PUP.Advance System Care

Threat Scorecard

Popularity Rank: 12,903
Threat Level: 10 % (Normal)
Infected Computers: 965
First Seen: March 27, 2019
Last Seen: November 14, 2025
OS(es) Affected: Windows

File System Details

PUP.Advance System Care may create the following file(s):
# File Name MD5 Detections
1. 1.0.0.2509_ascsetup 12.27.17.exe 20b872df4f82905ba4826c27cad2081a 20

Analysis Report

General information

Family Name: PUP.Advance System Care
Signature status: Self Signed

Known Samples

MD5: 7bc499c82eedaecad3d5b8ea2d382762
SHA1: 56354e644c5b126a92b3d031ffcf427bbf485406
SHA256: D0C58212890E9CC10EE6A42533CE67734F31B39B6C40C86EBD3075E8B7270146
File Size: 4.65 MB, 4652720 bytes
MD5: ffc5e75abb799772ff31bdb89b307825
SHA1: f488ba2fefa846ad06b1debcd75411b7ea06bc85
SHA256: 02F32FDA16669C93C8B0AC500E492ADF4E588866D40A5816A74C9E3785C2232B
File Size: 5.87 MB, 5872064 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name
  • AdvancedPasswordManager.com
  • globalpcworks.com
File Description
  • Advanced Password Manager
  • System Care
File Version
  • System Care
  • Advanced Password Ma
Product Name
  • Advanced Password Manager
  • System Care
Product Version
  • 1.0.0.11457
  • 1.0.0.6807

Digital Signatures

Signer Root Status
Advanced PC Tools COMODO RSA Code Signing CA Self Signed
PC Speedup Tools COMODO RSA Code Signing CA Self Signed

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-4p7rf.tmp\56354e644c5b126a92b3d031ffcf427bbf485406_0004652720.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bd92d.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bd92d.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-bd92d.tmp\isxdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-dr218.tmp\f488ba2fefa846ad06b1debcd75411b7ea06bc85_0005872064.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-o3bg8.tmp\_isetup\_iscrypt.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-o3bg8.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-o3bg8.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-o3bg8.tmp\isxdl.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ﰰ䕱ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 璜ⲯ喰ǜ RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess

Shell Command Execution

"C:\Users\Ytrateso\AppData\Local\Temp\is-4P7RF.tmp\56354e644c5b126a92b3d031ffcf427bbf485406_0004652720.tmp" /SL5="$301FE,4145773,148992,c:\users\user\downloads\56354e644c5b126a92b3d031ffcf427bbf485406_0004652720"
open taskkill.exe /f /im "gpcw.exe"
WriteConsole: ERROR: The proce
open taskkill.exe /f /im "GPCWValidatorService.exe"
open taskkill.exe /f /im "appmanager.exe"
Show More
"C:\Users\Ywdaqstw\AppData\Local\Temp\is-DR218.tmp\f488ba2fefa846ad06b1debcd75411b7ea06bc85_0005872064.tmp" /SL5="$70068,5330239,180224,c:\users\user\downloads\f488ba2fefa846ad06b1debcd75411b7ea06bc85_0005872064"
open schtasks.exe /delete /tn "Advanced Password Manager_launcher" /f
open taskkill.exe /f /im "apmui.exe"

Trending

Most Viewed

Loading...