PUP.Bat2Exe.F

The detection of PUP.Bat2Exe.F on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Bat2Exe.F?

PUP.Bat2Exe.F is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They may be bundled with other software, downloaded from the internet, or installed through exploit kits.

How PUP.Bat2Exe.F Operates

PUP.Bat2Exe.F, like other PUPs, may operate by installing additional software, displaying unwanted advertisements, or collecting user data without consent. It may also modify system settings, registry entries, or browser configurations to achieve its goals. The exact behavior of PUP.Bat2Exe.F may vary, but its primary purpose is to generate revenue for its creators or serve as a conduit for more malicious activities.

Symptoms of Infection

The symptoms of a PUP.Bat2Exe.F infection may include slow system performance, unwanted pop-ups or advertisements, unexpected changes to browser settings or search engines, and the installation of additional software without user consent. You may also notice unusual network activity, suspicious processes running in the background, or unfamiliar icons on your desktop or system tray.

  • Unwanted changes to system settings or browser configurations
  • Slow system performance or crashes
  • Unusual network activity or suspicious processes
  • Unwanted pop-ups, advertisements, or search engine redirects

How to Remove PUP.Bat2Exe.F

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for internet access.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full system scan and detect any malware or PUPs present on your system.
  3. Uninstall any suspicious programs or software that may be related to the PUP.Bat2Exe.F infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions, add-ons, or modifications.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the PUP has been completely removed and that no additional threats are present.

Conclusion

Removing PUP.Bat2Exe.F from your system requires a combination of technical knowledge, caution, and the right tools. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and maintain the security and performance of your computer. Remember to always be cautious when downloading software, avoid suspicious links or attachments, and keep your operating system and security software up to date to minimize the risk of PUP infections.

Analysis Report

General information

Family Name: PUP.Bat2Exe.F
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 741afcf7fdb1dbda0e858b427481aaed
SHA1: c9f33a7413ce1fccf6826bd645c371107a8984ab
SHA256: 28C25FC93D8DACFF158A07D9744BA7070BBC16D43597E8CAD114AB09B64EDBD8
File Size: 82.94 KB, 82944 bytes
MD5: 93b2ab4476b9375e3d91dece51ba162e
SHA1: 84c319c8f35c2d1d7fcade79a482ff01857f9818
SHA256: 3A5DBCF74EBB20B1439A41E8D506C14B96F4C8CCA821AD80219425528ABA471A
File Size: 12.80 KB, 12800 bytes
MD5: 6dfc4ed97dd029cd66af99233a6e348b
SHA1: 54769a98d1a521eaa4142f6fe5b87568b4c75d5e
SHA256: ECCAC361C7D7B649974FD89A38FAEEEED18A46DD3558D50A392F2EAA5EA02CFA
File Size: 76.29 KB, 76288 bytes
MD5: 597efb3c5f10b92812af0a1f70758017
SHA1: 6316bddf326382cc51a17fcdb99581898a398ccd
SHA256: 684B1902D0CE1A3EC2A2DFF82872E0AEBFE9920595BE2D217DF07D667510F679
File Size: 9.22 KB, 9216 bytes
MD5: bc0042fdab4b082ce767ed9a9f08b492
SHA1: 837ee6acbc279292da3f8bf5ba2b0e60e897b2ed
SHA256: E6E927973D20D6A1734C4B2588D0E8393C7372CF632F7938CFC5BAABFBE0F671
File Size: 13.82 KB, 13824 bytes
Show More
MD5: c504a639ffeced9658263f03ffa9ae62
SHA1: e7b830ca080513e95cd75ca5c96e1c08b8327c06
SHA256: 356F62FEB2FB9BB952B255958E8B72ABAE7A6C309E0BFDF0FC8C344BF1B1F3D6
File Size: 131.58 KB, 131584 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 1,0,0,0

File Traits

  • 2+ executable sections
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 16
Potentially Malicious Blocks: 0
Whitelisted Blocks: 16
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bat2Exe.F
  • Downloader.Agent.D

Files Modified

File Attributes
c:\users\user\appdata\local\temp\1d0e.tmp\b2e.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\1fbe.tmp\batchfile.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\2b6c.tmp\b2e.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\2dfd.tmp\batchfile.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\4a2f.tmp\b2e.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\4c96.tmp\b2e.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\4eb9.tmp\batchfile.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\a822.tmp\b2e.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ab2f.tmp\batchfile.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ef72.tmp\b2e.exe Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\f231.tmp\batchfile.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\selfdel0.bat Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鰂ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 榀⬉ʾ鬎ʂ䈛x䀣ʲ茣ǧ숤ʨ䠱O᤹˃噀ñ뽹ɞ傄ë횎ǜɼķ鶝’꾢ʊ閾ʴ淃駃ó⟋ʪ䧌V柏ũߙĤ¶⣳ġjᰂŁ鈄ĞꀌʎἘě鍂€ꩠŖÉ窵ň RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ៚漠ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鰅ȁ攘ť獖} 偫~ 엦1eꙥžܰ엦1¶iꙥžr=֢vꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鲀ȁਪˣ鈯ˣ遙̃豤̃অˣ炑̃濖̃賬̃獖}਷ˣ邯̃뫯ʃ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 8k' �v����(�1�1HO@V�H[u_�zb"hj�bk�qw�n{b��P��jI�/������7�M�b:�������X������a ��*�m�Ù��IV����$�8წ���&M�(!��j��=�S/�.SLB1_T�Vw�`�V��%�������AE�Q]��D��&��$��� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 뉀蜤玧ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 1k 8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� 6 xy* �/��Y�d�kP~� ��ރ�p��^�o���zee*Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 2k 8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 졖ﱼ西ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� 6 xy* �/��Y�d�kP~� ��ރ�p��^�o���zee+Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 掠﹞西ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 闶ȁ ਪˣ鈯ˣ遙̃豤̃অˣ炑̃龡^濖̃賬̃獖}偫~엦1਷ˣ邯̃뫯ʃe¶r ֢ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 lkz8�jg �� �v �� ۀ��T������%��3bBx��#��$kF&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1`1�1HO5,]@V�A��B��G�IH[uH�pN$U_*X�.\te_�zb"hc�wc�zh�rj�bk`k�ql(�lR o��q�XtǤvy�v�!w�n RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 溕琌늊ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 陙ȁ ਪˣ鈯ˣ遙̃豤̃অˣ炑̃龡^濖̃賬̃獖} 偫~ 엦1਷ˣ邯̃뫯ʃeꙥžࠄ엦1*¶fꙥžiUꙥžr;֢sꙥžvꙥž RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ⇛銌ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::enablelua RegNtPreCreateKey
HKCU\console::virtualterminallevel  RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��  xy* �/��Y�d�kP~� ��ރ�p,��^�o�eeaVs}EkP~E��1B��7 ���ﺃePe���"D��1P��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m8��8tXz�jg�B�8 �� �6 �v z �Z xy �� �a��T�B�����������5���� +Bx�<��5�R �!wz"Wc#�#��$kF$��%:�%`�%�&� &�-(�(X�)E)�`*J*9*�"+�[,=�,��-!R/9�/��0P% RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecute
  • ShellExecuteEx
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Terminate
  • TerminateProcess

Shell Command Execution

open C:\Users\Pwjkoeng\AppData\Local\Temp\2B6C.tmp\b2e.exe C:\Users\Pwjkoeng\AppData\Local\Temp\2B6C.tmp\b2e.exe c:\users\user\downloads "c:\users\user\downloads\c9f33a7413ce1fccf6826bd645c371107a8984ab_0000082944"
open C:\Users\Pwjkoeng\AppData\Local\Temp\2DFD.tmp\batchfile.bat
WriteConsole: The system canno
WriteConsole: The system canno
WriteConsole: The system canno
Show More
WriteConsole: Could Not Find c
WriteConsole: The system canno
WriteConsole: The system canno
WriteConsole: 'w.bat' is not r
WriteConsole: goto was unexpec
open C:\Users\Pwjkoeng\AppData\Local\Temp\selfdel0.bat
open C:\Users\Qcyhfkna\AppData\Local\Temp\1D0E.tmp\b2e.exe C:\Users\Qcyhfkna\AppData\Local\Temp\1D0E.tmp\b2e.exe c:\users\user\downloads "c:\users\user\downloads\84c319c8f35c2d1d7fcade79a482ff01857f9818_0000012800"
open C:\Users\Qcyhfkna\AppData\Local\Temp\1FBE.tmp\batchfile.bat
open C:\Users\Smntfksk\AppData\Local\Temp\A822.tmp\b2e.exe C:\Users\Smntfksk\AppData\Local\Temp\A822.tmp\b2e.exe c:\users\user\downloads "c:\users\user\downloads\54769a98d1a521eaa4142f6fe5b87568b4c75d5e_0000076288"
open C:\Users\Smntfksk\AppData\Local\Temp\AB2F.tmp\batchfile.bat
WriteConsole: c:\users\user\do
WriteConsole: The syntax of th
WriteConsole: c:\Users\user\do
WriteConsole: === Backup Data
WriteConsole: 'exp' is not rec
open C:\Users\Smntfksk\AppData\Local\Temp\selfdel0.bat
open C:\Users\Jqgpnhbn\AppData\Local\Temp\EF72.tmp\b2e.exe C:\Users\Jqgpnhbn\AppData\Local\Temp\EF72.tmp\b2e.exe c:\users\user\downloads "c:\users\user\downloads\6316bddf326382cc51a17fcdb99581898a398ccd_0000009216"
open C:\Users\Jqgpnhbn\AppData\Local\Temp\F231.tmp\batchfile.bat
WriteConsole: ****************
WriteConsole:
WriteConsole: - SwissMan
WriteConsole: ( CRO Rati
WriteConsole: obnavlja sta
WriteConsole: na C-dis
WriteConsole: Press any key to
WriteConsole: Administrato
WriteConsole: pravo Ime ko
WriteConsole: za odustajan
WriteConsole: xxx
WriteConsole: koncentriraj
WriteConsole: Ubaci sistemsko
open C:\Users\Rwhdhgfb\AppData\Local\Temp\4C96.tmp\b2e.exe C:\Users\Rwhdhgfb\AppData\Local\Temp\4C96.tmp\b2e.exe c:\users\user\downloads "c:\users\user\downloads\837ee6acbc279292da3f8bf5ba2b0e60e897b2ed_0000013824"
open C:\Users\Rwhdhgfb\AppData\Local\Temp\4EB9.tmp\batchfile.bat
C:\WINDOWS\system32\reg.exe Reg.exe ADD "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v "EnableLUA" /t REG_DWORD /d "0" /f
C:\WINDOWS\system32\reg.exe Reg.exe add "HKCU\CONSOLE" /v "VirtualTerminalLevel" /t REG_DWORD /d "1" /f
open C:\Users\Ddafzizj\AppData\Local\Temp\4A2F.tmp\b2e.exe C:\Users\Ddafzizj\AppData\Local\Temp\4A2F.tmp\b2e.exe c:\users\user\downloads "c:\users\user\downloads\e7b830ca080513e95cd75ca5c96e1c08b8327c06_0000131584"

Related Posts

Trending

Most Viewed

Loading...