PUP.PowerRun
The detection of PUP.PowerRun on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it to prevent further problems.
Table of Contents
What Is PUP.PowerRun?
PUP.PowerRun is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as damaging as other types of malware, such as viruses or Trojans, it can still cause significant issues with your system. PUPs are often installed unintentionally, and they can lead to a range of problems, including slowed system performance, unwanted advertisements, and potential security vulnerabilities.
How PUP.PowerRun Operates
PUPs like PUP.PowerRun typically operate by installing themselves on a system without the user's full knowledge or consent. They may be bundled with other software, or they may be installed through exploits in vulnerable applications. Once installed, PUPs can collect user data, display unwanted advertisements, and even install additional malware. They may also modify system settings and configure themselves to start automatically when the system boots.
Symptoms of Infection
If your system is infected with PUP.PowerRun, you may notice a range of symptoms. These can include slowed system performance, unwanted pop-up advertisements, and new toolbars or extensions in your web browser. You may also notice that your system is configured to start certain programs automatically, or that your default search engine or homepage has been changed. Additionally, you may see suspicious programs or processes running in the background, consuming system resources.
- Unwanted advertisements and pop-ups
- Slow system performance
- New toolbars or extensions in your web browser
- Changes to system settings and configurations
- Suspicious programs or processes running in the background
How to Remove PUP.PowerRun
- Boot your system in Safe Mode with Networking to prevent PUP.PowerRun from loading and to give you access to the internet for downloading removal tools.
- Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or PUPs that may be present.
- Uninstall any suspicious programs that were installed around the time the PUP was detected. Be cautious and only uninstall programs that you are certain are not needed or are malicious.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by the PUP.
- Reboot your system and perform another scan with your anti-malware tool to ensure that all malware and PUPs have been removed.
Conclusion
Removing PUP.PowerRun from your system is crucial to preventing further issues and ensuring your computer's security and performance. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this potentially unwanted program and protect your system from similar threats in the future. Remember to always be cautious when installing software and to monitor your system for any suspicious activity to prevent PUPs and other malware from infecting your computer.
Analysis Report
General information
| Family Name: | PUP.PowerRun |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
cf22c17ca19f7c31dbf098683d458b9c
SHA1:
1a51bd6efd4b8ddf12ff456a54f55102fbd3f986
File Size:
842.99 KB, 842994 bytes
|
|
MD5:
41e1e078871a73b1ccb5842a8517a2b8
SHA1:
9bfcb1c13dadc06128ef6fd6791dbac81f6c0210
File Size:
543.66 KB, 543661 bytes
|
|
MD5:
1a6bf240f43808ff58b98bdf3b85524c
SHA1:
d9e0b62548153f132887c39f72befcbd4b453f9c
SHA256:
E58B3F06F81E9F454922E56F20875AB5CF5A7D0F99524E02B7603F46B1F831F7
File Size:
843.73 KB, 843733 bytes
|
|
MD5:
d8949a1bdbf7b72369296f3ef39f59a1
SHA1:
1d750a9d018dd9a953b4f36bc4c5401045a32bee
SHA256:
DA011EABF65A8CFB44705B62140AC963C82E25727825E949EB81F47C806FCCBD
File Size:
899.74 KB, 899742 bytes
|
|
MD5:
5acc6239eb4321ad197f30e30bb17307
SHA1:
591e997fc3cc0a1146646057e9ddeff4aad9d10c
SHA256:
1A23326D5628EC55B9F8033CCDC1324C36D3A7536CDC7E2C44056049134E69C7
File Size:
894.02 KB, 894016 bytes
|
Show More
|
MD5:
05af406f46a08be6ebdd86c282f746e9
SHA1:
8b87d60415c0ead149be5883fb15f52a9c2e899d
SHA256:
B9DE9C1E9D6723CD6915474FB67BA878F445431CA6C0338F5F567E298E19A06B
File Size:
1.05 MB, 1054979 bytes
|
|
MD5:
75d9dd5c5da200748ad280e4d2580bba
SHA1:
623908159b8a9815db2f2e754ca691b76d22684e
SHA256:
C72D2EE2333BA87E962ADF00E441468C96B72F5609905B3C91C9758EA26E995E
File Size:
1.67 MB, 1673760 bytes
|
|
MD5:
6eb1baa41c8731fd84bcde7081f0d940
SHA1:
36dfc44315b2c5e649b1bbaea322e6ca6b1e7264
SHA256:
47E0AA5F1B337D02C800F91D5360431E5B9883299722AB25E74F6DB3ECF40B5F
File Size:
2.08 MB, 2082848 bytes
|
|
MD5:
15c3d5d3bbde6b7b20954d870adb0c7d
SHA1:
1204dba6aa49b03abb3f79b5a31101a31c1b0cb9
SHA256:
CB14A3D093C2B4B2BE0EE5E123EBAFFCD7D5F681D222F97A5341D6C6D65C1E2D
File Size:
833.56 KB, 833560 bytes
|
|
MD5:
121a7cadbeea06d5544df7786b3309f2
SHA1:
47e2188597ba3d77ff1ebb977329be21ab00e6e2
SHA256:
77F356F648B91916E9BD1711F11B67A1986FC26CEEAA915AADD53D0A266BE65A
File Size:
999.03 KB, 999033 bytes
|
|
MD5:
409e1c6995725b25551809484a8e1f45
SHA1:
00b2651355689bc73a47b523f56243a13c03dc4c
SHA256:
50436566C22D4E7AC32B9BE8D78CC5245234BE14824313B41165FF324BB07F88
File Size:
789.62 KB, 789624 bytes
|
|
MD5:
82fa1feb495fe325ee10a856ce62c2e8
SHA1:
292a7cf11809edf7860f7dc9c5da410ec946d79b
SHA256:
56DB4A91890041FC193FA87BB28B0750F6B251C904D49CAAA4298A0D9435A34E
File Size:
1.08 MB, 1076224 bytes
|
|
MD5:
0682814a4296f8ef67399ebac1d9c354
SHA1:
db00beefcdb88ece77abf235a139c8c50206ab80
SHA256:
11C05C4E2D9ABFF3048A175AED285ACA0E1EAC2CBECF8614C3B2F0D3316C6A87
File Size:
831.82 KB, 831818 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has TLS information
- File is .NET application
- File is 32-bit executable
- File is 64-bit executable
- File is either console or GUI application
Show More
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version |
|
| Coder | By BlueLife |
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
Show More
|
| Internal Name |
|
| Legal Copyright |
|
| Legal Trademarks |
|
| Original Filename |
|
| Product Name |
|
| Product Version |
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| AnWave Software and Simon Macer Project | AnWave Software and Simon Macer Project | Self Signed |
| Sordum Software | Sordum Software | Hash Mismatch |
File Traits
- big overlay
- HighEntropy
- WriteProcessMemory
- x64
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Autoit
- Bitcoinminer.BDA
- Bitcoinminer.BDB
- Bitcoinminer.DJE
- Rugmi.T
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\dav rpc service | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| \device\namedpipe\gmdasllogger | Generic Write,Read Attributes |
| \device\namedpipe\pshost.134228115379821550.8436.defaultappdomain.powershell | Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288 |
| \device\namedpipe\wkssvc | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\programdata\anwaverootinstall\require\simonmacer.pfx | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7r5v6f8k.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\7r5v6f8k.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\powerrun.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\powerrun.exe | Synchronize,Write Attributes |
Show More
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removedefender.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removedefender.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removeshellassociation.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removeshellassociation.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp\remove_securitycomp.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp\remove_securitycomp.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\removesechealthapp.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\removesechealthapp.ps1 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\script_run.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs14e6.tmp\script_run.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender\disable_def.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender\disable_def.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender\enable_def.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender\enable_def.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\add firewall menu.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\add firewall menu.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\remove firewall menu.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\remove firewall menu.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\antivirus_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\antivirus_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\defender anti-phishing_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\defender anti-phishing_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\exploit guard_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\exploit guard_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\security health_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\security health_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\smartappcontrol_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\smartappcontrol_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\windows security center_d.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\windows security center_d.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\antivirus_e.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\antivirus_e.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\defender anti-phishing_e.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\defender anti-phishing_e.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\security health_e.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\security health_e.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\windows security center_e.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\windows security center_e.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable lsa protection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable lsa protection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable microsoft vulnerabile driver blocklist.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable microsoft vulnerabile driver blocklist.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable smartscreen.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable smartscreen.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable uac.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable uac.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable vbs.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable vbs.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\no more delay and timeouts.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\no more delay and timeouts.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\security health.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\security health.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\windows settings page visibility.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\windows settings page visibility.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\oscdimg.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\oscdimg.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\powerrun.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\powerrun.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender and security center notifications.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender and security center notifications.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender policies.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender policies.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable tamper protection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable tamper protection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\lockdown windows defender security center.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\lockdown windows defender security center.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of anti-phishing services.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of anti-phishing services.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of sechealthui.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of sechealthui.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows defender antivirus.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows defender antivirus.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows security action center.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows security action center.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove defender tasks.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove defender tasks.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove security and maintenance.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove security and maintenance.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove services.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove services.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove shell association.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove shell association.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove startup entries.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove startup entries.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows defender firewall rules.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows defender firewall rules.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows webthreat.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows webthreat.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remover of defender context menu.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remover of defender context menu.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\script_run.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\script_run.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\winwim.cmd | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs413b.tmp\winwim.cmd | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\powerrun.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\powerrun.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\nomoredelayandtimeouts.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\nomoredelayandtimeouts.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removedefender.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removedefender.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removeshellassociation.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removeshellassociation.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp\remove_securitycomp.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp\remove_securitycomp.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\removesechealthapp.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\removesechealthapp.ps1 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\script_run.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zs45bf.tmp\script_run.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\files_removal.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\files_removal.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\powerrun.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\powerrun.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disable mitigation.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disable mitigation.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disable smartscreen.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disable smartscreen.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disableantivirusprotection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disableantivirusprotection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disabledefenderpolicies.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disabledefenderpolicies.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removalofwindowsdefenderantivirus.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removalofwindowsdefenderantivirus.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removedefendertasks.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removedefendertasks.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removerofdefendercontextmenu.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removerofdefendercontextmenu.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removeservices.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removeservices.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removeshellassociation.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removeshellassociation.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removesignatureupdates.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removesignatureupdates.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removestartupentries.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removestartupentries.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removewindowswebthreat.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removewindowswebthreat.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\windowssettingspagevisibility.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\windowssettingspagevisibility.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_securitycomp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_securitycomp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_securitycomp\remove_securitycomp.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\remove_securitycomp\remove_securitycomp.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\removesechealthapp.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\removesechealthapp.ps1 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\script_run.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa15.tmp\script_run.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\powerrun.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\powerrun.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disableantivirusprotection.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disableantivirusprotection.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderpolicies.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderpolicies.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\nomoredelayandtimeouts.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\nomoredelayandtimeouts.reg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removalofwindowsdefenderantivirus.reg | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removalofwindowsdefenderantivirus.reg | Synchronize,Write Attributes |
134 additional files are not displayed above.
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 俆ꦎ⚖ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 竞⚛ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ಲ䪩茔ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ����� | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Syscall Use |
Show More
130 additional items are not displayed above. |
| Service Control |
|
| Keyboard Access |
|
| Other Suspicious |
|
| Cert Store Read |
|
| Cert Store Write |
|
| Encryption Used |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
.\Script_Run.bat
|
WriteConsole: ------ Defender
|
WriteConsole: Select an option
|
WriteConsole:
|
WriteConsole: Do you want to r
|
Show More
WriteConsole: If you PC have a
|
WriteConsole: After confirmati
|
WriteConsole: A backup and/or
|
WriteConsole: [Y] Remove Windo
|
WriteConsole: [A] Remove Windo
|
WriteConsole: [S] Disable All
|
C:\WINDOWS\system32\choice.exe choice /C:yas /N
|
WriteConsole: (NULL)
|
C:\Users\Sqljlniy\AppData\Local\Temp\{2C6E2BE6-1CB4-4E15-8576-CBF76CA4FD6A}\Script_Run.bat
|
WriteConsole: Defender Remover
|
WriteConsole: 592ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 4e2ce29494e2959720e294a4e28c90e2
|
WriteConsole: 452ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 482ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 492ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 462ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 472ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 522ce29494e2959720e294a4e28c90e2
|
WriteConsole: 552ce29595c2aa20e294a4e28c90e295
|
WriteConsole: 4a2ce29595c2aa20e294a4e28c90e295
|
WriteConsole: e2959de29692e294bce2949ce2959fe2
|
WriteConsole: e29691cea6e2959de29599e2959fe295
|
C:\WINDOWS\system32\mode.com mode con cols=70 lines=25
|
WriteConsole: Access is denied
|
WriteConsole: e2959fceb4e295a4c3ade29598c2b1e2
|
WriteConsole: e295a9e2959fe29596c2b1e295a5c2ac
|
WriteConsole: e2959acf84e295a3e2889ae29480cf80
|
WriteConsole: 28e294a4e295a6e2959ce294bce29692
|
WriteConsole: e2959ae29596e2959ae295a7e29594e2
|
WriteConsole: e2959cc2bfe295a5ce98e295a9e295a3
|
WriteConsole: 5b595d20e295a5e2959ee29482c2b220
|
WriteConsole: 5b415d20e295a5e2959ee29482c2b220
|
WriteConsole: 5b535d20e2959ce2889ae29599e2949c
|
C:\WINDOWS\system32\mode.com mode con cols=80 lines=25
|
C:\WINDOWS\system32\net.exe net session
|
WriteConsole: e2959fceb4e2959fe289a4e295a3e296
|
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "Start-Process 'C:\Users\Zybjmzbz\appdata\local\temp\7zsa15.tmp\script_run.bat' -Verb RunAs"
|