Dropped Files | ZeroBOX
Name 8a791ce74b32d03e_googleanalyticshelperiv.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\GoogleAnalyticsHelperIV.dll
Size 248.4KB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 1c180d536028d241c1b1c8faae8186f0
SHA1 eeaec8b2e3f084ef9fd3ce1fe57a36585196e364
SHA256 8a791ce74b32d03e012df85dded1282baf0d62cb7d251a67ad4119c4d2ebfe32
CRC32 EEA83BB1
ssdeep 3072:lJr2pBvssBjFgfKzC3Hhz6nB0vjfE+9+WVP1uDVwG0B+T8xR24G9sqYaXQj7/k7O:72phJpW3Yn8/V9uDVwlNxR2PEaXQItI
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name 8051478fc68a438e_browserhelper.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\BrowserHelper.dll
Size 1.6MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 1f258a55db7463e3634cb92518cc5a99
SHA1 9bffdc6c6f860d0f42baf9851d47650ae0103df8
SHA256 8051478fc68a438e0983e0a3b6d5bc842553d3255e7fc0bbdc7511c47492df5e
CRC32 9D9370A3
ssdeep 12288:EuAo7WpN8S1SVA3pBaKIecHAxdyXbF6PfTleExBRAWPt+u3V+QiF3pwHPHo9waa7:VAoCeS1IdKIekUjleExPAb8PHlXXL
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name e2c737e9fd38ce62_checkserialnumber.log
Submit file
Filepath C:\ProgramData\Outbyte\PC Repair\1.x\Logs\CheckSerialNumber.log
Size 940.0B
Processes 2764 (Installer.exe)
Type Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
MD5 65121151fd845c86ab250fbd9eb5b3c9
SHA1 fb15366633fc6a93291b8aeb4385e5411b54a3f1
SHA256 e2c737e9fd38ce62f927429c534328c525b4987e95fd5de8657788734336b0de
CRC32 9E539C6A
ssdeep 24:QDhd1OQb41WqarwhQMnOSlURWFTtMnOpNIlc:wu1a0nOf8FKnOTYc
Yara None matched
VirusTotal Search for analysis
Name 7af4101dd2c1ccde_installer.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Installer.exe
Size 3.1MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 c8fcce141f1a49cb00d6e3425344fcb7
SHA1 632d3f236f74d6edf76322d1a2070a18a8903066
SHA256 7af4101dd2c1ccdef5f1f81d70a8b956c13156d238af5704ba5a9d510bae2ad7
CRC32 83A7BF31
ssdeep 49152:tsu5yuJ2k32mVObwJntytXTlKLICBvETWr2kujG7KAmnkhFnw35q:tsEyuYkm9wMgvETW9BKHMq5q
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 3a0495160e2d1692_rtl250.bpl
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\rtl250.bpl
Size 10.1MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 ef5c969b767e8e21a99f1487351750b2
SHA1 c5246c4fc8e636de0ac11931b3ecec4a7add0b44
SHA256 3a0495160e2d169274838fdc72cf5b8a8c6c0300b603ebbacd08a51427ca1fde
CRC32 9A2DD9DB
ssdeep 98304:3rPcd7oJhMeF+JH4m3r3PtjvcHZKbcX/d+XuJSLuB:3Q1ZJYe3P9c9PzW8
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • IsDLL - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • ftp_command - ftp command
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name df59bc4f5de8f99b_vcl250.bpl
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\vcl250.bpl
Size 3.9MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 5dcfee9dc4ee87099c955b40c47f3a10
SHA1 876a6af45b4a213587d1239ccad7871041839bc5
SHA256 df59bc4f5de8f99b96010d9b0d8eaff43d15c63e20204bf235267f7b3e804587
CRC32 0C4BF782
ssdeep 49152:u3WQ4ED/9aSr4TUpgZmhXQIP2mrzwFrAj7Bo0kL3udI+Wl:uGQkTofzuAj7BhAF
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name 512e4e95427a8c66_$$$Cookies162002093
Submit file
Filepath C:\ProgramData\Outbyte\PC Repair\1.x\$$$Cookies162002093
Size 36.0KB
Type SQLite 3.x database, last written using SQLite version 3021000
MD5 f4c540f52d5c08d24a79805eda1d7abf
SHA1 22be46826df7693f58736adb232ab2da790f2571
SHA256 512e4e95427a8c66b2993b27bb23d99cdab2ebd6e9e8937c7f6a39ed8c6a5b94
CRC32 95C9FB3A
ssdeep 24:TLmg/5UcJOyTGVZTPaFpEvg3obNmCFk6Uwcc85fB34444z:T5/ecVTgPOpEveoJZFrU1cQB34444z
Yara None matched
VirusTotal Search for analysis
Name 3ca7a122d8dc1141_rus.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\rus.lng
Size 775.8KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 f4b3dda42b6b6009adbab38123f44e61
SHA1 c69b8cb9bcc31307aa28be202cc4f1eedf473b79
SHA256 3ca7a122d8dc1141f046c32c7f6bf1cfc3923fcd58297e79ff5ce3718724f37f
CRC32 7D5A55D7
ssdeep 3072:YDcypa1EAtd3nXLVr4jdbk5pF77nJhMXnFz47M3n6dmpDoRfGyBAXbbpFD8HWFHb:Yta1827vTdKr0jIjeOzxUU
Yara None matched
VirusTotal Search for analysis
Name 2b6a979a04082ff7_pcrepair.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\PCRepair.exe
Size 10.5MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 6b77404f4885997ff2bcd77079f29990
SHA1 cf0556f36c89c46877266f676c037bd00f302f78
SHA256 2b6a979a04082ff79ab9805c29f92df0e9b8ea3ba384c585727d2c56728ab62e
CRC32 1F12118A
ssdeep 196608:TWa5/06DtsPl+MyZVAnPx/ptXI2KpG9khWmMaF:TWa5/06gl+MyZunPx/pVI20k0
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • Antivirus - Contains references to security software
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name db8a61756c371c76_plk.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\plk.lng
Size 780.6KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 db1d15c2804d32279968330ea0afc616
SHA1 d5b74d4ec67a4ef4d11f8b0db5b6774ee63b88b5
SHA256 db8a61756c371c76f8ad4b1da88fa7b91cf9f4b548b12b014c13f72a14b424cf
CRC32 D0C6BB5A
ssdeep 3072:Vuf3CpAaaZrAtd3nXLVr4jdbk5pF77nJhMXnFz47M3n6dmpDoRfGyBAXbbpFD8Hg:HAxPyj5Y1TIEZNPqa0i+GWpzxcKzne
Yara None matched
VirusTotal Search for analysis
Name b1462be4eb64564d_googleanalyticshelper.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\GoogleAnalyticsHelper.dll
Size 126.4KB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 e14233d78602dae69c0206caefaaeacb
SHA1 29b1078a47797a3bb37be0fe9b5b4047e1399d84
SHA256 b1462be4eb64564dbecba83f560ce406067f45029c2ca5dda0a6179591080a79
CRC32 6C94FD39
ssdeep 3072:d4CcT7XH6E6V3pFcVFK5NPsqYaiJj7/Apy7xR:GCYXLw3AVIeaiJSy3
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 26270a9091eaa412_localizer.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Localizer.dll
Size 189.4KB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 6a42a1ed51b1b38c2852e494621c5c23
SHA1 090d5f922f5fa09ceaacd7089db5f040aba727f7
SHA256 26270a9091eaa4123f113161cd61376cf1720a56a52c2c0b9056aa0049af0b01
CRC32 FF5B2C90
ssdeep 3072:8u2BNY/BvSXCv6cAv6bVUenRV4xJrIrT4XMDWQsqYaBej7//S8wT:abFbvkVjnRVtrkXoWBaBea7
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name 1a0edd4be6f74b1d_setuphelper.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\SetupHelper.dll
Size 3.2MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 5ff89e1e693481156d601f1ff5a48a02
SHA1 af2a0233bcd7ac719b4af3c1d18636965620b6ef
SHA256 1a0edd4be6f74b1d8a996e27ce7db50a7992b496270d924426fac251833f3735
CRC32 6A97AC2B
ssdeep 49152:WpRN7YRRspwvkiVhTHITkeABK6OSCDxioNY28WkMD3PTF:oRZIRshiVpIYISCDxiAj1Db
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 88984c1f3c30f67b_installerinternal.log
Submit file
Filepath C:\ProgramData\Outbyte\PC Repair\1.x\Logs\InstallerInternal.log
Size 6.9KB
Processes 2764 (Installer.exe)
Type Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
MD5 2665dbb6bbae85c268760f3e7c13b58a
SHA1 33784a5e0cb70cb5c5b105dc6def130c1216ffe8
SHA256 88984c1f3c30f67bc89820f3d8759e8ad0fe4cecc3395006a859fa27e416626e
CRC32 6CC51EBA
ssdeep 192:qF6jPEquihC49L7OqNSRoLVNwNyZbuEbl6Wb:pFt
Yara None matched
VirusTotal Search for analysis
Name bf2dc7f26d71c6d7_oxcomponentsrtl.bpl
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\OxComponentsRTL.bpl
Size 1.2MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 11f19273ee96c0405c7e3af9c47d6926
SHA1 b4c18d87a465f79ae4b83390cc631efaa9ea25fb
SHA256 bf2dc7f26d71c6d77e52068b5adf199f3180d929a9301c010c3433be79ed1f61
CRC32 1404DAD7
ssdeep 24576:kWUPREgVkraPPPonN55wx+Nh0UdaDIYnw2:kjnkqPopw2qnV
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 3243b33e4e6ef0fa_sqlite3.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\sqlite3.dll
Size 1.1MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 dd65295b4d221f8a837855bd5c829bd6
SHA1 bc7495c3b493feb412ae6ec7d8f3da4db84ca563
SHA256 3243b33e4e6ef0faa1997bd54113f94cc9a88a4fb1dfb7af16993085bffc6cad
CRC32 33691CA4
ssdeep 24576:kj58dSY2wv5a4GhotORJB3gbta/k9DEO1q:kjqP2wxpG8ORJB3AtFwd
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name abc49861c2ed90bc_ptb.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\ptb.lng
Size 808.3KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 7bc483969b86c5dfbedf80f19885bb6f
SHA1 9a81a800574a8a392c008d7d3df529c6d672f8ea
SHA256 abc49861c2ed90bcccc49c03cf68d53f3878d10a026dcc779a4d59d229dbfb30
CRC32 902D9BB9
ssdeep 3072:TZhCU9aD/pzG9Atd3nXLVr4jdbk5pF77nJhMXnFz47M3n6dmpDoRfGyBAXbbpFDJ:giHreT5EUhqhzxSA
Yara None matched
VirusTotal Search for analysis
Name 9580897707dc8024_deu.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\deu.lng
Size 837.3KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 b1202f383797e6a8a38419016f5906b2
SHA1 7d1a0a4d20fd220ab85c5ab502083e0755045320
SHA256 9580897707dc8024470bed4c030c602784d27d8e7a1b4c4d1ef9d7b31c9b9486
CRC32 D46FBB19
ssdeep 6144:oOO2tqBgGB6TVl9tMNT03+LzUOzxEcx7OZ:lRGBkl9tST03+LwOzCcx7OZ
Yara None matched
VirusTotal Search for analysis
Name b2d07cd0699a2e19_cfahelper.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\CFAHelper.dll
Size 94.9KB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0ac8215fe2165ad026e003e09fd5091f
SHA1 24f3fe37e8575bf9d6286ff35e53571b4e1f2d86
SHA256 b2d07cd0699a2e195e14aa4f670a1a878c4d14d76206585b709fae8d9acc69ab
CRC32 A7BBFB08
ssdeep 1536:Iu3Na6z5PVSr7BesdVdCOgDoqYaEjqY/CIJ27Hx+bY7nvxm:pNrYrlesdVmsqYaEj7/CIwsbY0
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name d11d5ef3a6851a0a_vclie250.bpl
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\vclie250.bpl
Size 1.0MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0a4e342a0c5da35a5effc92b96180578
SHA1 f984babeea425acfdc6878e60b0ff9d91cfd915c
SHA256 d11d5ef3a6851a0a4bc71153251c980d67eb2ab6b9cbc64d43a01a48c6f250c8
CRC32 6E532B05
ssdeep 24576:sFo/3f7F/ti9VcGJp1HbrqSJIMGCsw3QvE/:sFo/5c9VFVfN9
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name 25bdd6871f8acbee_ita.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\ita.lng
Size 831.2KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 5994a2ef0127ae4412c47e29cf254879
SHA1 41c08ac82d2a4cf5acaaa4cff4d28da6e6300c41
SHA256 25bdd6871f8acbee1d406065fc95795f7c2311da0d14afacb701b32debdfa67e
CRC32 364EBDEA
ssdeep 6144:mpYzSYWqRJY8FTnCe3cy+gU83QNz5stzxzV2lmRHh/oE6jcF:HzSb4zd
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name c086601f0b401d83_downloader.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Downloader.exe
Size 250.4KB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 8a7a2c037b63d537129e3630ac55ccfc
SHA1 b555272282282fe88fc804299167a0397e32092d
SHA256 c086601f0b401d830460307882fe3bdadb6c35f132fbd85e17199f0f959427c4
CRC32 41A9904A
ssdeep 3072:rDTipsw/kW03t0j5sZRI4U9O5W0NKgQ34fYLGNUfh5XJW11s7aEoCBxWmSaoouQ0:rDTusrFFR52YUJz2uLJWEXNLMalK
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name 1bd142429a177675_jpn.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\jpn.lng
Size 591.5KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 a850e601995d546afe48fc9367554ea0
SHA1 54d653b888ac9164df19b8234cc3b92f2e98effb
SHA256 1bd142429a177675f163a1170467639bbd3a2b4519c6b846c67c9663db570104
CRC32 43866D4A
ssdeep 6144:Ob3Xn/ioxSlXzFDMNrMxTaTUSmJ47iJzxDhTeBsJT:KXxxSlp6OhJzL6W
Yara None matched
VirusTotal Search for analysis
Name 7a9abe88b927f65f_axcomponentsvcl.bpl
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\AxComponentsVCL.bpl
Size 7.7MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 36bff4a5fd39eeb48af128d1ae0b4079
SHA1 6e20aac952d026582ffea4e8cd326473405b1337
SHA256 7a9abe88b927f65f12dc469e29e56e4424847459360465dac95368824e8ca297
CRC32 2B5C29C7
ssdeep 196608:pjpfHrCAGhK9S19behy0HCfvLZlNYNDFFhAL:pFfHrM9FkCfVlNYR3h0
Yara
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 2dab13dd98e252f4_enu.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\enu.lng
Size 750.2KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 3ea629679d7c0a5884898f74773c0f7e
SHA1 55c5044a74409b5bfffa4c8bd9fcab95596d9cf2
SHA256 2dab13dd98e252f4ca38fffc32f5edc54aa19b7fda601c02c97d6d80b70f8777
CRC32 B83F5989
ssdeep 3072:mn8VRtR8pb4Atd3nXLVr4jdbk5pF77nJhMXnFz47M3n6dmpDoRfGyBAXbbpFD8Hh:mjbg4SpVFTmiaNgM0YU5Vzxc3hGu
Yara None matched
VirusTotal Search for analysis
Name 6498487c9b065a52_trk.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\trk.lng
Size 773.6KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 b32e87588ce1ce710fe6e26c82f0e260
SHA1 752992a7125c90185e9a2aadacbc1399a3ed5616
SHA256 6498487c9b065a5276759b854c502fb7ee69653dad8421bc7d8a25e9a556ed30
CRC32 5AED6C2F
ssdeep 6144:6u0k/frc6C3MWHAWWzeTdpeE31uJNAyGjzxcWqMr:fzurr8zOHjzV
Yara None matched
VirusTotal Search for analysis
Name e701059a0fb7c07a_fra.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\fra.lng
Size 853.8KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 4ba6dfcd3ff97ed995786787e8c97beb
SHA1 500431b2c18b0bec73894301ccff8c5cb33dbecb
SHA256 e701059a0fb7c07a0160a6bd935db680a0f4d47b9897c689834a5f784e48bc12
CRC32 C4C6D3C0
ssdeep 3072:rm2ijn1pehAtd3nXLVr4jdbk5pF77nJhMXnFz47M3n6dmpDoRfGyBAXbbpFD8HWs:oefV3PTZJmwqdgsnzx3
Yara None matched
VirusTotal Search for analysis
Name 61f63580e416eb8a_$$$Databases.db162002109
Submit file
Filepath C:\ProgramData\Outbyte\PC Repair\1.x\$$$Databases.db162002109
Size 28.0KB
Type SQLite 3.x database, last written using SQLite version 3021000
MD5 6789f45721e36b5d9a809917fe2a52fe
SHA1 a53a8189104c0d9da71c39fe2e6a392876984298
SHA256 61f63580e416eb8a2c3c0b43ce1f8921d88852fa32c114261dc328e0714a6878
CRC32 06DC704E
ssdeep 12:TLiqidnGb0EiDFIlTSFbyrKZb9YwFOqAyl+FxOUwa5qgufTJpbZ75fOSG:TLi+NiD+lZk/Fj+6UwccNp15fBG
Yara None matched
VirusTotal Search for analysis
Name ef67739a6185887f_axcomponentsrtl.bpl
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\AxComponentsRTL.bpl
Size 1.8MB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 f19d5357eb5d5134ccd5a3254ba15dbe
SHA1 4df876e15db9e97f2d68050d063bb98f1cc47b0e
SHA256 ef67739a6185887fcae286818b1091a8f3bbbe9aca1eb4c61e1d43040c3adbf8
CRC32 3CAB72BE
ssdeep 24576:RfLpu1ZnH//lZDBhpHBqj59qsm2N1Y+ehUKIcnafB:1p4RVZphqj59XDYfUKIcnK
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name d8dd31d0e9143574_$$$Origin Bound Certs162002093
Submit file
Filepath C:\ProgramData\Outbyte\PC Repair\1.x\$$$Origin Bound Certs162002093
Size 20.0KB
Type SQLite 3.x database, last written using SQLite version 3021000
MD5 9efa338a15d99d483854e316bc0ead9f
SHA1 88633f6faeff30564e1f7828167f27255f761b2d
SHA256 d8dd31d0e9143574615f2f2dde71f156fd9da29c5fe5495c1f0c79199b0b5fc4
CRC32 27C65DFD
ssdeep 12:TLzIJvcg38AbbDJZYlo0FxOUwa5qguS60hZ75fOSu0MM:TL8JvkA1Glr6UwccK5fBlMM
Yara None matched
VirusTotal Search for analysis
Name 7588d3b4944d6d64_vclimg250.bpl
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\vclimg250.bpl
Size 363.4KB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 18248f0a800d184a1dfaa653ee92f8c3
SHA1 6aa948bd2b56e8171e931f47747409d5036b19d2
SHA256 7588d3b4944d6d6443f5905fa3b42568fe7cfcd72991289f70299b9db3974bfa
CRC32 BD4C313C
ssdeep 6144:TdJVpo6Pb6So4ZmCY6wAnAGgDPFLYU1hHXRn5c1zOVFvdcy3q:TNpNhmN6dAGgDtz1hHXx8zuvdcya
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name 0f903120b2abf37c_commonforms.site.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\CommonForms.Site.dll
Size 336.4KB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 72ff87971b0478b0d9e89cab0eb8b11b
SHA1 71db22fa9b1dc784b72509dba31a16076a0899cf
SHA256 0f903120b2abf37ccd568f45e789fca88f67cc4c3b70d852d2af9809bb2c57fe
CRC32 2229764B
ssdeep 6144:ZcO6ThVQN3YEbQa4l1VXVu3RCa47avjGnawKn/hy/O6P4:j6ThCN3JbQa4l9u3RCaeavjxrc/5w
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name f5db91b086ab2ecd_installerutils.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\InstallerUtils.dll
Size 910.9KB
Processes 2636 (outbyte-pc-repair.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 f67e9ed9d329d6fa58ddcbaf8908c9d2
SHA1 3e5627201f7185635ce1f8fd03be5ea1078afae2
SHA256 f5db91b086ab2ecd3ec592e496dd2e912b3c6392aef839219afe8ce359daf435
CRC32 01529BA7
ssdeep 24576:CnlI+x+ZCAPB46o6sCrhsg4ldubXhfJEy:Gpkt46o6sCrhsg4ly
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 848fe1ff9900e282_esp.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\esp.lng
Size 833.0KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 df493d46fa1c33585eca4fd91ca138ec
SHA1 f799c5329a53484d193d33c8904c798d0011e793
SHA256 848fe1ff9900e2820fa817052f2569bd17dad3fd74f4f66f0fb8d6a3f8df0722
CRC32 B42206BE
ssdeep 6144:6AW/6tVVck45bWf2DlDl73iiyqTYXA+I80nNnuyAdij3nUagul5qsYzxPmVjLZur:tBLzZ
Yara None matched
VirusTotal Search for analysis
Name d01e22915a124796_main.ini
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Data\main.ini
Size 2.2KB
Processes 2636 (outbyte-pc-repair.exe)
Type ISO-8859 text, with CRLF line terminators
MD5 d2e6586d1e57acfbc658cb5276cc8efc
SHA1 0f925c71177348c2d066b623712cdb5465948afc
SHA256 d01e22915a124796fd749acaaab18fe23cc60aac126e6e5f3807e53bc4c65921
CRC32 C229D762
ssdeep 48:t1Aip3JknDknAfCpwuSpUQsezAO9ATkVia:t1np5knDknCuglsezAO92kka
Yara None matched
VirusTotal Search for analysis
Name 2cab2dd825e26fae_dan.lng
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\Lang\dan.lng
Size 766.6KB
Processes 2636 (outbyte-pc-repair.exe)
Type data
MD5 9291c0b3eed2e4fd8747b75958afce3b
SHA1 61c734f3097cce2ee4a3dd99aa1bfe1da497e37c
SHA256 2cab2dd825e26fae7b4f9c813a13ed610d408718848205ae32ead769e2933a8c
CRC32 BFB80FD6
ssdeep 3072:ebQpm4/1iLLGXmHZ0sNFpChAtd3nXLVr4jdbk5pF77nJhMXnFz47M3n6dmpDoRf1:sQxalJTptovt3RdzxcDvGM
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 388a796580234efc__setup64.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-14082807.tmp\__setup\_setup64.tmp
Size 6.0KB
Processes 2764 (Installer.exe)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 e4211d6d009757c078a9fac7ff4f03d4
SHA1 019cd56ba687d39d12d4b13991c9a42ea6ba03da
SHA256 388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
CRC32 2CDCC338
ssdeep 96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis