"first_session_service":true,"tab_count":0,"time":"13340965895529112","type":2,"window_count":0},{"crashed":false,"time":"13340965896647302","type":0},{"did_schedule_command":false,"first_session_service":true,"tab_count":0,"time":"13340965897562572","type":2,"window_count":0},{"crashed":false,"time":"13340965899453521","type":0},{"did_schedule_command":false,"first_session_service":true,"tab_count":0,"time":"13340965900388040","type":2,"window_count":0},{"crashed":false,"time":"13340965902527967","type":0},{"did_schedule_command":false,"first_session_service":true,"tab_count":0,"time":"13340965907495322","type":2,"window_count":0},{"crashed":false,"time":"13340965909466868","type":0},{"did_schedule_command":false,"first_session_service":true,"tab_count":0,"time":"13340965910838554","type":2,"window_count":0},{"crashed":false,"time":"13340965912890131","type":0},{"did_schedule_command":false,"first_session_service":true,"tab_count":0,"time":"13340965913778449","type":2,"window_count":0}],"session_data_status":5},"settings":{"a11y":{"apply_page_colors_only_on_increased_contrast":true}},"signin":{"allowed":true},"spellcheck":{"dictionaries":["en-us"],"dictionary":""},"supervised_user":{"me
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: taskmde.youtube.superpop.http.www.youtube.comtaskmgra equals www.youtube.com (Youtube)
Source: global traffic DNS traffic detected: DNS query: collect.avqtools.com
Source: global traffic DNS traffic detected: DNS query: collect.smartpcupdate.com
Source: unknown HTTP traffic detected: POST /api/collect HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: Embarcadero URI Client/1.0Content-Length: 286Host: collect.smartpcupdate.com
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
Source: SPONotifications.exe, 0000000B.00000002.2507651152.0000000000B13000.00000004.00000020.00020000.00000000.sdmp, SPONotifications.exe, 0000000B.00000003.1388024357.0000000000AE4000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.com/root-r6.crl0G
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAEVR36.crl0
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0#
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://find.naupoint.com
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://find.naupoint.comE-4
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://find.naupoint.comStart
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ocsp.sectigo.com0
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ocsp.sectigo.com0/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ocsp2.globalsign.com/rootr606
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
Source: SmartPCOptimizer.exe, 0000000C.00000000.1320145194.0000000000D16000.00000002.00000001.01000000.0000000A.sdmp String found in binary or memory: http://www.gimp.org/xmp/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.google.com/search?q=
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.000000000536C000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp, SPONotifications.exe, 0000000B.00000000.1313420497.0000000000401000.00000020.00000001.01000000.00000008.sdmp, SPONotifications.exe, 0000000B.00000002.2509454654.00000000025D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.indyproject.org/
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000003.2501139691.00000000065D1000.00000004.00000020.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.lienvandekelder.be
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lienvandekelder.beQ
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lienvandekelder.com
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lienvandekelder.com/
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com:443
Source: SmartPCOptimizer.exe, 0000000C.00000002.2520880012.0000000005B17000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore/
Source: SmartPCOptimizer.exe, 0000000C.00000002.2520880012.0000000005B17000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chromewebstore.google.com/
Source: SPONotifications.exe, 0000000B.00000002.2506307194.0000000000AA5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://collect.avqtools.com/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SPONotifications.exe, 0000000B.00000000.1313420497.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://collect.avqtools.com/api/debug?program=pchs_cleaner_v
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SPONotifications.exe, 0000000B.00000000.1313420497.0000000000401000.00000020.00000001.01000000.00000008.sdmp String found in binary or memory: https://collect.avqtools.com/api/debugU
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SPONotifications.exe, 0000000B.00000000.1313420497.0000000000401000.00000020.00000001.01000000.00000008.sdmp, SPONotifications.exe, 0000000B.00000002.2506307194.0000000000AB9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://collect.avqtools.com/debug.txt
Source: SPONotifications.exe, 0000000B.00000002.2506307194.0000000000A68000.00000004.00000020.00020000.00000000.sdmp, SPONotifications.exe, 0000000B.00000002.2506307194.0000000000AA5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://collect.smartpcupdate.com/
Source: SPONotifications.exe, 0000000B.00000003.1388024357.0000000000AE4000.00000004.00000020.00020000.00000000.sdmp, SPONotifications.exe, 0000000B.00000002.2506307194.0000000000AB9000.00000004.00000020.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000002.2509629250.00000000029CD000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://collect.smartpcupdate.com/api/collect
Source: SPONotifications.exe, 0000000B.00000002.2507651152.0000000000B35000.00000004.00000020.00020000.00000000.sdmp, SPONotifications.exe, 0000000B.00000003.1387909516.0000000000B35000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://collect.smartpcupdate.com/k
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/document/installwebapp?usp=chrome_default
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/presentation/installwebapp?usp=chrome_default
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/spreadsheets/installwebapp?usp=chrome_default
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/drive/installwebapp?usp=chrome_default
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000000.1254764925.0000000000401000.00000020.00000001.01000000.00000003.sdmp String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/installwebapp?usp=chrome_default
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://sectigo.com/CPS0
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1259962441.0000000003490000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.00000000023FC000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.0000000002491000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.00000000023C5000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1334297281.0000000003720000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://smartpctools.com/eula/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1259962441.0000000003490000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.00000000023A1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://smartpctools.com/files/drivermanager.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2509629250.0000000002920000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://smartpctools.com/files/drivermanager.exel
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1259962441.0000000003490000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.00000000023F0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.000000000248A000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.00000000023C5000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1334297281.0000000003720000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://smartpctools.com/privacy-policy/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://smartpctools.com/privacy-policy/S
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://smartpctools.com/smart-driver-manager/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1259962441.0000000003490000.00000004.00001000.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000002.2520880012.0000000005AC7000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://smartpctools.com/smart-pc-optimizer/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.000000000240D000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://smartpctools.com/smart-pc-optimizer/A
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1259962441.0000000003490000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.000000000247C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://smartpctools.com/support/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1259962441.0000000003490000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.000000000238C000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.0000000002406000.00000004.00001000.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000002.2509629250.00000000029BE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://store.payproglobal.com/checkout?products
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1340185099.000000000236B000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1259962441.0000000003490000.00000004.00001000.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000002.2509629250.000000000293E000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://store.payproglobal.com/checkout?products%5b1%5d%5bid%5d=90862&page-template=18224&products%5
Source: SPONotifications.exe, 0000000B.00000002.2509454654.0000000002646000.00000004.00001000.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000002.2520880012.0000000005B77000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://subscriptions.smartpctools.com
Source: SPONotifications.exe, 0000000B.00000002.2509454654.0000000002646000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://techsupport.smartpcupdate.com
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.globalsign.com/repository/0
Source: SmartPCOptimizer.exe, 0000000C.00000002.2509629250.00000000029BE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: SmartPCOptimizer.exe, 0000000C.00000002.2509629250.00000000029BE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: SmartPCOptimizer.exe, 0000000C.00000002.2509629250.00000000029BE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: SmartPCOptimizer.exe, 0000000C.00000002.2509629250.00000000029BE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002690000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000000.1258247883.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: https://www.innosetup.com/
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002690000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000000.1258247883.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: https://www.remobjects.com/ps
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/s/notifications/manifest/cr_install.html
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 49705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49705
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown HTTPS traffic detected: 116.203.251.147:443 -> 192.168.2.7:49703 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.63.52.39:443 -> 192.168.2.7:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 178.63.52.39:443 -> 192.168.2.7:49711 version: TLS 1.2

Spam, unwanted Advertisements and Ransom Demands

barindex
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.HTML
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.HTML
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.HTML
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.PNG
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.PNG
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.PNG
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.PNG
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.PNG
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.PNG
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.TXT
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.TXT
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.TXT
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.TXT
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.TXT
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.TXT
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.TXT
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.PNG
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.PNG
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HELP_DECRYPT.HTML
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_609661C7 16_2_609661C7
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094E1C5 16_2_6094E1C5
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60963115 16_2_60963115
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094B2EA 16_2_6094B2EA
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6092126F 16_2_6092126F
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6093A38C 16_2_6093A38C
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6093E3D5 16_2_6093E3D5
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095432A 16_2_6095432A
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_609654DA 16_2_609654DA
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60950479 16_2_60950479
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60968614 16_2_60968614
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60951618 16_2_60951618
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095462C 16_2_6095462C
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60932677 16_2_60932677
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095B715 16_2_6095B715
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60966862 16_2_60966862
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_609699C4 16_2_609699C4
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_609609C1 16_2_609609C1
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60953AA4 16_2_60953AA4
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6092EAC1 16_2_6092EAC1
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60931AC4 16_2_60931AC4
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6096CA4C 16_2_6096CA4C
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6093EA7F 16_2_6093EA7F
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095FA67 16_2_6095FA67
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60936BAA 16_2_60936BAA
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60963BE7 16_2_60963BE7
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094FB31 16_2_6094FB31
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60954C98 16_2_60954C98
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60912CE0 16_2_60912CE0
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60915DB9 16_2_60915DB9
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60935DAF 16_2_60935DAF
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60930DD5 16_2_60930DD5
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6096CE90 16_2_6096CE90
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60909E0B 16_2_60909E0B
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094CE2C 16_2_6094CE2C
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process token adjusted: Security Jump to behavior
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-0G7HO.tmp.2.dr Static PE information: Resource name: RT_STRING type: DOS executable (COM, 0x8C-variant)
Source: is-5C8ME.tmp.2.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-UJHD8.tmp.2.dr Static PE information: Number of sections : 20 > 10
Source: is-0G7HO.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: is-RADPK.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000000.1254865877.00000000004C6000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFileName vs SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1256648179.0000000002788000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFileName vs SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1354868787.0000000002358000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamekernel32j% vs SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe, 00000000.00000003.1257004586.000000007FE35000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFileName vs SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engine Classification label: sus32.rans.spyw.evad.winEXE@8/65@2/2
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Program Files (x86)\Smart PC Solutions Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Users\user\AppData\Local\Programs Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Mutant created: \Sessions\1\BaseNamedObjects\AF54E2DC-EE25-4757-87F6-A1880E22042B
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Mutant created: \Sessions\1\BaseNamedObjects\dbcc15e2c3e24edf018ffd1269d25c9a
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe File created: C:\Users\user~1\AppData\Local\Temp\is-O0UIQ.tmp Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File read: C:\Program Files (x86)\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: SmartPCOptimizer.exe, 0000000C.00000003.1403819133.00000000063E1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';m
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: create table if not exists [mdns] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, [ipid] INTEGER NULL, [query] TEXT NULL, [answer] BLOB NULL);
Source: SmartPCOptimizer.exe, 0000000C.00000003.1389743593.0000000003930000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE vacuum_db.[ma-s] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT,[Pattern] TEXT NULL,[Name] TEXT NULL,[Address] TEXT NULL);
Source: SmartPCOptimizer.exe, 0000000C.00000003.2501139691.0000000006639000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: INSERT INTO 'vacuum_db'.sqlite_master VALUES('index','sqlite_autoindex_passwords_1','passwords',#4,NULL);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: create table if not exists [scans] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, [date] REAL NULL, [network] TEXT NULL, [win] TEXT NULL, [scantime] INTEGER NULL, [vultime] INTEGER NULL);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: create table if not exists [files] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, [scanid] INTEGER NULL, [name] TEXT NULL, [data] TEXT NULL);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SPONotifications.exe Binary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: create table if not exists [dhcpnames] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, [scanid] INTEGER NULL, [mac] TEXT NULL, [hostname] TEXT NULL, [vendorident] TEXT NULL);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000003.1403819133.00000000063E1000.00000004.00000020.00020000.00000000.sdmp, SPONotifications.exe Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp, SPONotifications.exe Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: create table if not exists [ports] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, [ipid] INTEGER NULL, [port] INTEGER NULL, [protocol] INTEGER NULL, [string] TEXT NULL);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: CREATE TABLE "%w"."%w_node"(nodeno INTEGER PRIMARY KEY, data BLOB);CREATE TABLE "%w"."%w_rowid"(rowid INTEGER PRIMARY KEY, nodeno INTEGER);CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY, parentnode INTEGER);INSERT INTO '%q'.'%q_node' VALUES(1, zeroblob(%d))
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: insert into [resources] ([ipid], [Name], [Description], [Path], [ServerName], [Password], [ResourceType], [Special], [Temporary]) values (?, ?, ?, ?, ?, ?, ?, ?, ?);SQh
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: create table if not exists [vulnerability] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, [portid] INTEGER NULL, [vultype] INTEGER NULL, [text1] TEXT NULL, [text2] TEXT NULL);U
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: create table if not exists [hosts] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, [scanid] INTEGER NULL, [ip] TEXT NULL, [mac] TEXT NULL, [scantime] INTEGER NULL, [vultime] INTEGER NULL, [vpassed] INTEGER NULL);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: SmartPCOptimizer.exe, 0000000C.00000003.1389743593.0000000003923000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: INSERT INTO 'vacuum_db'.sqlite_master VALUES('index','acports_index','acports',#1,'CREATE INDEX [acports_index] on [acports] ([Port] desc)');
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: create table if not exists [names] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, [ipid] INTEGER NULL, [type] INTEGER NULL, [value] TEXT NULL);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.0000000004FD0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1322343239.00000000053EE000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: create table if not exists [resources] ([id] INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, [ipid] INTEGER NULL, [Name] TEXT NULL, [Description] TEXT NULL, [Path] TEXT NULL, [ServerName] TEXT NULL,[Password] TEXT NULL, [ResourceType] INTEGER NULL, [Special] INTEGER NULL, [Temporary] INTEGER NULL, [Access] INTEGER NULL);
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe File read: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe "C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Process created: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp "C:\Users\user~1\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp" /SL5="$2044E,5851923,832512,C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe"
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe "C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe"
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe "C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer" /START
Source: unknown Process created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe "C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Process created: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp "C:\Users\user~1\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp" /SL5="$2044E,5851923,832512,C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe "C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe "C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer" /START Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: crtdll.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: sqlite3.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: security.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: olepro32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: webio.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: sqlite3.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wlanapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: crtdll.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: security.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: shunimpl.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: olepro32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: xmllite.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: firewallapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: fwbase.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: fwpolicyiomgr.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: crtdll.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: sqlite3.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: security.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Section loaded: olepro32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32 Jump to behavior
Source: Smart PC Optimizer.lnk.2.dr LNK file: ..\..\..\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe
Source: Smart PC Optimizer.lnk0.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe
Source: Uninstall Smart PC Optimizer.lnk.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\unins000.exe
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File written: C:\Users\user\AppData\Roaming\Smart PC Optimizer\Backup\Extensions.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Window found: window name: TMainForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Automated click: Next
Source: Window Recorder Window detected: More than 3 window changes detected
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Static PE information: certificate valid
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Static file information: File size 6716192 > 1048576
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6096C33C _winmajor,LoadLibraryA,GetProcAddress,GetProcAddress,FreeLibrary, 16_2_6096C33C
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Static PE information: section name: .didata
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp.0.dr Static PE information: section name: .didata
Source: is-0G7HO.tmp.2.dr Static PE information: section name: .didata
Source: is-5C8ME.tmp.2.dr Static PE information: section name: .didata
Source: is-RADPK.tmp.2.dr Static PE information: section name: .didata
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /4
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /19
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /35
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /51
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /63
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /77
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /89
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /102
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /113
Source: is-UJHD8.tmp.2.dr Static PE information: section name: /124
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60989267 pushad ; retn 0009h 16_2_60989269
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6096CD38 push eax; ret 16_2_6096CD68
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60911E87 push ecx; mov dword ptr [esp], ebx 16_2_60911EBC
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Users\user\AppData\Local\Temp\is-TJ8GA.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\is-0G7HO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\sqlite3.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\is-5C8ME.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\is-RADPK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\is-UJHD8.tmp Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe File created: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Jump to dropped file

Boot Survival

barindex
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Registry key monitored: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Registry key monitored: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Registry key monitored: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Registry key monitored: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart PC Optimizer Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart PC Optimizer\Smart PC Optimizer.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart PC Optimizer\Uninstall Smart PC Optimizer.lnk Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: Yara match File source: 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: SmartPCOptimizer.exe PID: 7528, type: MEMORYSTR
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: PROCMON.EXE
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: PROCESSHACKER.EXE
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: PROCMON.EXEA
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: REGMON.EXE
Source: SmartPCOptimizer.exe, 0000000C.00000003.2499863229.00000000064E9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SBIECTRL.EXESANDBOXIECONTROL
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500883197.000000000651A000.00000004.00000020.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000003.2499863229.00000000064E9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 5-SUPERANTISPYWARE.EXESUPERANTISPYWARE
Source: SmartPCOptimizer.exe, 0000000C.00000003.2499863229.00000000064E9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: REGMON.EXEREGISTRY MONITOR
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: PROCESSHACKER.EXE9
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: FILEMON.EXEFILE PROTECTION MONITOR
Source: SmartPCOptimizer.exe, 0000000C.00000003.2499863229.00000000064E9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: PROCMON.EXEPROCMON
Source: SmartPCOptimizer.exe, 0000000C.00000003.2499863229.00000000064E9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: PROCESSHACKER.EXEPROCESS HACKER 2
Source: SmartPCOptimizer.exe, 0000000C.00000003.2499863229.00000000064E9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SNIFFER.EXESYSTEMWIZARD SNIFFER
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: REGMON.EXEQ8
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.00000000065D1000.00000004.00000020.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000003.2501139691.00000000065D1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: WINDBG.EXEWINDOWS DEBUGGER
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.00000000065D1000.00000004.00000020.00020000.00000000.sdmp, SmartPCOptimizer.exe, 0000000C.00000003.2501139691.00000000065D1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: WIRESHARK.EXE*MANAGRMEDIAMICRO
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMUSRVC.EXEVPCUSERSERVICES
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-TJ8GA.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\is-UJHD8.tmp Jump to dropped file
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Microsoft Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Microsoft\Windows Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Microsoft\Windows\History\desktop.ini Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData Jump to behavior
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Fonts34.exeVMware admin Tool
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VBoxTray.exeVBoxTray#
Source: SmartPCOptimizer.exe, 0000000C.00000003.2499863229.00000000064E9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: spooles.exeVmwares-
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: _VMwareHostd=Part of VMware Workstation. If you do not use VMware, this service can be disabled.
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: hqtray.exeVMware Workstation9
Source: SPONotifications.exe, 0000000B.00000002.2506307194.0000000000AA5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAWp
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMUSBArbService=VMware USB Arbitration service. If you do not use VMware, this service can be disabled.
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware process Tool
Source: SPONotifications.exe, 0000000B.00000003.1388024357.0000000000AE4000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: vmware-unity.exevmware-unity$
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: ^VMware NAT Service=VMware NAT Service. If you do not use VMware, this service can be disabled.g
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Help.exeVMware process Tool%
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: vmnethcp.exeMicrosoft Routing Utilities
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: vmicshutdown
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware hptray7a
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMAuthdService=VMware Authorization Service. If you do not use VMware, this service can be disabled.
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: hpmon.exeVMware hptray
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware hptray
Source: SPONotifications.exe, 0000000B.00000002.2509454654.0000000002671000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMWARE=
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware admin Tool
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMwareHostd=Part of VMware Workstation. If you do not use VMware, this service can be disabled.
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMnetDHCPP
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware [UserName] process
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: addins2.exeVMWARE
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMwareHostdP
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware Workstation
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: vmicheartbeat
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VBoxService=Oracle's VirtualBox Virtual Machine service. If you do not use VirtualBox, this service can be disabled.
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: vmware-tray.exevmware-tray.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware Workstation1-
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VBoxService.exeVBoxService.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: explorer.exe,vmware-tray.exe
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMUSrvc.exeVPCUserServices
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: explorer.exe,vmware-tray.exe5
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: vmnetdhcp.exevmnetdhcp%
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: sVMnetDHCP=VMware VMnet DHCP service for VMware Workstation. If you do not use VMware, this service can be disabled.##fn`
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: vmware.exeWorkstation Ver 5.0!
Source: SmartPCOptimizer.exe, 0000000C.00000002.2506935990.0000000001003000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware admin Tool225
Source: SmartPCOptimizer.exe, 0000000C.00000003.1343856549.0000000003ABA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 000C29VMware, Inc.
Source: SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp, 00000002.00000003.1343673699.00000000007F2000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware NAT Service=VMware NAT Service. If you do not use VMware, this service can be disabled.
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware process ToolFAA{
Source: SmartPCOptimizer.exe, 0000000C.00000003.1392026070.00000000065BB000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 005056VMware, Inc.
Source: SmartPCOptimizer.exe, 0000000C.00000003.1343856549.0000000003ABA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 000569VMware, Inc.
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VBoxServiceP
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: vmremotems.exevmware remotemks
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware, Inc..exeVMware, Inc.
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMnetDHCP=VMware VMnet DHCP service for VMware Workstation. If you do not use VMware, this service can be disabled.
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: tVBoxService=Oracle's VirtualBox Virtual Machine service. If you do not use VirtualBox, this service can be disabled.iq`
Source: SmartPCOptimizer.exe, 0000000C.00000003.1392026070.00000000065BB000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 001C14VMware, Inc.;
Source: SmartPCOptimizer.exe, 0000000C.00000003.2500615100.000000000663B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: vmvctr6.exeVMware vCenter6
Source: SmartPCOptimizer.exe, 0000000C.00000003.2498149093.0000000006591000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: explorer.exe,vmware-tray.exeShell
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Process information queried: ProcessInformation Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6096C33C _winmajor,LoadLibraryA,GetProcAddress,GetProcAddress,FreeLibrary, 16_2_6096C33C
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: progman.exeA
Source: SmartPCOptimizer.exe, 0000000C.00000003.2499863229.00000000064E9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: progman.exeCS5YFRYIG0TV65APDE8=
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: progman.exe
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion ProductId Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-O0UIQ.tmp\SecuriteInfo.com.Program.Unwanted.5533.30107.22661.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: ALMon.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: procmon.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: mcagent.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: KavPFW.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: guard.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: hackmon.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: kav32.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: APVXDWIN.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: bdss.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: Ashwebsv.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2533654031.000000000768D000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: AVGnt.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: KAVStart.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: kavsvc.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: RAVMOND.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: avgemc.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: AVGEMC.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: iefix.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: QOELoader.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: MSASCui.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: kxetray.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: almon.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: RavTask.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: livesrv.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: PSIMSVC.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: Nod32.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: avgnt.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: KPFWSvc.EXE
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: Inicio.exe
Source: SmartPCOptimizer.exe, 0000000C.00000003.1643265911.0000000007889000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: ashServ.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: HijackThis.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: mbam.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: mcvsshld.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: op_mon.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: McUpdate.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: Drwebscd.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: nod32cc.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: mcvsrte.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: GDFirewallTray.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: AVKTray.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: nod32kui.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: KPFW32.EXE
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: emlproxy.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: nod32.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2533654031.000000000768D000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: AVGAMSVR.EXE
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: kav.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: KAV.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: avgui.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: nod32krn.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: MsMpEng.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: mcupdate.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: K7TSecurity.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: bdagent.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: avgas.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: avguard.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: APVXDWIN.EXE
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: Guard.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2533654031.000000000768D000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: zlclient.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: AVGuard.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: Kav.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: pg2.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: K7SysTry.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: EMLPROUI.EXE
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: Avgamsvr.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: pctsTray.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: ashDisp.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: avgtray.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: Nod32krn.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: nspsvc.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: PavFnSvr.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2529902132.0000000007110000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: ashmaisv.exe
Source: SmartPCOptimizer.exe, 0000000C.00000002.2527191299.0000000006F60000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: regmon.exe
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : SELECT * FROM AntiVirusProduct
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : SELECT * FROM FirewallProduct

Stealing of Sensitive Information

barindex
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqlite Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqlite-shm Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqlite-wal Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\SiteSecurityServiceState.txt Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SmartPCOptimizer.exe File read: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\Cookies.txt Jump to behavior
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095E09B sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_bind_value, 16_2_6095E09B
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095F08D sqlite3_malloc,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, 16_2_6095F08D
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094B05B sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,memmove, 16_2_6094B05B
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094A1DE sqlite3_bind_int64,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_malloc,sqlite3_reset,sqlite3_free, 16_2_6094A1DE
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_609661C7 sqlite3_value_text,sqlite3_mprintf,sqlite3_free,strcmp,sqlite3_free,sqlite3_malloc,sqlite3_bind_int64,sqlite3_step,sqlite3_column_type,sqlite3_reset,sqlite3_column_blob,sqlite3_reset,sqlite3_malloc,sqlite3_free,sqlite3_reset,sqlite3_result_error_code,sqlite3_result_blob, 16_2_609661C7
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094B1FC sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step, 16_2_6094B1FC
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094C159 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free, 16_2_6094C159
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6096914B sqlite3_bind_int,sqlite3_step,sqlite3_column_int,sqlite3_reset, 16_2_6096914B
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095F16D sqlite3_malloc,sqlite3_bind_int,sqlite3_step,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_bind_int,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,sqlite3_free, 16_2_6095F16D
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6090C16E sqlite3_clear_bindings,sqlite3_mutex_enter,sqlite3_mutex_leave, 16_2_6090C16E
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094B273 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step, 16_2_6094B273
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094A3AD sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset, 16_2_6094A3AD
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094C3D1 sqlite3_value_int,sqlite3_value_int,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_null,sqlite3_bind_null,sqlite3_step,sqlite3_reset, 16_2_6094C3D1
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6090F358 sqlite3_bind_parameter_index, 16_2_6090F358
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095F371 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_result_error_code, 16_2_6095F371
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_609654DA sqlite3_finalize,sqlite3_free,sqlite3_value_numeric_type,sqlite3_value_numeric_type,sqlite3_value_text,sqlite3_value_int,memcmp,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_strnicmp,sqlite3_mprintf,sqlite3_mprintf,sqlite3_malloc,sqlite3_free,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_bind_value, 16_2_609654DA
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094A444 sqlite3_bind_int64,sqlite3_bind_null,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, 16_2_6094A444
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6096250A sqlite3_stricmp,sqlite3_bind_int64,sqlite3_mutex_leave, 16_2_6096250A
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60969693 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset, 16_2_60969693
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60968614 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_malloc,sqlite3_malloc,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_realloc,sqlite3_realloc,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_free, 16_2_60968614
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6090573E sqlite3_bind_parameter_count, 16_2_6090573E
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60905750 sqlite3_bind_parameter_name, 16_2_60905750
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60969762 sqlite3_bind_int,sqlite3_column_int,sqlite3_step,sqlite3_reset, 16_2_60969762
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60966862 sqlite3_malloc,sqlite3_bind_int,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_reset,sqlite3_bind_int,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_malloc,sqlite3_bind_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_reset,memcmp,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_bind_int64,sqlite3_realloc,sqlite3_column_int,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_bind_int,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free, 16_2_60966862
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_609699C4 sqlite3_value_text,sqlite3_value_bytes,sqlite3_strnicmp,sqlite3_strnicmp,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_malloc,sqlite3_column_int,sqlite3_column_int64,sqlite3_column_text,sqlite3_column_bytes,sqlite3_finalize,sqlite3_step,sqlite3_free,sqlite3_finalize,sqlite3_strnicmp,sqlite3_bind_int,sqlite3_column_int,sqlite3_step,sqlite3_reset,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_column_int64,sqlite3_column_int,sqlite3_column_text,sqlite3_column_bytes,sqlite3_step,sqlite3_finalize,sqlite3_strnicmp,sqlite3_strnicmp,sqlite3_bind_int,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_value_int,sqlite3_malloc,sqlite3_bind_null,sqlite3_step,sqlite3_reset,sqlite3_value_int,sqlite3_value_text,sqlite3_value_bytes,sqlite3_free, 16_2_609699C4
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6091DA91 sqlite3_bind_zeroblob,sqlite3_mutex_leave, 16_2_6091DA91
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6090EA12 sqlite3_transfer_bindings, 16_2_6090EA12
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6091DBB8 sqlite3_mutex_leave,sqlite3_bind_text16, 16_2_6091DBB8
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6091DBE3 sqlite3_bind_text, 16_2_6091DBE3
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60961BE5 sqlite3_mprintf,sqlite3_vtab_config,sqlite3_malloc,sqlite3_mprintf,sqlite3_mprintf,sqlite3_errmsg,sqlite3_mprintf,sqlite3_free,sqlite3_mprintf,sqlite3_exec,sqlite3_free,sqlite3_prepare_v2,sqlite3_bind_text,sqlite3_step,sqlite3_column_int64,sqlite3_finalize,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_errmsg,sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_free,sqlite3_mprintf,sqlite3_free,sqlite3_declare_vtab,sqlite3_errmsg,sqlite3_mprintf,sqlite3_free, 16_2_60961BE5
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095EBEC sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 16_2_6095EBEC
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60967B7D sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_column_int64,sqlite3_reset,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free, 16_2_60967B7D
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095EB67 sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, 16_2_6095EB67
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6091DCCD sqlite3_bind_int,sqlite3_bind_int64, 16_2_6091DCCD
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6091DCF3 sqlite3_bind_double,sqlite3_mutex_leave, 16_2_6091DCF3
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_60964C1A memcmp,sqlite3_realloc,qsort,sqlite3_malloc,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_step,sqlite3_reset, 16_2_60964C1A
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6091DC0E sqlite3_bind_blob, 16_2_6091DC0E
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6091DC39 sqlite3_bind_null,sqlite3_mutex_leave, 16_2_6091DC39
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095EC78 sqlite3_bind_int64,sqlite3_bind_int,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, 16_2_6095EC78
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6091DC6A sqlite3_bind_int64,sqlite3_mutex_leave, 16_2_6091DC6A
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095EDA2 sqlite3_bind_int,sqlite3_step,sqlite3_column_type,sqlite3_reset, 16_2_6095EDA2
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6091DD64 sqlite3_bind_value,sqlite3_bind_int64,sqlite3_bind_double,sqlite3_bind_blob, 16_2_6091DD64
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6095EF8D sqlite3_value_int,sqlite3_bind_int,sqlite3_bind_value,sqlite3_step,sqlite3_reset, 16_2_6095EF8D
Source: C:\Program Files (x86)\Smart PC Solutions\Smart PC Optimizer\SPONotifications.exe Code function: 16_2_6094AF16 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, 16_2_6094AF16
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs