PUP.Bar.H

The detection of PUP.Bar.H indicates that your system may be infected with a potentially unwanted program (PUP). This type of malware is designed to perform actions that are not necessarily malicious but can still cause problems for the user. PUPs can slow down your system, display unwanted advertisements, and even collect your personal data. In this report, we will provide you with information on what PUP.Bar.H is, how it operates, and most importantly, how to remove it from your system.

What Is PUP.Bar.H?

PUP.Bar.H is a type of potentially unwanted program that can be installed on your system without your knowledge or consent. It can be bundled with other software or downloaded from the internet. Once installed, it can perform various actions, such as displaying advertisements, collecting data, or changing your system settings. PUPs like PUP.Bar.H can be difficult to remove, as they often disguise themselves as legitimate programs or system files.

How PUP.Bar.H Operates

PUP.Bar.H operates by installing itself on your system and then performing its intended actions. It can create folders and files, modify system settings, and even interact with other programs. PUPs can also communicate with their creators or other malicious programs, allowing them to receive updates or send stolen data. The exact actions of PUP.Bar.H can vary, but its primary goal is to generate revenue for its creators, often at the expense of the user's experience and system performance.

Symptoms of Infection

If your system is infected with PUP.Bar.H, you may notice various symptoms. These can include slow system performance, unwanted advertisements or pop-ups, and changes to your system settings or browser configuration. You may also notice that your system is crashing or freezing more frequently, or that your personal data is being collected or sent to unknown parties. In some cases, PUPs can also install additional malware or create backdoors for other malicious programs to exploit.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Changes to system settings or browser configuration
  • Crashing or freezing system
  • Collection or transmission of personal data

How to Remove PUP.Bar.H

  1. Boot your system in Safe Mode with Networking to prevent PUP.Bar.H from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that may be related to PUP.Bar.H.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any changes made by the PUP.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that PUP.Bar.H has been completely removed.

Conclusion

Removing PUP.Bar.H from your system requires careful attention to detail and a comprehensive approach. By following the steps outlined in this report, you can effectively remove the PUP and restore your system to its normal state. It is essential to be cautious when downloading software or clicking on links, as PUPs can be easily installed without your knowledge or consent. By staying informed and taking proactive measures, you can protect your system and personal data from potentially unwanted programs like PUP.Bar.H.

Analysis Report

General information

Family Name: PUP.Bar.H
Signature status: Self Signed

Known Samples

MD5: 667c101c0425aa3256d4e4d1d5dcd831
SHA1: 7d4c2ff3e0b8357ffb089dfd09363edd2974fde8
SHA256: 68FF903DD7186E18F460664D156CBDED01B9ECEBB9AA34DDFB2237C1850A19F2
File Size: 686.93 KB, 686928 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Babylon Software Ltd.
File Description Babylon Setup SE
File Version 12.0.0.13
Internal Name Setup Stub
Legal Copyright Copyright © Babylon Software Ltd. 1997-2023
Original Filename SetupStub.exe
Product Name Babylon Setup
Product Version 12.0.0.13

Digital Signatures

Signer Root Status
Babylon Software LTD DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed

File Traits

  • big overlay
  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 456
Potentially Malicious Blocks: 42
Whitelisted Blocks: 414
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x 0 x 0 0 0 0 x x x x x x 0 x x x x x x x x x x x x x 0 x 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 x x 0 x x 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 0 0 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • KillMBR.XE

Files Modified

File Attributes
c:\users\user\appdata\local\temp\sudump.dmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\abortpage.aof Synchronize,Write Data
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\abortpage.aoi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\clientsetup.aof Synchronize,Write Data
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\clientsetup.aoi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\clientsetupstart.aof Synchronize,Write Data
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\clientsetupstart.aoi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\clientsetupstart.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\htmlscreens\loading.html Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\htmlscreens\naverror.html Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\htmlscreens\pbar.gif Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\iecookielow.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\setup.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\setup.ico Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\setupstrings.dat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\sqlite3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{47863303-bab0-7891-be34-8a05c3d6297d}\stp_bbl.dat Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �c�r�S��*����8��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�����B�����x�%���8�5����Bx�����\�!IN�sb!>!wz#@�#��#�O$kF$��%:�%f�%�'�'i'�!(�) ;)� RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Network Winhttp
  • WinHttpOpen
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetOpenUrl
  • InternetSetOption
Network Winsock2
  • WSAStartup

Shell Command Execution

"C:\Users\Stmqoimq\AppData\Local\Temp\{47863303-BAB0-7891-BE34-8A05C3D6297D}\setup.exe"

Related Posts

Trending

Most Viewed

Loading...