PUP.DotSetupIo

The detection of PUP.DotSetupIo on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent further problems.

What Is PUP.DotSetupIo?

PUP.DotSetupIo is a type of malware that is classified as a potentially unwanted program. This means that it may not be as damaging as other types of malware, such as viruses or Trojans, but it can still cause significant issues with your system. PUPs are often installed unintentionally by users, usually through bundled software downloads or misleading advertisements. They can collect user data, display unwanted ads, and slow down system performance.

How PUP.DotSetupIo Operates

PUP.DotSetupIo operates by installing itself on your system, often without your knowledge or consent. Once installed, it can start collecting user data, such as browsing history and search queries, and transmit it to its creators. It may also display unwanted advertisements, such as pop-ups or banners, and slow down your system by consuming system resources. In some cases, PUPs can also install additional malware or software on your system, leading to further problems.

Symptoms of Infection

If your system is infected with PUP.DotSetupIo, you may notice several symptoms. These can include slow system performance, unwanted advertisements, and suspicious programs or toolbars installed on your system. You may also notice that your browser homepage or search engine has been changed without your consent. Additionally, you may experience frequent crashes or freezes, and your system may become unstable.

  • Unwanted ads or pop-ups
  • Suspicious programs or toolbars installed
  • Slow system performance
  • Changed browser settings
  • Frequent crashes or freezes

How to Remove PUP.DotSetupIo

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware.
  3. Uninstall any suspicious programs or software that you don't recognize or need.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing PUP.DotSetupIo from your system is crucial to prevent further problems and protect your personal data. By following the steps outlined above, you can effectively remove this potentially unwanted program and restore your system to its normal state. It's essential to be cautious when downloading software and to always read user agreements and privacy policies carefully to avoid installing unwanted programs. Additionally, keeping your operating system and software up to date, using strong antivirus software, and being aware of online threats can help prevent future infections.

Analysis Report

General information

Family Name: PUP.DotSetupIo
Signature status: Root Not Trusted

Known Samples

MD5: df6ab261699e3728ca62666a684531a7
SHA1: 5c2b9b9124dc4b8c8d561e18f87e3a37d2fbf0a0
SHA256: DF845C2DFC62B727846A61806308A78F1C93C47E272E44D95BDF55806CD29F4D
File Size: 316.41 KB, 316408 bytes
MD5: 0a1d9adb2c415ad52f66a77f210e33f0
SHA1: f8e8813fb218ed652f7e554584dadd30ef034ed9
SHA256: A209BF4CED1EE999EBF1E55558E984FEF4C06F6DFCACEDAE4219DDBDAC351166
File Size: 300.06 KB, 300056 bytes
MD5: 86961c013b521f5795cc861626244156
SHA1: 6f01e7ebacbcf1630dc06523273b3da94dfb2b65
SHA256: 66D71566DFCA25549BA849C627EB0FEB8693C5CA0D095F9B3963A092EA559A68
File Size: 316.41 KB, 316408 bytes
MD5: c35622ba936f78ac50db978118eef2d8
SHA1: 0246c4234093c5a675a587da1a357de11be25111
SHA256: ED6950049C589EB0F4B04C3F1F5AD6C64688A7D134FBBA7D4DFEA4AF0D17F438
File Size: 316.41 KB, 316408 bytes
MD5: 1a52a2b0162e506c9bcbd26389f03a8b
SHA1: 53449fc3b38e1e63b1d1e8e19197b7f8fcec77f5
SHA256: F7A3F3E71D47E9EA515E4FC03510267AE9596F761D74F395A57F51E9082CEC06
File Size: 228.54 KB, 228536 bytes
Show More
MD5: 28b274163b08ce454b4fe7c5f066002d
SHA1: d62d711f014313b80812a2cb638dd10b469d38c5
SHA256: 8ED3888F8180D687C345F5984EA624B617B5F56739CFD176D38A8B8E750B6565
File Size: 316.41 KB, 316408 bytes
MD5: a1ed533099f199731bbead71cf2d71fd
SHA1: b401a53ed164d990713c14a8492e786f016dcb6d
SHA256: 1C364EADACA754254FAC676BC3F30DEA77E66E26CA1EE3F11D7C10010D894D33
File Size: 273.91 KB, 273912 bytes
MD5: a46a5db98c756737d851f339aedc4015
SHA1: baf643bc3ddcffc29945856ff531f29bae66e3ac
SHA256: BBA01ABC344F5C9B7C8113D38CFCABADE919D0482BAEFA0EC384FB8D281C84C0
File Size: 273.91 KB, 273912 bytes
MD5: a59d014ecd34923dad8c2173631b04a9
SHA1: 7583baf0d1bdad6f3c8b3d0a0f75a8ecf7a02810
SHA256: EC3FAA404A969BAA547B56B14131A3602B2DA31E3A4BDE7832F1CF9ACEE35790
File Size: 300.06 KB, 300056 bytes
MD5: 7bf5aad1d5776c03d47df69e2c11bac3
SHA1: d8caec4a69839dbd1f35399d2e0e848aa6636aad
SHA256: 8B49D3E48392601B1BEE4A088145F8CEEB182EE4FEE1B5A8BEB2217D746BFC50
File Size: 300.06 KB, 300056 bytes
MD5: 82613194f0bfc562c28ba537bc2f6591
SHA1: b2876ab53c143494829c744ff4620433834a13e1
SHA256: 4BD0D3ADE9640951911D84FDBA5ADE07113B8C121E9470F6FF96C42BAE7C5577
File Size: 316.41 KB, 316408 bytes
MD5: b75fdf23226d2ce714a502d787620a9f
SHA1: 88a39e009dc97ac2e7b8d2f9bcdc8e50d02ca3f6
SHA256: 977627C1AB2990E2D4D23D4D70DBDB20422BE67CFBE9D0A8A018915D6B8F6FE7
File Size: 319.99 KB, 319992 bytes
MD5: 7333c845c0a4ae710bbbae7195386773
SHA1: 130730745fc746408f2e0e047f381ea9dee78ccc
SHA256: 0A2ACAB3C86336B41F4F297E6A33B52DC7652648C727319D7915BCC9A18C6D1E
File Size: 41.41 KB, 41408 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File has exports table
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 4.0.1.2
  • 4.0.1.1
  • 4.0.1.0
  • 1.92.3.8643
  • 0.0.0.0
Comments
  • DotSetupSDK Installer
  • MD_Utils Helper
  • Microvirt Installer
  • SDKx86
File Description
  • DotSetupSDK Installer
  • Microvirt Installer
  • SDKx86
  • Utils_MDS
File Version
  • 4.0.1.2
  • 4.0.1.1
  • 4.0.1.0
  • 1.92.3.8643
  • 0.0.0.0
Internal Name
  • DotSetup.dll
  • DotSetupSDK.dll
  • mds.dll
  • utils_mds.dll
Legal Copyright
  • Copyright
  • Copyright dotSetup.io Open Source Project
  • Copyright Microvirt
  • Copyright SDKx86.
  • Copyright Utils MDS.
Original Filename
  • DotSetup.dll
  • DotSetupSDK.dll
  • mds.dll
  • utils_mds.dll
Product Name
  • DotSetup
  • DotSetupSDK Installer
  • MDUtils
  • Microvirt Installer
  • SDKx86
Product Version
  • 4.0.1.2
  • 4.0.1.1
  • 4.0.1.0
  • 1.92.3.8643
  • 0.0.0.0

Digital Signatures

Signer Root Status
Noviadigm Sectigo Public Code Signing Root R46 Root Not Trusted

Block Information

Total Blocks: 78
Potentially Malicious Blocks: 40
Whitelisted Blocks: 38
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x 0 0 0 0 0 0 x x 0 0 x 0 0 x x x x x x x x x x 0 x 0 0 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • DotSetupIo.A
  • DotSetupIo.B

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5c2b9b9124dc4b8c8d561e18f87e3a37d2fbf0a0_0000316408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f8e8813fb218ed652f7e554584dadd30ef034ed9_0000300056.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6f01e7ebacbcf1630dc06523273b3da94dfb2b65_0000316408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0246c4234093c5a675a587da1a357de11be25111_0000316408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\53449fc3b38e1e63b1d1e8e19197b7f8fcec77f5_0000228536.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d62d711f014313b80812a2cb638dd10b469d38c5_0000316408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7583baf0d1bdad6f3c8b3d0a0f75a8ecf7a02810_0000300056.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d8caec4a69839dbd1f35399d2e0e848aa6636aad_0000300056.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b2876ab53c143494829c744ff4620433834a13e1_0000316408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\88a39e009dc97ac2e7b8d2f9bcdc8e50d02ca3f6_0000319992.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\130730745fc746408f2e0e047f381ea9dee78ccc_0000041408.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...