PUP.Softomate.E

The detection of PUP.Softomate.E on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent further problems.

What Is PUP.Softomate.E?

PUP.Softomate.E is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as harmful as other types of malware, such as viruses or Trojans, it can still cause significant issues with your system. PUPs are often installed unintentionally by users, usually through bundled software downloads or deceptive advertising. They can lead to a range of problems, including slowed system performance, unwanted pop-ups, and compromised security.

How PUP.Softomate.E Operates

PUP.Softomate.E, like other PUPs, operates by installing itself on your system without your full knowledge or consent. It may do this by exploiting vulnerabilities in your system or by piggybacking on other software installations. Once installed, it can begin to cause a range of problems, including displaying unwanted advertisements, collecting your personal data, and slowing down your system's performance. PUPs can also make changes to your system settings and configuration, which can lead to further issues and security vulnerabilities.

Symptoms of Infection

If your system is infected with PUP.Softomate.E, you may notice a range of symptoms. These can include slowed system performance, unwanted pop-ups and advertisements, and changes to your system settings and configuration. You may also notice that your browser homepage has been changed, or that you are being redirected to unwanted websites. In some cases, PUPs can also cause your system to crash or freeze, or lead to issues with your internet connection.

  • Unwanted advertisements and pop-ups
  • Slowed system performance
  • Changes to system settings and configuration
  • Browser homepage changes
  • Redirects to unwanted websites
  • System crashes or freezes
  • Issues with internet connection

How to Remove PUP.Softomate.E

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to give you a clean environment to work in.
  2. Use a reputable malware removal tool, such as SpyHunter, to perform a full scan of your system and detect and remove any malicious files and settings.
  3. Uninstall any suspicious programs that may be related to the PUP. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by the PUP.
  5. Reboot your system and perform another scan with your malware removal tool to ensure that all remnants of the PUP have been removed.

Conclusion

Removing PUP.Softomate.E from your system is crucial to preventing further problems and protecting your personal data. By following the steps outlined above, you can effectively remove this PUP and restore your system to a safe and secure state. It's also essential to take steps to prevent future infections, including being cautious when downloading software, avoiding suspicious websites, and keeping your system and software up to date. Remember, prevention is key, and staying informed about the latest threats and security best practices can help you stay safe online.

Analysis Report

General information

Family Name: PUP.Softomate.E
Signature status: No Signature

Known Samples

MD5: b32fb898ee875d11a2f7aac2756ad87b
SHA1: 393cad7bb2c639478afdde86ebfe7f7114eb4ed2
SHA256: 932C0906262EA4B771426511304E81DDBCB7B1C52E6A13A72ADA4DB0D48DF673
File Size: 992.13 KB, 992131 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Oleg N. Scherbakov
File Description 7z Setup SFX
File Version 1, 3, 0, 1501
Internal Name 7ZSfxNew
Legal Copyright Copyright © 2005-2009 Oleg N. Scherbakov
Original Filename 7ZSfxNew.exe
Private Build September 7, 2009
Product Name 7ZSfxNew
Product Version 1, 3, 0, 1501

File Traits

  • HighEntropy
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop Synchronize,Write Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\crashrpt.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\crashrpt.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\regworkshop.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\regworkshop.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\regworkshop.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\regworkshop.ini Synchronize,Write Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\regworkshopx64.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\regworkshopx64.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\rwreg.txt Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\2k10\regworkshop\rwreg.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\rwresrus.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\2k10\regworkshop\rwresrus.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\classes\reg:: URL:Reg Protocol RegNtPreCreateKey
HKLM\software\classes\reg::url protocol (NULL) RegNtPreCreateKey
Show More
HKLM\software\classes\reg\shell\open\command:: "C:\Users\Fpljliwa\appdata\local\temp\2k10\regworkshop\regworkshopx64.exe" /g "%1" RegNtPreCreateKey
HKLM\software\classes\regfile\shell::editflags 虄椖 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xy�ރ ��^��zeePVs}kP~��1>��ee�����1��fe��ise��r��se��ue��ve��{e�� RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx
Keyboard Access
  • GetKeyState

Shell Command Execution

(NULL) RegWorkshopX64.exe

Related Posts

Trending

Most Viewed

Loading...