PUP.MailRu.A

The detection of PUP.MailRu.A on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it to prevent further damage.

What Is PUP.MailRu.A?

PUP.MailRu.A is a type of malware that is classified as a potentially unwanted program. This means that it is not necessarily malicious in nature, but it can still cause problems with your system's stability and security. PUPs are often installed unintentionally by users, usually as a result of downloading software from untrusted sources or clicking on suspicious links. They can also be bundled with other software, making it difficult to detect and remove them.

How PUP.MailRu.A Operates

PUPs like PUP.MailRu.A typically operate by collecting user data, displaying unwanted advertisements, or modifying system settings without user consent. They can also slow down system performance, cause crashes, and increase the risk of other malware infections. In some cases, PUPs can even lead to more severe security threats, such as ransomware or Trojans, if left unchecked.

It is crucial to note that PUPs can be challenging to detect, as they often disguise themselves as legitimate programs or system files. They can also use various tactics to evade detection, such as code obfuscation or anti-debugging techniques. Therefore, it is essential to use reputable security software and follow best practices to prevent PUP infections.

Symptoms of Infection

If your system is infected with PUP.MailRu.A, you may experience a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and modified system settings. You may also notice that your browser homepage or search engine has been changed without your consent. In some cases, you may even experience crashes or freezes, especially when trying to launch certain programs or access specific system features.

  • Unwanted advertisements or pop-ups
  • Modified system settings or browser configurations
  • Slow system performance or crashes
  • Unexplained changes to system files or registry entries

How to Remove PUP.MailRu.A

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a more effective removal process.
  2. Use a reputable malware removal tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or registry entries associated with PUP.MailRu.A.
  3. Uninstall any suspicious programs or software that may be related to the PUP infection.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any modifications made by the PUP.
  5. Reboot your system and perform a follow-up scan to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.MailRu.A from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable security software, you can effectively remove this potentially unwanted program and prevent future infections. It is essential to remain vigilant and proactive in maintaining your system's security, as PUPs can evolve and become more sophisticated over time. By staying informed and taking the necessary precautions, you can protect your system and personal data from the risks associated with PUPs like PUP.MailRu.A.

Analysis Report

General information

Family Name: PUP.MailRu.A
Signature status: No Signature

Known Samples

MD5: d7a28031f2ba6b32b34459b8db4963eb
SHA1: 7ad86b6799b4218ad06d3010f69e5e1be8cdfbb5
SHA256: D7FB7AF069C19F2C1ECD67F8DA1285BC5BD20C715C8961CEB18964F7DE8B03C0
File Size: 428.03 KB, 428032 bytes
MD5: 28e074ffd1cfae43f698f942fcfc29a1
SHA1: 13c2096f93e2cd61a5586c31a4f65e4d9a50dfd0
SHA256: 635DBF0DB2E3CD96441CFCA02A1F7EA60FF6554A43FDF6279E3DC4C2AFECCD60
File Size: 428.03 KB, 428032 bytes
MD5: f1ed3aa775eb089e9a031b2f22861613
SHA1: 77cef38cf622ab754cafdda1c0793284c307c953
SHA256: A9D315779FD2E2EFD70AFED8E8C4C003E836AA0A8EDDBB903F2CF87DEE880D74
File Size: 397.31 KB, 397312 bytes
MD5: 67574b44e4d325987c871fff8a0c09f8
SHA1: 6b7d76367fc8a1dbe3c0f3f2d1cc405d0e2d4b3e
SHA256: 6F342E6969F4AD64193041F26C916291C9B2ABE7AAD7744D24F843DED6ABA321
File Size: 428.03 KB, 428032 bytes
MD5: 79a52ca43d3eddf2952fbe38e09fad80
SHA1: 2d97c30030f8e9b4e9776601acae68c1bae961fd
SHA256: EEE03C781CE31D9BCAA515707339218835D53E52B68124C1037DA9E0F566ED5D
File Size: 428.03 KB, 428032 bytes
Show More
MD5: f22ffe4796b817e13364a85b94830542
SHA1: 00e330997c450307a874f5d92c5e032a5aac7745
SHA256: 1D47635D1BF684C6ED25F08721752158402B2130F373765A12F0E2D2D223BB66
File Size: 428.03 KB, 428032 bytes
MD5: f45c21915c6af358d7b809081c93c9ba
SHA1: c2169ccda91fafcaa094c1bd436c209608e4118c
SHA256: 5727968B55760FE7C5A876E9A8BE642C8116DBF82A9B832827F5607E4C6EA703
File Size: 159.74 KB, 159744 bytes
MD5: 34b495cda41399aca795d3ef5ae23ad9
SHA1: cf5fc4d2d33f933d9e667f440533f8877dd8f0c9
SHA256: D21141CDBDC0BD787C79015F28EC77510D8B0E20D56C8261FF3DE831699E4E21
File Size: 428.03 KB, 428032 bytes
MD5: 64ba846f0df6143b02d94b255b01e081
SHA1: 41ec83cdc0f784578f4dcc85f3716dfdb7a2001b
SHA256: 23815C1154E7D4DE3CED9185ADDED3E7E3908CA81555D1E317E6D98F0B604503
File Size: 428.03 KB, 428032 bytes
MD5: 7959fe7c3a941fd230283f94ef853fe5
SHA1: eda721e22482647624ed062e9e687fea5eebec53
SHA256: 0C8A12B67E1E9CCC810E7FE73230B6784051D3E0D10616FC1C2FF04982DF03D6
File Size: 428.03 KB, 428032 bytes
MD5: fb2a6bce55b1b7bf12796daf3ba62491
SHA1: 61311fe92c126aa62fe08a1fd5fe115ea0882e39
SHA256: 430265E31071BCC65B4B67AE9FE465CCC98F19F9376ED0C9D3673D0A95219D56
File Size: 428.03 KB, 428032 bytes
MD5: 8620d39b1755610115fe9f382d66a42a
SHA1: d527c3317309caa29207adc5744b9bdf2007981b
SHA256: E4C192C76D4A9EEF47F715446E2B30EFC5A025DF26FDD582E22E331181E3A6AF
File Size: 453.12 KB, 453120 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 3.0.0.607
  • 1.0.0.0
Comments ZStat-System. Prüft Statistikdateien
Company Name
  • Corel Corp.
  • Schröder-Software, Berlin
  • Zitu Informatika S.L.
File Description
  • Actualizador Kudeaketa
  • TextArt 8 executable
  • TextArt 10 executable
  • ZStat_Prüfer_2019
File Version
  • 10.0.0.943
  • 8.0.0.223
  • 3.0.0.607
  • 1.0.0.0
Internal Name
  • TEXTART3D
  • Update.exe
  • ZStat_Prüfer_2022.exe
Legal Copyright
  • Copyright (c) 1996-99 Corel Corp. All Rights Reserved.
  • Copyright (c) 1996/97 Corel Corp. All Rights Reserved.
  • Copyright © - 2008
  • Copyright © 2019
Original Filename
  • textart.exe
  • Update.exe
  • ZStat_Prüfer_2022.exe
Product Name
  • Kudeaketa_act
  • TextArt
  • ZStat_Prüfer
Product Version
  • 10.0.0.943
  • 8.0.0.223
  • 3.0.0.607
  • 1.0.0.0

File Traits

  • .NET
  • .sdata
  • NewLateBinding
  • x86

Block Information

Total Blocks: 76
Potentially Malicious Blocks: 0
Whitelisted Blocks: 23
Unknown Blocks: 53

Visual Map

0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �v����&�-(�1�1HO@V�A��H[u_�zb"hk�q�P�������m��$�8���&MB1_��� RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱壤隞̃耀꧌Õ7 RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 848