PUP.DotSetupIo.C

The detection of PUP.DotSetupIo.C on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to address this detection to prevent potential problems and maintain the integrity of your system.

What Is PUP.DotSetupIo.C?

PUP.DotSetupIo.C is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems, such as slowing down your system, displaying unwanted advertisements, or collecting your personal data. The name PUP.DotSetupIo.C suggests that it may be related to a setup or installation process, but the exact nature of this PUP is not immediately clear.

How PUP.DotSetupIo.C Operates

PUPs like PUP.DotSetupIo.C often operate by installing themselves on your system through various means, such as bundled software downloads, infected websites, or exploited vulnerabilities. Once installed, they may run in the background, consuming system resources and potentially causing problems. PUPs may also collect your personal data, such as browsing history or search queries, and transmit it to third-party servers. In some cases, PUPs may also display unwanted advertisements or modify your system settings without your consent.

Symptoms of Infection

If your system is infected with PUP.DotSetupIo.C, you may experience a range of symptoms, including slow system performance, unwanted advertisements or pop-ups, and changes to your system settings. You may also notice that your browser homepage or search engine has been modified without your consent. In some cases, you may experience crashes or freezes, or find that your system is running out of disk space due to the PUP's activities.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Changes to system settings
  • Browser modifications
  • Crashes or freezes
  • Disk space issues

How to Remove PUP.DotSetupIo.C

  1. Boot your system in Safe Mode with Networking to prevent the PUP from running and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious or unwanted files.
  3. Uninstall any suspicious programs or applications that may be related to the PUP.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any modifications made by the PUP.
  5. Reboot your system and perform a follow-up scan to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.DotSetupIo.C from your system is essential to prevent potential problems and maintain the integrity of your system. By following the steps outlined above, you can safely and effectively remove the PUP and restore your system to its normal state. It is also essential to practice good security habits, such as regularly updating your software, using strong passwords, and avoiding suspicious downloads, to prevent future infections. Remember to always use reputable anti-malware tools and to be cautious when installing new software or visiting unfamiliar websites.

Analysis Report

General information

Family Name: PUP.DotSetupIo.C
Packers: UPX
Signature status: Modified signature

Known Samples

MD5: b3778284a028dcc3f48e38b00174d600
SHA1: ecdf05a090a44a3a9d6eb95722f517dae65aa5b3
SHA256: F89A11889F809F7AEDCBAC97067F9CF8C3B920D55569BE337D13B6ED88DF7E54
File Size: 9.90 MB, 9895424 bytes
MD5: e631f464d74ccf80a86256e19863195d
SHA1: 86c41a0b5cebbcb9865d50a957c7c197ed895038
SHA256: 5519B02A91ED8F5E713737D12B2C8A046D61AF87BAEB8006217586A6399E152C
File Size: 7.01 MB, 7014240 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microvirt Software Technology Co. Ltd.
File Description
  • MEmu Uninstaller
  • 联想模拟器卸载程序
File Version
  • 8.0.8.0
  • 7.2.1.0
Internal Name MEmuSetup.exe
Legal Copyright
  • Copyright (C) 2020 Microvirt Software Technology Co. Ltd. All rights reserved
  • Copyright (C) 2022 Microvirt Software Technology Co. Ltd. All rights reserved
Original Filename MEmuSetup.exe
Product Name
  • MEmu Uninstaller
  • 联想模拟器卸载程序
Product Version
  • 8.0.8.0
  • 7.2.1.0

Digital Signatures

Signer Root Status
Shanghai Microvirt Software Technology Co., Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
Shanghai Microvirt Software Technology Co., Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed

File Traits

  • .UPX
  • 2+ executable sections
  • GetConsoleWindow
  • HighEntropy
  • imgui
  • Installer Manifest
  • Installer Version
  • packed
  • upx
  • UPX!
Show More
  • x86

Block Information

Total Blocks: 22,161
Potentially Malicious Blocks: 1,461
Whitelisted Blocks: 20,520
Unknown Blocks: 180

Visual Map

0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x x 0 0 0 x 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 x x x x ? ? ? 0 x x x x x x x x x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x ? x x x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? x x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? ? ? x x x x x x x ? ? ? ? ? ? x x ? 0 0 x x x x 0 0 x x ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? ? ? ? x 0 x x 0 x x 0 0 0 0 0 x x x x x x x x x 0 x x x ? x x x 0 x x ? 0 x x x x x x x 0 0 0 0 0 0 x ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x x x x x x ? ? x ? ? x 0 0 x 0 0 1 0 0 0 0 1 0 x 0 0 0 x 0 0 0 x ? 0 x x ? 0 0 0 x x 0 x x x 0 x 0 x 0 x 0 x 0 x 0 0 0 0 x x x 0 0 0 x x ? x ? 0 x x x x ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? x ? ? ? x ? ? ? ? ? ? x ? 0 ? 0 ? x ? x x 0 x x ? x x x x ? ? 0 x ? ? ? ? ? ? x 0 0 0 1 x x ? 0 ? x ? 0 x ? 0 0 x x ? ? ? x ? 0 x ? 0 x ? x x 0 x x ? ? ? ? ? x x x x x 0 0 0 x x x x 0 x x x ? x x 0 x 0 ? 0 0 0 0 0 0 x x x 0 x 0 0 0 x 0 x 0 0 0 0 x x 0 x x x x 0 0 x x x ? ? 0 0 x 0 0 x ? x x 0 0 x x 0 ? 0 x x x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 x ? x 0 0 x x x ? 0 x x x 0 0 x x x x 0 ? ? ? x ? x x ? ? 0 0 0 0 0 0 0 0 0 x x x 0 0 x x x 0 0 x x x x x 0 x ? 0 0 0 x x 0 0 x x x x x x x 0 0 0 0 x x x 0 0 x 0 x 0 x 0 x x x 0 x x x x x 0 0 0 0 0 0 x x x ? x ? x x 0 0 ? 0 x 0 x x x x x x 0 0 x x x x 0 x x x x x 0 x 0 x x 0 ? ? ? 0 0 ? 0 0 x x ? ? x ? ? 0 x x ? x 0 0 0 x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 x x 0 0 x x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • DotSetupIo.C

Files Modified

File Attributes
\device\namedpipe\__lemu_installer_pipe_name___ Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\__memu_installer_pipe_name__ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\lenovo\fusionengine\setup\lemusetup.log Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • OutputDebugString
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx
Network Info Queried
  • GetAdaptersInfo
Network Winsock2
  • WSAConnect
  • WSASend
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • getpeername
  • getsockname
  • setsockopt

Related Posts

Trending

Most Viewed

Loading...