PUP.DisableDefender
The detection of PUP.DisableDefender on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.
Table of Contents
What Is PUP.DisableDefender?
PUP.DisableDefender is a type of malware that is designed to disable or weaken the defenses of your computer, making it more vulnerable to other types of threats. This can include disabling antivirus software, firewall protection, and other security features that are meant to protect your system from harm. PUPs like PUP.DisableDefender are often bundled with other software or downloaded from the internet, and they can be difficult to detect and remove without proper tools and expertise.
How PUP.DisableDefender Operates
PUP.DisableDefender operates by exploiting vulnerabilities in your system's security features, allowing it to gain unauthorized access and make changes to your computer's settings. This can include modifying system files, registry entries, and other critical components that are essential to the proper functioning of your computer. Once installed, PUP.DisableDefender can also communicate with its creators or other malicious servers, allowing them to remotely control your computer and steal sensitive information.
In addition to disabling security features, PUP.DisableDefender can also display unwanted advertisements, collect personal data, and slow down your computer's performance. It can also create backdoors for other types of malware, making it easier for them to infect your system.
Symptoms of Infection
If your computer is infected with PUP.DisableDefender, you may notice a range of symptoms, including slow performance, unwanted pop-ups and advertisements, and unexpected changes to your system settings. You may also notice that your antivirus software is disabled or not functioning properly, or that your firewall is not blocking suspicious activity. In some cases, you may not notice any symptoms at all, which is why it's essential to regularly scan your computer for malware and other types of threats.
- Unwanted pop-ups and advertisements
- Slow computer performance
- Disabled antivirus software or firewall protection
- Unexpected changes to system settings
- Unexplained crashes or errors
How to Remove PUP.DisableDefender
- Boot your computer in Safe Mode with Networking to prevent PUP.DisableDefender from loading and to allow for a more thorough removal process.
- Use a reputable malware removal tool, such as SpyHunter, to scan your computer and detect any malicious files or components associated with PUP.DisableDefender.
- Uninstall any suspicious programs or applications that may be related to PUP.DisableDefender.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
- Reboot your computer and run a full scan with your antivirus software to ensure that all remnants of PUP.DisableDefender have been removed.
Conclusion
Removing PUP.DisableDefender from your computer requires a combination of technical expertise and the right tools. By following the steps outlined above, you can help to ensure that your computer is free from this potentially unwanted program and that your security features are restored to their full functionality. It's also essential to practice safe computing habits, such as regularly updating your operating system and software, using strong passwords, and avoiding suspicious downloads and links, to prevent future infections and protect your computer from other types of threats.
Analysis Report
General information
| Family Name: | PUP.DisableDefender |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
71b5f8bab80742650151ff4fc2eafa84
SHA1:
90c5aba6eeb3acbdc63b0c57c2c893889877f280
SHA256:
CA403188D0AE885EE657F97E896E5A0F99C971E41AECDF9C38BF56E0417FD377
File Size:
888.43 KB, 888435 bytes
|
|
MD5:
6bf0418ae10835d5dad3f505dd227f2c
SHA1:
f26216112ed1752311c21152923083abd8e53bc4
SHA256:
38F0EA1245567942D30647FF93EAD34F81F75655045DEACD72D8B740F2F8176D
File Size:
7.17 KB, 7168 bytes
|
|
MD5:
c16d92879668c2f25e70e6aa4d775125
SHA1:
2e1c26d7c4d2d477b80e39483788159020e3d73f
SHA256:
E732D9A120E729E5E7D2119E839D1A2C38891E5617319237B27B540B6A095A42
File Size:
13.31 KB, 13312 bytes
|
|
MD5:
d0cd10409fdfaa1b05e356664919a027
SHA1:
8b77b8679b4c775e48f8818b6a7fae74bc7b3837
SHA256:
5A420A3BACD988F78A8DD6ED901447B5C2F3F26631FCB1C73B4BB9B98D899B0C
File Size:
1.62 MB, 1617408 bytes
|
|
MD5:
613043f124cb3aa441cd995a3c639548
SHA1:
f0efc4fe8a597775117888f1f0233442de4af266
SHA256:
AAC52AD0CA579CD03A462A6B5A225DD08B7DFE727159D0FA7D09E907BA6AECD4
File Size:
1.00 MB, 1002111 bytes
|
Show More
|
MD5:
78f3cec69fb0a56558d31096c2ed575b
SHA1:
f9ab673ba7d7c0cbb9d72c3944584e6b1b203493
SHA256:
5B2EF5EEE4E58598DF3741382E8B845949118925DFEE673A292C58ECC20A6246
File Size:
60.93 KB, 60928 bytes
|
|
MD5:
2ba30791e1058c062ee6987751ffee64
SHA1:
372bde4e34790ae56e009454a7e430e412adb535
SHA256:
42FB473C553A222A2AD2C79B398F388A1AC745ABE48CB29669534EF288D4D4CF
File Size:
3.79 MB, 3791085 bytes
|
|
MD5:
407d560f5dcafdd707d9c4475939fc07
SHA1:
ca0006b80f5b654f168cc21f258295162f135451
SHA256:
9B846657DC15BC1DFB1DBD410B8274F5692D51FF4B4D2208065F2177A8267DE8
File Size:
927.93 KB, 927928 bytes
|
|
MD5:
04fb24273b3b32341d195a464aaf634f
SHA1:
c6bbb4061cc914f30d10fb13bdc2a67011e1fab6
SHA256:
23322754A573A0298CB6B6F9734DD512F9433405FDB115E7897FD767CCFA8DDA
File Size:
3.73 MB, 3727872 bytes
|
|
MD5:
1234305bde15383e9923f3ed85b719b2
SHA1:
e4aaac09cde88a5d7a41b8fbe6fc41d0c314e591
SHA256:
9FC80CDF6DD39B7CFF2711F2CC4EFE30B01162D7BB08DC7B7C8808F2E51F6D15
File Size:
1.39 MB, 1394753 bytes
|
|
MD5:
6dd8798c258a5ce70e19aeafbdbb2c56
SHA1:
2368b3fdeccaab1e5519ee22224d5f08a16c8a76
SHA256:
DA05C7D3A828A399ED94C7013AD76A4DD83B5A7A6CF5896D165E4327F8E4E9B0
File Size:
281.09 KB, 281088 bytes
|
|
MD5:
abd176e37ab7951e22d0799d01e0320f
SHA1:
b6383309020985c278ff8b58d7fc018c53bf9cf9
SHA256:
B09B860574D81FB42C9BA9CD500F1073B5127E5B0A9ABD6C0B0BCDC47D3703A8
File Size:
8.26 MB, 8262656 bytes
|
|
MD5:
4e207259d5844f03513f152a192845c2
SHA1:
0dcf4365cc41cd54ed30ef37bf6e56a9c132b79c
SHA256:
3D4F0884B99631C500D67F5976A7026D7CD32573069C6CF8714F2CF36A20891E
File Size:
210.68 KB, 210677 bytes
|
|
MD5:
1f2f9bf71ff8eb6ff976aa4941a2e3da
SHA1:
e6ca496ca7f0d1d9ca958f7aa0c316b5aeb2f0d3
SHA256:
E2AA2990A3A0F7EF1CCD5B2CF43C41AF37C5461948B00FACFD096E2BC0EC045A
File Size:
7.64 MB, 7638528 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has exports table
- File has TLS information
- File is .NET application
- File is 32-bit executable
- File is 64-bit executable
Show More
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version |
|
| Coder | By BlueLife |
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Original Filename |
|
| Product Name |
|
| Product Version |
|
File Traits
- .NET
- 2+ executable sections
- big overlay
- dll
- HighEntropy
- Inno
- InnoSetup Installer
- Installer Manifest
- Installer Version
- ntdll
Show More
- Run
- SusSec
- VirtualQueryEx
- WriteProcessMemory
- x64
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 4,873 |
|---|---|
| Potentially Malicious Blocks: | 396 |
| Whitelisted Blocks: | 585 |
| Unknown Blocks: | 3,892 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Autoit
- BestaFera.G
- Bitcoinminer.BDA
- Bitcoinminer.BDB
- Bitcoinminer.DJE
Show More
- Delf.DA
- Injector.XD
- MSIL.BypassUAC.K
- MSIL.Downloader.CAYD
- MSIL.Rozena.GG
- Ousaban.V
- Rugmi.T
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\srvsvc | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\program files\common files\system\symsrv.dll | Generic Write,Read Attributes |
| c:\programdata\optimizer\optimizer.json | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\programdata\optimizer\readymademenus\desktopshortcuts.reg | Generic Write,Read Attributes |
| c:\programdata\optimizer\readymademenus\installtakeownership.reg | Generic Write,Read Attributes |
| c:\programdata\optimizer\readymademenus\powermenu.reg | Generic Write,Read Attributes |
| c:\programdata\optimizer\readymademenus\removetakeownership.reg | Generic Write,Read Attributes |
| c:\programdata\optimizer\readymademenus\systemshortcuts.reg | Generic Write,Read Attributes |
| c:\programdata\optimizer\readymademenus\systemtools.reg | Generic Write,Read Attributes |
| c:\programdata\optimizer\readymademenus\windowsapps.reg | Generic Write,Read Attributes |
Show More
| c:\programdata\optimizer\required\disableofficetelemetrytasks.bat | Generic Write,Read Attributes |
| c:\programdata\optimizer\required\disableofficetelemetrytasks.reg | Generic Write,Read Attributes |
| c:\programdata\optimizer\required\disabletelemetrytasks.bat | Generic Write,Read Attributes |
| c:\programdata\optimizer\required\disablexboxtasks.bat | Generic Write,Read Attributes |
| c:\programdata\optimizer\required\enableofficetelemetrytasks.bat | Generic Write,Read Attributes |
| c:\programdata\optimizer\required\enableofficetelemetrytasks.reg | Generic Write,Read Attributes |
| c:\programdata\optimizer\required\enabletelemetrytasks.bat | Generic Write,Read Attributes |
| c:\programdata\optimizer\required\enablexboxtasks.bat | Generic Write,Read Attributes |
| c:\programdata\optimizer\required\onedrive_uninstaller.cmd | Generic Write,Read Attributes |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\002ca36d_rar\ca0006b80f5b654f168cc21f258295162f135451_0000927928 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\002ca36d_rar\ca0006b80f5b654f168cc21f258295162f135451_0000927928 | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\users\user\appdata\local\temp\002ca3fa_rar\ca0006b80f5b654f168cc21f258295162f135451_0000927928 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\002ca3fa_rar\ca0006b80f5b654f168cc21f258295162f135451_0000927928 | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\users\user\appdata\local\temp\a1d26e2\e335ba41590.tmp | Generic Write,Read Attributes |
| c:\windows\system.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\policies\microsoft\windows defender::disableantispyware | RegNtPreCreateKey | |
| HKLM\software\policies\microsoft\windows defender\real-time protection::disablebehaviormonitoring | RegNtPreCreateKey | |
| HKLM\software\policies\microsoft\windows defender\real-time protection::disableonaccessprotection | RegNtPreCreateKey | |
| HKLM\software\policies\microsoft\windows defender\real-time protection::disablescanonrealtimeenable | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\securityhealthservice::start | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\mpssvc::start | RegNtPreCreateKey | |
| HKLM\software\policies\microsoft\windowsfirewall\standardprofile::enablefirewall | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | 沉 䠱O噀ñʁ傄ë駃óߙĤ É | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center::antivirusoverride | RegNtPreCreateKey |
Show More
| HKLM\software\wow6432node\microsoft\security center::antivirusdisablenotify | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center::firewalldisablenotify | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center::firewalloverride | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center::updatesdisablenotify | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center::uacdisablenotify | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center\svc::antivirusoverride | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center\svc::antivirusdisablenotify | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center\svc::firewalldisablenotify | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center\svc::firewalloverride | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center\svc::updatesdisablenotify | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\security center\svc::uacdisablenotify | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings::globaluseroffline | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows\currentversion\policies\system::enablelua | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::enablefirewall | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::donotallowexceptions | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::disablenotifications | RegNtPreCreateKey | |
| HKCU\software\apcr\1214104697::1919251317 | ª | RegNtPreCreateKey |
| HKCU\software\apcr\1214104697::-456464662 | RegNtPreCreateKey | |
| HKCU\software\apcr\1214104697::1462786655 | RegNtPreCreateKey | |
| HKCU\software\apcr\1214104697::-912929324 | # | RegNtPreCreateKey |
| HKCU\software\apcr\1214104697::1006321993 | ĉ | RegNtPreCreateKey |
| HKCU\software\apcr\1214104697::-1369393986 | http://intercomplustula.ru/logo.gif http://gocekmanti.com/imag | RegNtPreCreateKey |
| HKCU\software\apcr\1214104697::549857331 | f�P�(/� ��Z� �z��!�<Q��+�^�� ѩ�]T�u[L��m����Mgݾq����gR | RegNtPreCreateKey |
| HKCU\software\apcr::u1_0 | 㑞㗊 | RegNtPreCreateKey |
| HKCU\software\apcr::u2_0 | | RegNtPreCreateKey |
| HKCU\software\apcr::u3_0 | 権ă | RegNtPreCreateKey |
| HKCU\software\apcr::u4_0 | RegNtPreCreateKey | |
| HKCU\software\apcr::u1_1 | �� | RegNtPreCreateKey |
| HKCU\software\apcr::u2_1 | 泺牥 | RegNtPreCreateKey |
| HKCU\software\apcr::u3_1 | ᥜ獦 | RegNtPreCreateKey |
| HKCU\software\apcr::u4_1 | 獵牥 | RegNtPreCreateKey |
| HKCU\software\apcr::u1_2 | ༾脦 | RegNtPreCreateKey |
| HKCU\software\apcr::u2_2 | 앟 | RegNtPreCreateKey |
| HKCU\software\apcr::u3_2 | 賃 | RegNtPreCreateKey |
| HKCU\software\apcr::u4_2 | | RegNtPreCreateKey |
| HKCU\software\apcr::u1_3 | ㌣儵 | RegNtPreCreateKey |
| HKCU\software\apcr::u2_3 | 䌆地 | RegNtPreCreateKey |
| HKCU\software\apcr::u3_3 | ぶ嘳 | RegNtPreCreateKey |
| HKCU\software\apcr::u4_3 | 婟地 | RegNtPreCreateKey |
| HKCU\software\apcr::u1_4 | ᝦ쩾 | RegNtPreCreateKey |
| HKCU\software\apcr::u2_4 | 헋즕 | RegNtPreCreateKey |
| HKCU\software\apcr::u3_4 | ꟽ좖 | RegNtPreCreateKey |
| HKCU\software\apcr::u4_4 | 췔즕 | RegNtPreCreateKey |
| HKCU\software\apcr::u1_5 | ഄ汎 | RegNtPreCreateKey |
| HKCU\software\apcr::u2_5 | 慄㯻 | RegNtPreCreateKey |
| HKCU\software\apcr::u3_5 | ⭠㫸 | RegNtPreCreateKey |
| HKCU\software\apcr::u4_5 | 䅉㯻 | RegNtPreCreateKey |
| HKCU\software\apcr::u1_6 | ꐆ | RegNtPreCreateKey |
| HKCU\software\apcr::u2_6 | 钴깠 | RegNtPreCreateKey |
| HKCU\software\apcr::u3_6 | ��c� | RegNtPreCreateKey |
| HKCU\software\apcr::u4_6 | 뒾깠 | RegNtPreCreateKey |
| HKCU\software\apcr::u1_7 | 뷻 | RegNtPreCreateKey |
| HKCU\software\apcr::u2_7 | ヾ | RegNtPreCreateKey |
| HKCU\software\apcr::u3_7 | 䈚⇅ | RegNtPreCreateKey |
| HKCU\software\apcr::u4_7 | ⠳ | RegNtPreCreateKey |
| HKCU\software\apcr::u1_8 | 룾긲 | RegNtPreCreateKey |
| HKCU\software\apcr::u2_8 | 軡錫 | RegNtPreCreateKey |
| HKCU\software\apcr::u3_8 | 鈨 | RegNtPreCreateKey |
| HKCU\software\apcr::u4_8 | 鮨錫 | RegNtPreCreateKey |
| HKCU\software\apcr::u1_9 | 꽧ﲳ | RegNtPreCreateKey |
| HKCU\software\apcr::u2_9 | ᖃ֑ | RegNtPreCreateKey |
| HKCU\software\apcr::u3_9 | 攴Ғ | RegNtPreCreateKey |
| HKCU\software\apcr::u4_9 | ༝֑ | RegNtPreCreateKey |
| HKCU\software\apcr::u1_10 | 귋삚 | RegNtPreCreateKey |
| HKCU\software\apcr::u2_10 | 齥矶 | RegNtPreCreateKey |
| HKCU\software\apcr::u3_10 | 盵 | RegNtPreCreateKey |
| HKCU\software\apcr::u4_10 | 芒矶 | RegNtPreCreateKey |
| HKCU\software\apcr::u1_11 | 았瑫 | RegNtPreCreateKey |
| HKCU\software\apcr::u2_11 | 폍 | RegNtPreCreateKey |
| HKCU\software\apcr::u3_11 | 鰮 | RegNtPreCreateKey |
| HKCU\software\apcr::u4_11 | | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Other Suspicious |
|
| User Data Access |
|
| Syscall Use |
Show More
|
| Anti Debug |
|
| Encryption Used |
|