PUP.MSIL.Bundler.B
The detection of PUP.MSIL.Bundler.B on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it to prevent further damage.
Table of Contents
What Is PUP.MSIL.Bundler.B?
PUP.MSIL.Bundler.B is a type of potentially unwanted program that is designed to bundle additional software with legitimate programs. This bundled software can include toolbars, adware, and other unwanted applications that can compromise your system's security and slow down its performance. PUPs like PUP.MSIL.Bundler.B are often installed without the user's knowledge or consent, and they can be challenging to remove.
How PUP.MSIL.Bundler.B Operates
PUP.MSIL.Bundler.B operates by bundling itself with other software, often freeware or shareware, and installing itself on your system without your explicit consent. Once installed, it can start displaying unwanted advertisements, collecting your personal data, and slowing down your system's performance. It may also install additional software or modify your system's settings to facilitate its malicious activities.
Symptoms of Infection
The symptoms of PUP.MSIL.Bundler.B infection can vary, but common signs include unwanted advertisements, slow system performance, and suspicious programs installed on your system. You may also notice that your browser's homepage or search engine has been changed, or that you are being redirected to unwanted websites. Additionally, you may experience frequent crashes or freezes, and your system may become more vulnerable to other malware infections.
- Unwanted advertisements and pop-ups
- Slow system performance and crashes
- Suspicious programs installed on your system
- Changes to your browser's settings and behavior
- Increased vulnerability to other malware infections
How to Remove PUP.MSIL.Bundler.B
- Boot your system in Safe Mode with Networking to prevent PUP.MSIL.Bundler.B from loading and to allow you to download and install removal tools.
- Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove PUP.MSIL.Bundler.B and any other malware.
- Uninstall any suspicious programs that you do not recognize or that were installed without your consent.
- Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by PUP.MSIL.Bundler.B.
- Reboot your system and perform another scan with your anti-malware tool to ensure that PUP.MSIL.Bundler.B has been completely removed.
Conclusion
Removing PUP.MSIL.Bundler.B from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above, you can effectively remove this potentially unwanted program and restore your system's security and performance. It is essential to remain vigilant and to regularly scan your system for malware to prevent future infections and ensure your system remains safe and secure.
Analysis Report
General information
| Family Name: | PUP.MSIL.Bundler.B |
|---|---|
| Signature status: | Hash Mismatch |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
046ad574583cbc7567dc59ed177601fd
SHA1:
8460fa3ca90174a7beaba96d64dffdd1918d5cdc
SHA256:
BD2D9B47F4DE34DB0447BC1EA3240C4A6FDED002BBF37607370B8B431ADB822F
File Size:
792.65 KB, 792653 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | Disc Soft Ltd. |
| File Description | DAEMON Tools Lite Installer |
| File Version | 1.4.24 |
| Internal Name | DAEMON Tools Lite Installer1.4.24.exe |
| Legal Copyright | Copyright (C) 2000-2017 |
| Original Filename | DTLiteInstaller1.4.24.exe |
| Product Name | DAEMON Tools Lite Installer |
| Product Version | 1.4.24 |
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| Disc Soft Ltd | COMODO RSA Code Signing CA | Hash Mismatch |
File Traits
- .NET
- HighEntropy
- Installer Manifest
- Installer Version
- x86
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\temp\appinstaller.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsqb176.tmp\system.dll | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory | %windir%\tracing | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing | RegNtPreCreateKey |
Show More
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory | %windir%\tracing | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Encryption Used |
|
| Network Winsock2 |
|
| Network Winsock |
|
| Network Winhttp |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\Users\Vgruwnus\AppData\Local\Temp\AppInstaller.exe
|