PUP.Dsztfso

The detection of PUP.Dsztfso on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. PUPs are software applications that are not necessarily malicious but can still pose a risk to your system's stability and privacy. In this report, we will provide you with information on what PUP.Dsztfso is, how it operates, its symptoms, and most importantly, how to remove it from your system.

What Is PUP.Dsztfso?

PUP.Dsztfso is a type of potentially unwanted program that can be installed on your system without your knowledge or consent. It may be bundled with other software applications or downloaded from the internet. PUPs like PUP.Dsztfso can be used to display unwanted advertisements, collect user data, or install additional software applications that can further compromise your system's security.

How PUP.Dsztfso Operates

PUP.Dsztfso operates by installing itself on your system and then running in the background, often without your knowledge or consent. It may use various techniques to evade detection, such as disguising itself as a legitimate application or using misleading names and icons. Once installed, PUP.Dsztfso can start displaying unwanted advertisements, collecting user data, or installing additional software applications that can further compromise your system's security.

Symptoms of Infection

The symptoms of PUP.Dsztfso infection can vary, but common signs include unwanted advertisements, pop-ups, and banners displayed on your screen. You may also notice that your system is running slower than usual, or that your browser is being redirected to unwanted websites. Additionally, you may see suspicious programs or applications installed on your system that you do not recognize.

  • Unwanted advertisements and pop-ups
  • System slowdowns and performance issues
  • Browser redirects and unwanted website visits
  • Suspicious programs or applications installed on your system

How to Remove PUP.Dsztfso

  1. Boot your system in Safe Mode with Networking to prevent PUP.Dsztfso from running and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or applications associated with PUP.Dsztfso.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your consent.
  4. Reset your web browsers, including Google Chrome, Mozilla Firefox, and Microsoft Edge, to their default settings to remove any unwanted extensions or add-ons.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that PUP.Dsztfso has been completely removed.

Conclusion

Removing PUP.Dsztfso from your system requires careful attention to detail and a thorough removal process. By following the steps outlined in this report, you can help ensure that your system is free from the potentially unwanted program and any associated malware. Remember to always be cautious when downloading software applications from the internet and to use reputable anti-malware tools to protect your system from potential threats. Regular system scans and updates can also help prevent future infections and keep your system running smoothly and securely.

Analysis Report

General information

Family Name: PUP.Dsztfso
Signature status: Root Not Trusted

Known Samples

MD5: 69ab4148e84ae856ddafe44a4ed4070a
SHA1: f8d25f7a32d837ebff5b467a9dfb3365910afd7d
File Size: 4.01 MB, 4006248 bytes
MD5: e4c72ecf19d960ce816241b8e81f3e63
SHA1: 413c9425025ff7f7b9d6887c4d463d9fc79ff689
SHA256: 7347823C29B903837E2F2CA31EB0F3F28D7C6F31ED80152F1FDAC081A132F48A
File Size: 119.88 KB, 119880 bytes
MD5: 83b41824d889083e23b011238d900a77
SHA1: b65a69f22aefcec36c8ecc259558afc6d13c60bf
SHA256: 22C83E582C4DFC6A1899BEEA0A447E40CAC12CBC2B720F74126E28BE40BD9164
File Size: 3.44 MB, 3437424 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name TODO: <公司名>
File Description
  • TODO: <文件说明>
  • VMware安装小助手
  • 拳皇小助手
File Version
  • 1.1.0.0
  • 1.0.0.1
Internal Name
  • CMyControl.dll
  • setup.exe
Legal Copyright
  • Copyright (C)
  • TODO: (C) <公司名>。 保留所有权利。
Original Filename CMyControl.dll
Product Name
  • TODO: <产品名>
  • VMware安装小助手
  • 拳皇小助手
Product Version
  • 1.0.0.1
  • 1.0.0.0

Digital Signatures

Signer Root Status
南京博世嘉信文化传媒有限公司 DigiCert Trusted Root G4 Root Not Trusted
上海茹布网络科技有限公司 GlobalSign Root Not Trusted
上海茹布网络科技有限公司 GlobalSign Root Not Trusted

Files Modified

File Attributes
c:\users\user\appdata\local\temp\main.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-localization-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-misc-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-multibyte-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\gamepayment.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\httpreq.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\islsvmware.exe Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\main.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\installvmware\msvcp140.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\res\res.zip Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\tjf.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\installvmware\zlib.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-localization-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-misc-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-multibyte-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\gamepay.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\httpreq.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\mainzqh.exe Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\msvcp140.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\msvcr90.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\tjf.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\roaming\mainqh\zlib.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\fygame\soft-vmware::mn Օ���\�g�<ܪ�� RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSAStartup
Network Info Queried
  • GetAdaptersAddresses
Network Winsock
  • closesocket
  • connect
  • send
  • socket
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Shell Command Execution

"C:\Users\Ztqzpurc\AppData\Roaming\InstallVMware\islsvmware.exe" f8d25f7a32d837ebff5b467a9dfb3365910afd7d_0004006248.exe
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\413c9425025ff7f7b9d6887c4d463d9fc79ff689_0000119880.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...