PUP.DialupPass.A

The detection of PUP.DialupPass.A on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take prompt action to remove it. In this report, we will provide you with an overview of PUP.DialupPass.A, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is PUP.DialupPass.A?

PUP.DialupPass.A is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They often come bundled with other software or are downloaded from the internet, and can be difficult to remove once installed.

How PUP.DialupPass.A Operates

PUP.DialupPass.A, like other PUPs, may operate by collecting user data, displaying unwanted advertisements, or modifying system settings without permission. It may also install additional software or toolbars, which can further compromise your system's security and performance. PUPs often use deceptive tactics to install themselves on a system, such as bundling with other software or using fake updates to gain access to a system.

Symptoms of Infection

If your system is infected with PUP.DialupPass.A, you may notice a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and changes to your browser settings or homepage. You may also notice that your system is crashing or freezing frequently, or that your internet connection is slower than usual. In some cases, PUPs can also collect user data, such as browsing history or personal information, without consent.

  • Unwanted changes to browser settings or homepage
  • Slow system performance or crashes
  • Unwanted pop-ups or advertisements
  • Collection of user data without consent
  • Installation of additional software or toolbars

How to Remove PUP.DialupPass.A

  1. Boot your system in Safe Mode with Networking to prevent PUP.DialupPass.A from loading and to allow for a safe removal process.
  2. Use a reputable malware removal tool, such as SpyHunter, to perform a full scan of your system and detect any malware or PUPs.
  3. Uninstall any suspicious programs or software that may be related to PUP.DialupPass.A.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by the PUP.
  5. Reboot your system and perform another scan with your malware removal tool to ensure that PUP.DialupPass.A has been completely removed.

Conclusion

Removing PUP.DialupPass.A from your system requires a combination of technical knowledge and the right tools. By following the steps outlined in this report, you can help to ensure that your system is free from this potentially unwanted program and any related malware. It's essential to remain vigilant and take steps to protect your system from future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading software or clicking on links from unknown sources.

Analysis Report

General information

Family Name: PUP.DialupPass.A
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 0481d2e281d173aee1ad883b1bc0c255
SHA1: e1c7b220e5b3d916bca4e8f58134d209cd68a4aa
SHA256: 572F3DEC8FBE7CA65B3335020F1A4F7BA715557460FBACC7C7338247D36BE3DF
File Size: 8.31 MB, 8312320 bytes
MD5: 0771acdc653eac4383109dea220ad25c
SHA1: 0640d2e845ef8619f48b6a4cec2234cfa915faec
SHA256: 53D18AC64A1F7607FEB8B3A4495DA6A4543CA25BC2A964F2E86F0C7377A502F3
File Size: 237.80 KB, 237800 bytes
MD5: f89c093212db6bce05d6767626407f03
SHA1: 23a429e86fe99f73de394f0d56de1a2c74e47c3e
SHA256: 298785131AC5D295BBC2BAFF9F7DDFD1162A0CEE1176FF7168F7A97A471B5634
File Size: 4.45 MB, 4452760 bytes
MD5: 404db851c8bd23df4898c76d87ee588e
SHA1: 0b567e165db957fa4aeed47971efb60358c6b20e
SHA256: 1E92B5E313F6DB5946F98F8B005FAB77483A162B7BD9362CCBC9FFE141811B08
File Size: 745.19 KB, 745186 bytes
MD5: 3f51b915918b6610850bcdcd1d09d437
SHA1: fa377e2ba8903962766a335584be44e9ed9f6eb1
SHA256: C590D921CB884A36CB71893B181DAB45F0FAF7B73FE1D91101E971C237508D81
File Size: 239.67 KB, 239674 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • PE2.0 Cd open
  • Utilitaire de conversion d'image en Splash Screen TomTom avec Iview32.exe
Company Name AutoIt Team
Compilation Date 18/06/2007
Compilation Heure 02:34:45
Compiled Script AutoIt v3 Script : 3, 2, 4, 9
Créer Par Tlem
Email tlem@tuxolem.net
Entreprise Tuxolem Software
File Description
  • AutoIt v3 Setup
  • Créateur de Splash Screen TomTom
  • FastStone Capture三哥汉化分享
  • Simple CDROM open sw
File Version
  • 9.1.0.0
  • 3.2.4.9
  • 3, 2, 4, 9
  • 1.1.0.0
  • 1.0.0.0
Legal Copyright
  • (c)1999-2007 Jonathan Bennett & AutoIt Team
  • Copyright (C) 2003 - 2007 Tuxolem Software
  • Copyright (C) 2019 by FastStone Soft
Nom Interne TomTom Splash Screen Creator
Product Version 3.3.9.4
Version Du Compilateur AutoIt v3.2.4.9

Digital Signatures

Signer Root Status
Belgacom GlobalSign Root CA Root Not Trusted
Jonathan Bennett GlobalSign Root CA Root Not Trusted

File Traits

  • Autoit
  • big overlay
  • HighEntropy
  • packed
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 1,505
Potentially Malicious Blocks: 785
Whitelisted Blocks: 717
Unknown Blocks: 3

Visual Map

x x 0 x x x 0 0 x 0 0 x x 0 x 0 x x x x x x x x x x x x x x x x x x x 0 x x 0 x x x x x 0 0 x x 0 x x x 0 x x x x x x x x x x 0 0 x 0 x x x x x x x 0 0 x x 0 x 0 x x x x x x x x x x x x x 0 x x x x 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x 0 x x 0 x x x x x x x x x x x 0 0 0 0 0 0 0 x 0 0 0 x x x 0 x x x x 0 0 x x x x 0 x 0 0 0 0 x x x x 0 x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x x 0 0 x 0 x 0 x x 0 0 0 0 0 0 x x x x x x x x x 0 0 x x x x x 0 x x x x x 0 x 0 x x 0 x x x x 0 0 0 x x 0 0 0 x x x x x x x x x 0 x x 0 0 x x 0 x x x 0 0 x x x 0 x 0 x x x x x x x x x x x x x x 0 0 x x x x x x 0 x 0 x x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 x x x x x x x x x x x x x 0 x x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x x x x 0 x x x 0 x 0 x x x 0 0 x x 0 0 x x x x x x x 0 x x x x 0 0 x x 0 x x 0 0 x x x 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 x 0 x x x 0 x 0 0 x 0 0 x 0 x 0 0 x 0 0 0 0 x x x x 0 0 x x x 0 x x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x x 0 0 0 0 x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 x x 0 x 0 0 x 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x 0 0 x x 0 x x 0 x x x x 0 x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x 0 x x x 0 x x x x 0 x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x 0 x 0 0 0 0 x 0 x 0 x x x x 0 x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x x 0 x 0 0 0 x x 0 x x x x x 0 0 0 0 x x 0 0 x 0 x x x 0 x 0 x x x 0 x 0 0 0 0 x x 0 0 x x 0 0 x 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 1 0 0 0 1 0 0 0 0 1 0 1 0 1 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Autoit
  • BadJoke.FH
  • DialupPass.A
  • Sohanad.B

Files Modified

File Attributes
c:\users\user\appdata\local\temp\aut363e.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut364f.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut37a8.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3816.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3836.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3857.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3896.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut38d6.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3a1f.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\aut3a7e.tmp Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\aut579e.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\autad5f.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\eject.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\i_view32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\i_view32.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\iodefaultopen.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsca8cf.tmp\iodefaultopen.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\iopreviousversion.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsca8cf.tmp\iopreviousversion.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsca8cf.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\modern-header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca8cf.tmp\userinfo.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsna8bf.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\portable faststone capture rus Synchronize,Write Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fsc.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fsc.db Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapture.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapture.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapture.rus Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapture.rus Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapturehelp.chm Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapturehelp.chm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapturehelp.chm.bak Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\portable faststone capture rus\fscapturehelp.chm.bak Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fscrosshair.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fscrosshair.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fsfocus.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fsfocus.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fsrecorder.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fsrecorder.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\fsrecorder.rus Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\fsrecorder.rus Generic Write,Read Attributes
c:\users\user\appdata\local\temp\portable faststone capture rus\portable.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\portable faststone capture rus\portable.db Generic Write,Read Attributes
c:\users\user\downloads\0640d2e845ef8619f48b6a4cec2234cfa915faec_0000237800.manifest Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\0640d2e845ef8619f48b6a4cec2234cfa915faec_0000237800.manifest Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\supportsoft\providerlist\belgacom::ldrrestart manifest RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserName
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
Other Suspicious
  • SetWindowsHookEx
Keyboard Access
  • GetAsyncKeyState
  • GetKeyState

Shell Command Execution

C:\Users\Vljeakzb\AppData\Local\Temp\Portable FastStone Capture RUS\FSCapture.exe
C:\Users\user\downloads\0640d2e845ef8619f48b6a4cec2234cfa915faec_0000237800

Related Posts

Trending

Most Viewed

Loading...