PUP.Bat2Exe.F
The detection of PUP.Bat2Exe.F on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.
Table of Contents
What Is PUP.Bat2Exe.F?
PUP.Bat2Exe.F is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They may be bundled with other software, downloaded from the internet, or installed through exploit kits.
How PUP.Bat2Exe.F Operates
PUP.Bat2Exe.F, like other PUPs, may operate by installing additional software, displaying unwanted advertisements, or collecting user data without consent. It may also modify system settings, registry entries, or browser configurations to achieve its goals. The exact behavior of PUP.Bat2Exe.F may vary, but its primary purpose is to generate revenue for its creators or serve as a conduit for more malicious activities.
Symptoms of Infection
The symptoms of a PUP.Bat2Exe.F infection may include slow system performance, unwanted pop-ups or advertisements, unexpected changes to browser settings or search engines, and the installation of additional software without user consent. You may also notice unusual network activity, suspicious processes running in the background, or unfamiliar icons on your desktop or system tray.
- Unwanted changes to system settings or browser configurations
- Slow system performance or crashes
- Unusual network activity or suspicious processes
- Unwanted pop-ups, advertisements, or search engine redirects
How to Remove PUP.Bat2Exe.F
- Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for internet access.
- Use a reputable anti-malware tool, such as SpyHunter, to perform a full system scan and detect any malware or PUPs present on your system.
- Uninstall any suspicious programs or software that may be related to the PUP.Bat2Exe.F infection.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions, add-ons, or modifications.
- Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the PUP has been completely removed and that no additional threats are present.
Conclusion
Removing PUP.Bat2Exe.F from your system requires a combination of technical knowledge, caution, and the right tools. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and maintain the security and performance of your computer. Remember to always be cautious when downloading software, avoid suspicious links or attachments, and keep your operating system and security software up to date to minimize the risk of PUP infections.
Analysis Report
General information
| Family Name: | PUP.Bat2Exe.F |
|---|---|
| Packers: | UPX |
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
741afcf7fdb1dbda0e858b427481aaed
SHA1:
c9f33a7413ce1fccf6826bd645c371107a8984ab
SHA256:
28C25FC93D8DACFF158A07D9744BA7070BBC16D43597E8CAD114AB09B64EDBD8
File Size:
82.94 KB, 82944 bytes
|
|
MD5:
93b2ab4476b9375e3d91dece51ba162e
SHA1:
84c319c8f35c2d1d7fcade79a482ff01857f9818
SHA256:
3A5DBCF74EBB20B1439A41E8D506C14B96F4C8CCA821AD80219425528ABA471A
File Size:
12.80 KB, 12800 bytes
|
|
MD5:
6dfc4ed97dd029cd66af99233a6e348b
SHA1:
54769a98d1a521eaa4142f6fe5b87568b4c75d5e
SHA256:
ECCAC361C7D7B649974FD89A38FAEEEED18A46DD3558D50A392F2EAA5EA02CFA
File Size:
76.29 KB, 76288 bytes
|
|
MD5:
597efb3c5f10b92812af0a1f70758017
SHA1:
6316bddf326382cc51a17fcdb99581898a398ccd
SHA256:
684B1902D0CE1A3EC2A2DFF82872E0AEBFE9920595BE2D217DF07D667510F679
File Size:
9.22 KB, 9216 bytes
|
|
MD5:
bc0042fdab4b082ce767ed9a9f08b492
SHA1:
837ee6acbc279292da3f8bf5ba2b0e60e897b2ed
SHA256:
E6E927973D20D6A1734C4B2588D0E8393C7372CF632F7938CFC5BAABFBE0F671
File Size:
13.82 KB, 13824 bytes
|
Show More
|
MD5:
c504a639ffeced9658263f03ffa9ae62
SHA1:
e7b830ca080513e95cd75ca5c96e1c08b8327c06
SHA256:
356F62FEB2FB9BB952B255958E8B72ABAE7A6C309E0BFDF0FC8C344BF1B1F3D6
File Size:
131.58 KB, 131584 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has been packed
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| File Version | 1,0,0,0 |
File Traits
- 2+ executable sections
- No Version Info
- packed
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 16 |
|---|---|
| Potentially Malicious Blocks: | 0 |
| Whitelisted Blocks: | 16 |
| Unknown Blocks: | 0 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Bat2Exe.F
- Downloader.Agent.D
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\temp\1d0e.tmp\b2e.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\1fbe.tmp\batchfile.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2b6c.tmp\b2e.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2dfd.tmp\batchfile.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\4a2f.tmp\b2e.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\4c96.tmp\b2e.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\4eb9.tmp\batchfile.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\a822.tmp\b2e.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\ab2f.tmp\batchfile.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\ef72.tmp\b2e.exe | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\f231.tmp\batchfile.bat | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\selfdel0.bat | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 鰂 ȁ 獖} | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | 榀 ⬉ʾ鬎ʂ䈛x䀣ʲ茣ǧ숤ʨ䠱O᤹˃噀ñ뽹ɞ傄ë횎ǜɼķ鶝꾢ʊ閾ʴ淃駃ó⟋ʪ䧌V柏ũߙĤ¶⣳ġj ᰂŁ鈄ĞꀌʎἘě鍂ꩠŖÉ窵ň | RegNtPreCreateKey |
Show More
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ៚漠ǜ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 鰅 ȁ 攘ť 獖} 偫~ 엦1e ꙥܰ 엦1 ¶i ꙥr = ֢v ꙥ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 鲀 ȁ ਪˣ 鈯ˣ 遙̃ 豤̃ অˣ 炑̃ 濖̃ 賬̃ 獖} ˣ 邯̃ 뫯ʃ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | 8k ' |