PUP.BadJoke.PI

The detection of PUP.BadJoke.PI on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take prompt action to remove it to prevent potential harm.

What Is PUP.BadJoke.PI?

PUP.BadJoke.PI is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as harmful as other types of malware, such as viruses or Trojans, it can still cause problems with your system and compromise your personal data. PUPs are often installed unintentionally, and they can be difficult to remove without the right tools and guidance.

How PUP.BadJoke.PI Operates

PUPs like PUP.BadJoke.PI typically operate by installing themselves on your system without your knowledge or consent. They may be bundled with other software, or they may be downloaded from the internet through deceptive means. Once installed, PUPs can collect your personal data, display unwanted advertisements, and slow down your system's performance. They may also install additional malware or create backdoors for other malicious programs to exploit.

Symptoms of Infection

If your system is infected with PUP.BadJoke.PI, you may notice a range of symptoms, including slow system performance, unwanted pop-ups and advertisements, and unexpected changes to your browser settings. You may also notice that your system is crashing or freezing frequently, or that your personal data is being collected and transmitted to unknown parties. In some cases, PUPs can also install additional malware or create backdoors for other malicious programs to exploit.

  • Unwanted pop-ups and advertisements
  • Slow system performance
  • Unexpected changes to browser settings
  • System crashes or freezes
  • Unexplained data collection and transmission

How to Remove PUP.BadJoke.PI

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan to detect and remove the PUP.
  3. Uninstall any suspicious programs that may be related to the PUP, and be cautious when installing new software to avoid bundling with other PUPs.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any unwanted extensions or add-ons.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.BadJoke.PI from your system requires careful attention to detail and the right tools. By following the steps outlined above, you can help to ensure that your system is safe and secure. Remember to always be cautious when installing new software, and never click on suspicious links or download attachments from unknown sources. By taking these precautions, you can help to prevent future infections and keep your system running smoothly and securely.

Analysis Report

General information

Family Name: PUP.BadJoke.PI
Signature status: No Signature

Known Samples

MD5: a917d77d01c355f8d86d2925f793629e
SHA1: 8e06f16d4f099666714f1ee34a7a98129bda2615
SHA256: 0068141D4E450674B367482C32754B0EEA6D3A9CBA76B6BF54C59E5CF451F449
File Size: 641.51 KB, 641509 bytes
MD5: 9bf00aa3391bf42c3c75a87340cc5cca
SHA1: 204e8f9bc9ed0195e6477d18fbfdb1a6cae65419
SHA256: A27F345D8955814E1B772C50860458A6F6FC0B9E22D8D9566301D00E50FB7EDD
File Size: 4.27 MB, 4267653 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Nenad Hrg (SoftwareOK.de)
Company Name Nenad Hrg (SoftwareOK.com)
File Description
  • TheAeroClock
  • Twisted Lands: Origin
File Version
  • 3, 8, 1, 0
  • 1, 0, 0, 1
Internal Name
  • TheAeroClock
  • Twisted Lands: Origin
Legal Copyright
  • Copyright (C) 2012
  • Copyright © 2011-2015
Original Filename
  • TheAeroClock.exe
  • Twisted Lands: Origin
Product Name
  • TheAeroClock SoftwareOK.com
  • Twisted Lands: Origin
Product Version
  • 3, 8, 1, 0
  • 1, 0, 0, 0
Thin App Build Date Time
  • 20150816 131735
  • 20161008 211209
Thin App License
  • PORTAL PORTABLES BRASIL
  • VMware ThinApp
Thin App Version
  • 5.1.1-2722044

File Traits

  • big overlay
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 534
Potentially Malicious Blocks: 183
Whitelisted Blocks: 351
Unknown Blocks: 0

Visual Map

x x x x x 0 x x x x x x x x x x x 0 x x x 0 0 x 0 0 0 x x x x x x x x x x x x x x 0 x x x 0 x x 0 x 0 x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x x x x 0 x x x x x x 0 x x 0 x x x 0 x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x x x x x x x x 0 0 x x x x 0 0 x x x x x x x 0 x x x x x 0 x x x x 0 x x 0 x x x x x 0 0 0 0 0 x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x 0 0 0 x x x x x 0 x x x 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 2 2 0 0 1 1 0 0 0 0 1 1 0 0 1 0 0 0 0 0 2 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 2 3 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 1 0 0 0 1 1 1 0 1 1 1 0 0 1 1 0 1 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 1 0 0 1 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\downloads\theaeroclock\registry.rw.tvr Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\theaeroclock\registry.rw.tvr.lck Synchronize,Write Data
c:\users\user\downloads\theaeroclock\registry.rw.tvr.lck.desktop-dlos3m3.ffffffff.1894 Generic Write,Read Attributes
c:\users\user\downloads\theaeroclock\registry.rw.tvr.transact Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\theaeroclock\registry.rw.tvr.transact Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\downloads\theaeroclock\registry.tlog Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\theaeroclock\registry.tlog.cache Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation

Related Posts

Trending

Most Viewed

Loading...