PUP.ServU

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 0
First Seen: January 19, 2011
OS(es) Affected: Windows

The detection of PUP.ServU on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. PUPs are software applications that, while not necessarily malicious, can cause a range of problems, from annoying pop-ups and redirects to more serious issues like data theft and system instability.

What Is PUP.ServU?

PUP.ServU is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. It is designed to serve unknown purposes, potentially including the collection of user data, the display of unwanted advertisements, or the installation of additional unwanted software. PUPs like PUP.ServU can be bundled with other software applications, or they may be installed through exploits or other malicious means.

How PUP.ServU Operates

PUP.ServU operates by installing itself on your system and then running in the background, often without your knowledge or consent. It may communicate with remote servers to send and receive data, or it may install additional software components to carry out its functions. In some cases, PUP.ServU may also modify system settings or configure itself to start automatically when your computer boots up. The exact nature of PUP.ServU's operations can vary, but its presence on your system is likely to cause problems and compromise your security.

Symptoms of Infection

The symptoms of a PUP.ServU infection can vary, but common indicators include unwanted pop-ups, redirects, and advertisements, as well as slower system performance, crashes, and instability. You may also notice that your browser settings have been changed, or that unfamiliar programs are running in the background. In some cases, PUP.ServU may also cause problems with your internet connection, or interfere with the operation of other software applications.

  • Unwanted pop-ups, redirects, and advertisements
  • Slower system performance, crashes, and instability
  • Changed browser settings
  • Unfamiliar programs running in the background
  • Problems with your internet connection
  • Interference with other software applications

How to Remove PUP.ServU

  1. Boot your computer in Safe Mode with Networking to prevent PUP.ServU from running and to give you a clean environment to work in.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.ServU and any other associated malware.
  3. Uninstall any suspicious programs that may be associated with PUP.ServU, taking care to follow the uninstallation instructions carefully.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by PUP.ServU.
  5. Reboot your computer and run another scan with your anti-malware tool to ensure that PUP.ServU has been completely removed.

Conclusion

The removal of PUP.ServU from your system is an important step in protecting your security and performance. By following the steps outlined above, you can help to ensure that your computer is free from this potentially unwanted program and any associated malware. Remember to always be cautious when installing new software, and to keep your anti-malware tools up to date to prevent future infections. With the right tools and a little knowledge, you can help to keep your computer safe and secure.

Analysis Report

General information

Family Name: PUP.ServU
Signature status: No Signature

Known Samples

MD5: 4dd19a2a628526db4f2a2afddb5402b5
SHA1: 6c31f78990b2b28fcbe35619a7f4d08d503d721c
SHA256: A4786383343F63B6975CDCCBB757A7B96756A4B8EE245D6EAD81D20C51588684
File Size: 2.88 MB, 2881896 bytes
MD5: 558d93711896ea0c1eec002617f3f998
SHA1: 9b85136b385067d6fd7edece7871c1175f372823
SHA256: 69254A4AD83317B400945FE0C5A707138F6F34146CBD8EA55B2090DC14DCE1A1
File Size: 2.54 MB, 2538496 bytes
MD5: 684c388af388cc61b2f3c72ec601c24b
SHA1: 9a285af585c476a2d8ae26fab0aef202490571ef
SHA256: 79D95D12E15AC0DF3FEAAEE51423E4C1E55E893479F3674841BCD357DF038A59
File Size: 102.40 KB, 102400 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup: http://www.innosetup.com
Company Name
  • Rhino Software, Inc.
  • Rhino Software, Inc. +1(262) 560-9627
File Description
  • Serv-U Setup
  • Serv-U® File Server DLL
  • Serv-U 系统托盘状态程序
File Version
  • 12, 1, 0, 8
  • 6.4.0.2
  • 6, 4, 0, 6
Internal Name
  • Serv-U®
  • ServUTray
Legal Copyright
  • Copyright (C) 1995-2012 - Rhino Software, Inc.
  • Copyright © 1995-2008 - Rhino Software, Inc.
Legal Trademarks
  • Serv-U is a trademark of Rhino Software, Inc.
  • Serv-U® is a registered trademark of Rhino Software, Inc.
Original Filename
  • Serv-U.dll
  • ServUTray.exe
Product Name
  • Serv-U FTP Server
  • Serv-U® File Server
Product Version
  • 12, 1, 0, 8
  • 6, 4, 0, 6

Digital Signatures

Signer Root Status
Rhino Software, Inc. UTN-USERFirst-Object Self Signed

File Traits

  • dll
  • Inno
  • InnoSetup Installer
  • Installer Manifest
  • Installer Version
  • x86

Block Information

Total Blocks: 317
Potentially Malicious Blocks: 0
Whitelisted Blocks: 297
Unknown Blocks: 20

Visual Map

? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 1 0 0 0 2 2 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 2 0 0 0 1 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::servutrayicon c:\users\user\downloads\9a285af585c476a2d8ae26fab0aef202490571ef_0000102400 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Service Control
  • OpenSCManager
  • OpenService

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\9b85136b385067d6fd7edece7871c1175f372823_0002538496.,LiQMAxHB