PUP.SimpleFiles

Threat Scorecard

Popularity Rank: 15,955
Threat Level: 10 % (Normal)
Infected Computers: 33,277
First Seen: September 25, 2013
Last Seen: June 17, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove PUP.SimpleFiles

File System Details

PUP.SimpleFiles may create the following file(s):
# File Name MD5 Detections
1. SimpleFilesUpdater.exe 9657ba00089954583ae690df76f145d7 10,422
2. uninstall5267935.exe bc9e504665b1cb8ba8c2e17411d0e92f 2,682
3. uninstall5267779.exe fe1735da5d7941eb0056eebff40887b5 169
4. uninstall5267904.exe da056722395d5caf86e35617652476e2 99
5. SFUpdater.exe 6e6db79c9e607b16dcc649e105f9b7d8 22
6. SimpleFiles.exe bf958dfd29a44e7bc9993b5010263cf8 2
7. downloader.exe c4fa31f2ee4a89ba1196efb64a98fde1 2
8. uninstall.exe 6541de1b2b5fd4b008a1cf7b7ed27fb5 2
9. Installer.exe ef609a511a907c1d4e30fcbb3c2b6ed7 2
More files

Registry Details

PUP.SimpleFiles may create the following registry entry or registry entries:
File name without path
SimpleFiles.lnk
Regexp file mask
%TEMP%\SimpleFiles[RANDOM CHARACTERS].exe
%WINDIR%\System32\Tasks\SimpleFilesUpdate
%WINDIR%\System32\Tasks\Update Service SimpleFiles
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SimpleFilesUpdate
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Service SimpleFiles
Software\SimpleFiles
SOFTWARE\Wow6432Node\SimpleFiles

Directories

PUP.SimpleFiles may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\SimpleFiles
%APPDATA%\SimpleFiles
%PROGRAMFILES%\SimpleFiles
%PROGRAMFILES%\SimpleFilesUpdater
%PROGRAMFILES(x86)%\SimpleFiles
%PROGRAMFILES(x86)%\SimpleFilesUpdater

Analysis Report

General information

Family Name: PUP.SimpleFiles
Signature status: Root Not Trusted

Known Samples

MD5: 0dcf86bddccdb78bd5e654bb2863171d
SHA1: 08d26177d3db9220e2f21952c2eb0b9f0ff2e1c4
SHA256: 920DB848FC6F28BAC6AE4CC5AD84CFC122F1D6A546F5169C49FA216A4D635CA5
File Size: 1.36 MB, 1363088 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name http://SpottyFiles.com
File Description SpottyFiles
File Version 1.0.0.1
Internal Name Updater.exe
Legal Copyright Copyright http://SpottyFiles.com (C) 2012
Original Filename Updater.exe
Product Name SpottyFiles
Product Version 1.0.0.1

Digital Signatures

Signer Root Status
Technology Island, Inc. UTN-USERFirst-Object Root Not Trusted

Block Information

Total Blocks: 357
Potentially Malicious Blocks: 11
Whitelisted Blocks: 52
Unknown Blocks: 294

Visual Map

? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? x x ? ? 0 ? ? ? ? 0 ? x ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? 0 0 0 ? ? ? x ? 0 ? ? ? ? ? x ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? x ? ? ? x ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? x ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? x ? x 0 ? ? 0 ? ? ? ? ? 0 ? x ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...