PUP.SecurityXploded

The detection of PUP.SecurityXploded on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent further damage.

What Is PUP.SecurityXploded?

PUP.SecurityXploded is a type of potentially unwanted program that can be installed on your system without your knowledge or consent. It may be bundled with other software or downloaded from the internet, often through deceptive means. PUPs like PUP.SecurityXploded can compromise your system's security, collect sensitive information, and display unwanted advertisements.

How PUP.SecurityXploded Operates

PUPs like PUP.SecurityXploded typically operate by exploiting vulnerabilities in your system or using social engineering tactics to trick you into installing them. Once installed, they can modify system settings, create unwanted registry entries, and communicate with remote servers to transmit sensitive information. They may also display pop-up ads, banners, and other types of unwanted content to generate revenue for their creators.

Symptoms of Infection

Systems infected with PUP.SecurityXploded may exhibit a range of symptoms, including slow system performance, unwanted pop-up ads, and unexpected changes to system settings. You may also notice unfamiliar programs or icons on your desktop, or experience frequent system crashes and errors. In some cases, PUPs like PUP.SecurityXploded can also lead to more severe issues, such as data breaches or identity theft.

  • Unwanted pop-up ads and banners
  • Slow system performance and crashes
  • Unexpected changes to system settings
  • Unfamiliar programs or icons on your desktop
  • Frequent system errors and warnings

How to Remove PUP.SecurityXploded

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious components related to PUP.SecurityXploded.
  3. Uninstall any suspicious programs or applications that may be associated with the PUP, using the Add/Remove Programs feature in your system's Control Panel.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that all components of the PUP have been removed.

Conclusion

Removing PUP.SecurityXploded from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above, you can effectively remove this potentially unwanted program and restore your system to a secure and stable state. Remember to always be cautious when downloading software from the internet and to use reputable anti-malware tools to protect your system from future threats.

Analysis Report

General information

Family Name: PUP.SecurityXploded
Signature status: No Signature

Known Samples

MD5: aa32a7002599fca0be506f2dd375970d
SHA1: 60a7d18e1e363e06fc6b1aa7b4d73e9490e03234
File Size: 528.90 KB, 528896 bytes
MD5: 0772a4049fc8739241ff2a5913f6f832
SHA1: 0bca20a30c8012d8df3b374aa89095375da24254
File Size: 1.78 MB, 1781556 bytes
MD5: c90dfa77f391a834347d65c5f3bd69ef
SHA1: e8fef39e59726ac089352e69ebae2c882b35758d
SHA256: 3A7C319E4CDC8CFEDBCB85D11AEB4AFAD1BD9C0235B99ABDCA5B10503E3E799F
File Size: 395.29 KB, 395286 bytes
MD5: cb872ef9500907ac81ab8d3a7dbd10d4
SHA1: d37e0af6b0d37ba6fe97b86f3c82407da3e5afbb
SHA256: 093E04FC519640E558368353546DAFC3EBB43401278C1829296C85BF4B32B757
File Size: 409.32 KB, 409318 bytes
MD5: 097ef33dc268686be2b29a20e06e46f3
SHA1: 94c01013eba7faa5ab37313276d9da78762f6680
SHA256: E74D617CC67DD722417BF096BD56F1857FBBD39871712AB2CC1AB42C2B2FA6C2
File Size: 1.24 MB, 1240576 bytes
Show More
MD5: 71aa7ff4a98de9303a54ae42e485a3ac
SHA1: 0e3b6df7ebf3f396c717892aa1ac187319286bf8
SHA256: 3D7253A75923224A3B8510DB26BF130D2C41C02881F5C5888F6C58F13E747900
File Size: 407.86 KB, 407861 bytes
MD5: e0c74da608d6d7cc27a014ac0d1007b8
SHA1: ed426da1e5b9794cbe25bb08a1fa4ba07db07ac8
SHA256: B1FCDEB5F89B4FA928F1BC888FF489D0876784AF1D08C6C4550C420522B9A64E
File Size: 688.13 KB, 688128 bytes
MD5: 895a87c7fc3e25e71aa72716b4893ac9
SHA1: e4528dc08ef40792133cdd8cc668649e9fa56d6e
SHA256: 81069377A926E20E439B707E36BCB7EE3506B2EC5C227BAE504B0494B7C7947A
File Size: 9.02 MB, 9019696 bytes
MD5: 8f852a23f448a1bc9971339e02562dc3
SHA1: 9f033b9bdcf2479b8f8580178aa12242dbc32c15
SHA256: 7723EB8192F5D68138C39825F38BB89EABE4DD044FE10A614E2A0DDF26EF792D
File Size: 1.78 MB, 1781556 bytes
MD5: ba320d9c515162006623fe56125aa313
SHA1: 90e43e171c5b9e07be6d7ffeaf6f336d186c02cb
SHA256: 1E0C9A0D8CBE1018F85C7BA5F80F6B9A7C46A9A38BCC57839E0EEDE16CAC4452
File Size: 197.63 KB, 197632 bytes
MD5: 2156499fc25b43e950e294945a2d6af8
SHA1: 9570e22737b928f729cebabb1394274004656f9c
SHA256: 3BD5AE63A2FCB43CF914A40712AF5B7C70F0360E06323623B8892BCC197534D5
File Size: 374.07 KB, 374070 bytes
MD5: d68b45b6e722bc4f27a3a0994fe2f002
SHA1: 705e79c65ee24dc8f48ca57429acec3d54d658dc
SHA256: D132941C054EEB41B3298C13FDBC5C94C5B8215224EFBC81B36C4D58A06F2D15
File Size: 416.53 KB, 416532 bytes
MD5: 3f22e8cf87aa7c6b1c66b6334d81c2dc
SHA1: 29f9b71ce53592bc0004b1de3b69adabcbcaa0d6
SHA256: 96F909C9A798C5195279FEF35DF288E0CB62CB7F043A4E09EF3505FEC5E9B4B1
File Size: 2.61 MB, 2606592 bytes
MD5: c0d149921b527e5a30a87f19990acc9c
SHA1: 443bbe55c322c237929998720d36347494696ab3
SHA256: 33377966F1DE01FA7762AD77232A70CBF9602F071012A4E90E76BAF11908AA89
File Size: 5.68 MB, 5678281 bytes
MD5: b99766c3aee432d0b9945a36c0e75b3a
SHA1: 846864cc8442641c2902fa5416765a90e443fd61
SHA256: B0CC4453E7C5A66742CE4ED7EB785F275FEA6D0D50FA8A258FF5E1AA102BA57E
File Size: 5.68 MB, 5682488 bytes
MD5: 63fee2329b446ad74ed11dfdf00415bb
SHA1: 6c7fa21c01d5a1d4b4303d00c4579403b412f871
SHA256: 1A050D94DD1051FFF32DE3C7C74D65D2021C9E40079BACD3BCAF9D6FD0E9C4C1
File Size: 5.68 MB, 5680881 bytes
MD5: c758fb41e7a880a8bca25aa5430d144b
SHA1: 0d5b78e59bc68aed978d121d2680ce04e4011549
SHA256: 8BEF52D34843088EA7AAD508B74ADCF809F5EB4548E74A8ABE909C038F321F54
File Size: 7.75 MB, 7751990 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Comments
  • Nagareshwar Talekar (tnagareshwar@gmail.com)
  • www.SecurityXploded.com
Company Name
  • SecurityXploded
  • SecurityXploded Inc
  • Security_Xploded
File Description
  • All-in-one Facebook History Viewer Software
  • Autorun File Remover
  • Browser Password Recovery Software
  • Command-line Tool to Change File Date and Time
  • Desktop Tool to Perform Quick Anti-virus Scan using VirusTotal
  • Disable Windows Defender Installer
  • Free Tool to Block or Unblock Ads across all Web Browsers
  • Free Windows Encrypted File Discovery Software
  • LDAP Search Application
  • Process Network Port Monitoring Application
Show More
  • Show Windows
  • This installer database contains the logic and data required to install Process Network Monitor.
  • This installer database contains the logic and data required to install Simple Website Blocker.
  • This installer database contains the logic and data required to install Vista UAC Maker.
  • VirusTotal Scanner
File Version
  • 6.0.0.0
  • 6.0
  • 5.5
  • 5.0.0.0
  • 5.0
  • 3.5
  • 3.0
  • 2.0.0.0
  • 2.0
  • 2, 5, 0, 1
Show More
  • 2, 2, 0, 1
  • 1.6
  • 1.0.0.0
  • 1.0
Internal Name
  • AutorunFileRemover.exe
  • FileTimeChanger
  • LDAP Search
  • ProcNetMonitor
  • Setup_DisableWindowsDefender
  • Setup_ProcNetMonitor
  • ShowWindows
  • SimpleWebsiteBlocker
  • VirusTotalScanner.exe
  • VistaUACMaker
Legal Copyright
  • Copyright (C) 2006 - 2009
  • Copyright (C) 2007-2013 SecurityXploded, All rights reserved
  • Copyright (c) 2007-2016 SecurityXploded, All rights reserved.
  • Copyright (C) 2007-2017 SecurityXploded, All rights reserved
  • Copyright (C) 2010 SecurityXploded Inc, All rights reserved.
  • Copyright (C) 2017 SecurityXploded
  • Copyright (C) 2019 SecurityXploded
  • Copyright (C) 2026 Security_Xploded
  • Copyright © 2007-2013 SecurityXploded, All rights reserved
  • Copyright © 2007-2014 SecurityXploded, All rights reserved
Show More
  • Copyright © 2007-2015 SecurityXploded, All rights reserved
Original File Name
  • Setup_DisableWindowsDefender.exe
  • Setup_ProcNetMonitor.exe
  • SimpleWebsiteBlocker.aiui
  • VistaUACMaker.aiui
Original Filename
  • AutorunFileRemover.exe
  • FileTimeChanger.exe
  • LDAPSearch.exe
  • ProcNetMonitor.EXE
  • ShowWindows.exe
  • VirusTotalScanner.exe
Product Name
  • AutorunFileRemover
  • BrowserPasswordDecryptor
  • Disable Windows Defender
  • EncryptedFileScanner
  • FacebookHistorySpy
  • FileTimeChanger
  • LDAP Search Application
  • Process Network Monitor
  • ProcNetMonitor
  • ShowWindows
Show More
  • Simple Website Blocker
  • UniversalAdBlocker
  • VirusTotalScanner
  • Vista UAC Maker
Product Version
  • 6.0.0.0
  • 6.0
  • 5.5
  • 5.0.0.0
  • 5.0
  • 3.5
  • 3.0
  • 2.0.0.0
  • 2.0
  • 2, 5, 0, 1
Show More
  • 2, 2, 0, 1
  • 1.6
  • 1.0.0.0
  • 1.0

Digital Signatures

Signer Root Status
Plex, Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • AdvInst
  • big overlay
  • HighEntropy
  • imgui
  • Installer Manifest
  • Installer Version
  • nosig nsis
  • Nullsoft Installer
  • x64
  • x86

Block Information

Total Blocks: 4,151
Potentially Malicious Blocks: 0
Whitelisted Blocks: 4,128
Unknown Blocks: 23

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • 1stBrowser.A
  • Agent.M
  • Agent.MH
  • Agent.MI
  • Agent.MU
Show More
  • Autorun.LA
  • Downloader.Agent.EG
  • Downloader.Agent.EL
  • Downloader.Agent.LU
  • FakeAV.AU
  • Farfli.AV
  • KillAV.GA
  • Trojan.Downloader.Gen.BQ
  • Ursnif.C
  • Ursnif.XG

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsma786.tmp\btmimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsma786.tmp\confirm.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsma786.tmp\finish.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsma786.tmp\header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsma786.tmp\iswelcome.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsma786.tmp\leftimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsnaa45.tmp\btmimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsnaa45.tmp\confirm.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsnaa45.tmp\finish.ini Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nsnaa45.tmp\header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsnaa45.tmp\iswelcome.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsnaa45.tmp\leftimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp5861.tmp\btmimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp5861.tmp\confirm.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp5861.tmp\finish.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp5861.tmp\header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp5861.tmp\iswelcome.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp5861.tmp\leftimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr5dd1.tmp\btmimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr5dd1.tmp\confirm.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr5dd1.tmp\finish.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr5dd1.tmp\header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr5dd1.tmp\iswelcome.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsr5dd1.tmp\leftimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsw5cae.tmp\btmimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsw5cae.tmp\confirm.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsw5cae.tmp\finish.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsw5cae.tmp\header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsw5cae.tmp\iswelcome.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsw5cae.tmp\leftimg.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\shi2d6a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\shi3293.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\shi698e.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\~nsu.tmp\au_.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\securityxploded\process network monitor 6.0\install\holder0.aiph Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Dfhgnyoy\AppData\Local\Temp\~nsu.tmp\Au_.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Dfhgnyoy\AppData\Local\Temp\~nsu.tmp\Au_.exe\??\C:\Users\Dfhgnyoy\AppData\Local\Temp\~nsu.tmp RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Gpfetuov\AppData\Local\Temp\~nsu.tmp\Au_.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Gpfetuov\AppData\Local\Temp\~nsu.tmp\Au_.exe\??\C:\Users\Gpfetuov\AppData\Local\Temp\~nsu.tmp RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Vcjmpnmu\AppData\Local\Temp\~nsu.tmp\Au_.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Vcjmpnmu\AppData\Local\Temp\~nsu.tmp\Au_.exe\??\C:\Users\Vcjmpnmu\AppData\Local\Temp\~nsu.tmp RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Ol;�8 �vT������5!wz#�&� (�(X�1`1�1HO1�D9ߔ@V�H[uK��N�R20`�2g�Xi��j�bk`k�ql(�o�rnJtǤu�~y�9{�=�P��/������7�b:����X����T���.�a �T��T��m�Ù��IV���$�8���Κ��j���(��o RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Pl;�8 �vT������5!wz#�&� (�(X�1`1�1HO1�D9ߔ@V�H[uK��N�R20`�2g�Xi��j�bk`k�ql(�o�rnJtǤu�~y�9{�=�P��/������7�b:����X����T���.�a �T��T��m�Ù��IV���$�8���Κ��j���(��o RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::left RegNtPreCreateKey
Show More
HKCU\software\microsoft\ctf\msutb::top RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �mP8� �v ��T�����Bx$kF%�&� (�(X�)E*J1�1HO@V�A��G�IH[uH�pU_*_�za$b"hc�zh�rj�bk�ql(�q�XtǤvy�z��{b��P��jI�/������7����b:�������6�X��V�����.�a ���48��v�j���*��r� [�m�Ù� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �mQ8� �v ��T�����Bx$kF%�&� (�(X�)E*J1�1HO@V�A��G�IH[uH�pU_*_�za$b"hc�ze�vh�rj�bk�ql(�q�XtǤvy�z��{b��P��jI�/������7����b:�������6�X��V�����.�a ���48��v�j���*��r� [�m� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �mT8� �v ��T�����Bx$kF%�&� (�(X�)E*J,=�1�1HO@V�A��G�IH[uH�pN�U_*_�za$b"hc�ze�vh�rj�bk�ql(�q�XtǤvy�y�9z��{b��P��jI�/������7����b:�������6�X��V�����.�a ���48��v�j���* RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg �� �v xy ����T������%����3bBx�<��$kF%�&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1�1HO5,]=�@V�A��B��G�IH[uH�pJ��N$N�U_*X�.X�\te_�za$b"hc�wc�zh�ri��j�bk` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg �� �v xy ����T������%����3bBx�<��$kF%�&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1�1HO5,]=�@V�A��B��G�IH[uH�pJ��N$N�U_*X�.X�\te_�za$b"hc�wc�ze�vh�ri��j�b RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg �� �v xy ����T������%����3bBx�<��$kF%�&� &�-(�(X�(�)E)�`*J*9*�",=�-!R0P%1�1HO5,]=�@V�A��B��G�IH[uH�pJ��N$N�U_*X�.X�\te_�za$b"hc�wc�ze�vh�ri�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l! �v����Bx#��%�(�1`1�1HO@V�H[uH�pN$a$k`k�ql(��P���!���� ���3������m���gi�V�$�8���l� A�~B1_B��`�V�i�������Q]��@K�A*�"C��| RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l" �v����Bx#��%�(�1`1�1HO@V�H[uH�pN$a$e�vk`k�ql(��P���!���� ���3������m���gi�V�$�8���l� A�~B1_B��`�V�i�������Q]��@K�A*�"C��| RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
Show More
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx
Anti Debug
  • IsDebuggerPresent
  • OutputDebugString
User Data Access
  • GetUserName
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Keyboard Access
  • GetKeyState
Network Winsock2
  • WSAStartup
Network Winsock
  • getaddrinfo
  • gethostname

Shell Command Execution

"C:\Users\Dfhgnyoy\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
"C:\Users\Gpfetuov\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
"C:\Users\Vcjmpnmu\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
"C:\Users\Tlqqxdsa\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
"C:\Users\Pebtvvek\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\

Related Posts

Trending

Most Viewed

Loading...