PUP.MSIL.Bulz.RN

PUP.MSIL.Bulz.RN is a detection name used by security software to identify a potentially unwanted program (PUP) written in the .NET framework, as indicated by the "MSIL" component of its name. Programs flagged under this detection are generally not classified as traditional viruses or highly destructive malware, but they are considered unwanted because of the intrusive, deceptive, or privacy-invasive behaviors they tend to exhibit. Since detailed technical specifics for this particular detection are not confirmed, the information below describes the typical behavior associated with this category of threat.

What This Threat Typically Does

Programs identified as PUP.MSIL.Bulz.RN generally function as bundled or borderline applications that install themselves on a system alongside other software, often without the user's full awareness. Such programs commonly attempt to modify browser settings, inject advertisements into web pages, redirect search queries, or install additional toolbars and extensions that the user did not specifically request. In many cases, these programs are designed primarily to generate revenue for their developers through advertising networks, affiliate marketing schemes, or data collection practices rather than to provide any meaningful benefit to the end user.

Some PUPs in this category may also run background processes that consume system resources, display persistent pop-up notifications, or make it deliberately difficult for users to locate and uninstall them through normal means.

How It Usually Gets Onto Computers

PUPs like this one typically spread through software bundling, where they are packaged alongside free downloads such as media players, PDF converters, system utilities, or pirated software. Users who rush through installation wizards without reviewing each step may inadvertently agree to install these additional programs. Other common distribution methods include deceptive advertisements, fake software update prompts, and misleading "download" buttons on file-sharing or streaming websites that trick users into downloading the unwanted program instead of the content they intended to access.

Risks for the User

While PUPs are typically less dangerous than outright malware, they still pose several risks. These include reduced system performance, intrusive and excessive advertising, unwanted changes to browser homepages or default search engines, and potential exposure to further malicious content through the ads they display. Some PUPs may also collect browsing habits, search history, or other usage data and share it with third parties, raising privacy concerns.

Signs of Infection

Common indicators that a PUP such as this may be present on a system include a noticeably slower computer or browser, unexpected changes to browser settings, new toolbars or extensions that were not intentionally installed, frequent pop-up ads appearing even when the browser is not actively in use, and the presence of unfamiliar programs in the installed applications list or system startup entries.

How to Stay Protected

To reduce the risk of encountering unwanted programs like this one, users should always download software directly from official or trusted sources, carefully read each step of installation wizards, and opt out of any bundled offers by choosing "custom" or "advanced" installation options instead of default settings. Keeping the operating system and browsers updated, avoiding suspicious download links or pop-up prompts, and regularly reviewing installed programs and browser extensions can also help catch unwanted software early. Running reputable security software and performing periodic system scans remains an effective way to detect and remove such programs before they cause further disruption.

Analysis Report

General information

Family Name: PUP.MSIL.Bulz.RN
Signature status: No Signature

Known Samples

MD5: 95759f70ce5a8fd5b6e8caa195f277f6
SHA1: 41f0ba0cbe36e62eb1114fade3165cae38ada767
SHA256: 42C29A6CA7C25789888CE33992176765781F05FBFC1348BC68260F4AC90F1445
File Size: 45.57 KB, 45568 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments java环境变量配置工具
Company Name Microsoft
File Description java环境变量配置工具
File Version 1.0.0.0
Internal Name Jdk_Path_Config.exe
Legal Copyright Copyright © scimence 2022
Original Filename Jdk_Path_Config.exe
Product Name Jdk_Path_Config
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 29
Potentially Malicious Blocks: 10
Whitelisted Blocks: 8
Unknown Blocks: 11

Visual Map

x ? ? ? 0 x x x x ? 0 x x x 0 ? ? ? ? ? ? ? x x 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\programdata\scitools\scitools.data Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
Show More
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
Show More
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Anti Debug
  • IsDebuggerPresent