PUP.Passview.BC

The detection of PUP.Passview.BC on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. PUPs are software applications that are not necessarily malicious but can still pose a threat to your system's integrity and your personal data. In this report, we will provide you with information on what PUP.Passview.BC is, how it operates, its symptoms, and most importantly, how to remove it from your system.

What Is PUP.Passview.BC?

PUP.Passview.BC is a type of potentially unwanted program that is designed to perform certain functions on your computer without your explicit consent. While it may not be as harmful as other types of malware, such as viruses or Trojans, PUPs can still cause problems with your system's stability, slow down your computer, and even compromise your personal data. PUPs often find their way onto your system through bundled software downloads, infected websites, or phishing emails.

How PUP.Passview.BC Operates

Once PUP.Passview.BC is installed on your system, it can operate in various ways, depending on its intended purpose. Some common behaviors of PUPs include displaying unwanted advertisements, collecting your browsing data, and modifying your system's settings without your permission. In some cases, PUPs can also install additional software or plugins that can further compromise your system's security. It's essential to note that PUPs can be difficult to detect, as they often masquerade as legitimate software applications.

Symptoms of Infection

If your system is infected with PUP.Passview.BC, you may notice certain symptoms that indicate its presence. These can include unwanted pop-ups or advertisements, slow system performance, unexpected changes to your browser settings, and unfamiliar programs or icons on your desktop. You may also notice that your system is crashing or freezing more frequently than usual. If you suspect that your system is infected with PUP.Passview.BC, it's crucial to take immediate action to remove it.

How to Remove PUP.Passview.BC

To remove PUP.Passview.BC from your system, follow these steps:

  1. Boot your system in Safe Mode with Networking to prevent any malicious programs from loading.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove any malware, including PUP.Passview.BC.
  3. Uninstall any suspicious programs or applications that you don't recognize or need.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or plugins.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that PUP.Passview.BC has been completely removed.

Conclusion

In conclusion, PUP.Passview.BC is a potentially unwanted program that can cause problems with your system's performance and security. By understanding how it operates and following the removal steps outlined above, you can protect your system and your personal data from the potential risks associated with PUPs. Remember to always be cautious when downloading software or clicking on links from unknown sources, and keep your anti-malware tools up to date to ensure the best possible protection against malware and other online threats.

Analysis Report

General information

Family Name: PUP.Passview.BC
Signature status: No Signature

Known Samples

MD5: c30190fe322e579cb383dce4a1af3496
SHA1: 153c7e2d5363bb45d91453479cbb22e29d55eced
SHA256: 32E8D13AEE9BAABD1CDB7C981232420D5E3F2A8A06DBBCBAEBE883F0DAF3A702
File Size: 153.70 KB, 153696 bytes
MD5: 7c696ab72885ae480e2ce68a31102bd1
SHA1: 9af8b13400d7c32be48cdd76395f7901e9b2283a
SHA256: 268CB1722BE26F8B671743FD5C940A8B857F71EC8159D6A022BDA73D7D040E49
File Size: 67.07 KB, 67072 bytes
MD5: d0f63ca49c777a178dfab65063048940
SHA1: c8b0734a1a3f2b73779f1a24851cb3a543a2a1b6
SHA256: 3A2173858B65AA6C20E903794A6DF5C92E5EE73DA6375AF4624788C6205CCF9D
File Size: 131.88 KB, 131879 bytes
MD5: def116cc56cc2ee1f84a916102cc1cda
SHA1: f89fc44d6ac31e1efe5ca5248b56c26bcc957d28
SHA256: 24F43D3A80C136147CFADF250ED2DE0ACD78460F08EF6CB27E514DD9B9D5F0C7
File Size: 437.18 KB, 437179 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name NirSoft
File Description
  • BulletsPassView
  • WebCamImageSave
File Version
  • 1.32
  • 1.11
Internal Name
  • BulletsPassView
  • WebCamImageSave
Legal Copyright
  • Copyright © 2010 - 2015 Nir Sofer
  • Copyright © 2011 - 2012 Nir Sofer
Original Filename
  • BulletsPassView.exe
  • WebCamImageSave.exe
Product Name
  • BulletsPassView
  • WebCamImageSave
Product Version
  • 1.32
  • 1.11

File Traits

  • 2+ executable sections
  • HighEntropy
  • packed
  • SusSec
  • WriteProcessMemory
  • x86

Block Information

Similar Families

  • Passview.BC

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_16.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_idx.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\diskcountersview Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\diskcountersview\__tmp_rar_sfx_access_check_2926546 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\diskcountersview\diskcountersview.chm Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\diskcountersview\diskcountersview.chm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\diskcountersview\diskcountersview.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\diskcountersview\diskcountersview.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\diskcountersview\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\apps\diskcountersview\icon.ico Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\diskcountersview\readme.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\diskcountersview\readme.txt Synchronize,Write Attributes
c:\windows\system.ini Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalldisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalloverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::updatesdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::uacdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::firewalldisablenotify  RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\security center\svc::firewalloverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::updatesdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::uacdisablenotify  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings::globaluseroffline RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::enablelua RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::enablefirewall RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::donotallowexceptions RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::disablenotifications  RegNtPreCreateKey
HKCU\software\apcr\1214104697::1919251317 ˆ RegNtPreCreateKey
HKCU\software\apcr\1214104697::-456464662 RegNtPreCreateKey
HKCU\software\apcr\1214104697::1462786655 RegNtPreCreateKey
HKCU\software\apcr\1214104697::-912929324 # RegNtPreCreateKey
HKCU\software\apcr\1214104697::1006321993 ċ RegNtPreCreateKey
HKCU\software\apcr\1214104697::-1369393986 http://althawry.org/images/xs.jpghttp://www.careerdesk.org/im RegNtPreCreateKey
HKCU\software\apcr\1214104697::549857331 #��_�T^�xYw0CG^�>-�'��h� � �۝���r���3�#��[�F(y�8U��� RegNtPreCreateKey
HKCU\software\apcr::u1_0 ᅕ쒧 RegNtPreCreateKey
HKCU\software\apcr::u2_0 RegNtPreCreateKey
HKCU\software\apcr::u3_0 権ă RegNtPreCreateKey
HKCU\software\apcr::u4_0 RegNtPreCreateKey
HKCU\software\microsoft\multimedia\drawdib:: 1920x1200x32(bgr 0) 31,31,31,31 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k�8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~� % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee+Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey

Windows API Usage

Category API
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Shell Command Execution

(NULL) C:\Users\Rsbyvbkn\AppData\Local\Temp\Apps\DiskCountersView\DiskCountersView.exe

Related Posts

Trending

Most Viewed

Loading...