PUP.Patched.D

The detection of PUP.Patched.D on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it to prevent potential harm.

What Is PUP.Patched.D?

PUP.Patched.D is a type of potentially unwanted program that can be installed on your system without your knowledge or consent. These programs often come bundled with other software or are downloaded from untrusted sources. They can cause a range of problems, including displaying unwanted advertisements, collecting personal data, and slowing down your system.

How PUP.Patched.D Operates

PUPs like PUP.Patched.D typically operate by exploiting vulnerabilities in your system or using social engineering tactics to trick you into installing them. Once installed, they can run in the background, consuming system resources and potentially causing issues with your computer's performance. They may also communicate with their creators or other malicious servers, potentially leading to further malware infections or data breaches.

Symptoms of Infection

If your system is infected with PUP.Patched.D, you may notice a range of symptoms, including slow system performance, unwanted advertisements or pop-ups, and suspicious programs or toolbars installed on your browser. You may also notice that your browser homepage or search engine has been changed without your consent. In some cases, you may not notice any symptoms at all, which is why it's essential to regularly scan your system for malware and other threats.

  • Unwanted advertisements or pop-ups
  • Suspicious programs or toolbars installed on your browser
  • Slow system performance
  • Changes to your browser homepage or search engine
  • Unexplained data usage or network activity

How to Remove PUP.Patched.D

  1. Boot your system in Safe Mode with Networking to prevent the malware from running and interfering with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or other threats.
  3. Uninstall any suspicious programs or applications that you don't recognize or no longer need.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing PUP.Patched.D from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable anti-malware tools, you can help protect your system and personal data from potential harm. It's also essential to practice safe computing habits, such as avoiding untrusted sources and keeping your software up to date, to prevent future infections. Remember to always be vigilant and take prompt action if you suspect that your system has been compromised by malware or other threats.

Analysis Report

General information

Family Name: PUP.Patched.D
Signature status: No Signature

Known Samples

MD5: b2b2e5b358bed0e083ab6d6f32063917
SHA1: aee0880807f386054f30ec430f3f51e87bb842f4
File Size: 98.30 KB, 98304 bytes
MD5: e2746594390e2872356ec0bf49206347
SHA1: 88cc10eabe47ebd2da79808264f7c2dd27a72739
SHA256: 730F6D276E6BC2E9AE1DB9C54D9C7C86E1699AC2C0424BD9DA83F7B5E019429D
File Size: 188.42 KB, 188416 bytes
MD5: d33c436c3c508146034c718e20d25156
SHA1: b8b73a9a030b10e1efaca33bfc361cb0b95ec74a
SHA256: DDA050D37454B820E3A3603ABBB237CEA461B726654B1114F796F5E0B18DC326
File Size: 694.53 KB, 694528 bytes
MD5: d148cab533c9cb7914a11844b44d0120
SHA1: bcb36ae0356c63a153f46570b5be643122284dd8
SHA256: F624D53892032126C661CEF6B3F54071863671015B2AB66AA33782F57CD41B20
File Size: 138.24 KB, 138240 bytes
MD5: 61c3ee93bf4bd2cdba3f93ddd1da40dd
SHA1: 3b1ac3c4e8fb261116982818d2b2008c6c3cc7b5
SHA256: 934FE89489EC2136221AC60C8B5B8DA950289302D0733F752556C5BC6965C220
File Size: 128.41 KB, 128408 bytes
Show More
MD5: a827b4834f1fe9b0f5b9bf648507f26b
SHA1: 6fc2be520e80d149cd3055653adaff0d6859498e
SHA256: 29FB4CDBB9399E282CAACFE72DDCD59940C9EC335DD3742CF2F151A5967DFEE7
File Size: 108.06 KB, 108064 bytes
MD5: 2d97ebb4bc0ddffc7944baa1b0449885
SHA1: 4a48b29ec176397ad831d0f64b6a29f204f044b4
SHA256: 670B3FDD5339FAD3114BDBC30F069386E59EB2C16EA602E7FA5685AC9AB01CA5
File Size: 108.06 KB, 108064 bytes
MD5: 8f59aaee75795465900d121a3a1a6bcf
SHA1: 19d00246babe80e2eabbf5dac701d75346239bfd
SHA256: 518906C3EDDCCEE8C9189EF31E7917751FB449A58603FFD361D7DCEF940AEB0E
File Size: 95.60 KB, 95600 bytes
MD5: b47660b39c6f04e17644bd5b939bbccd
SHA1: 8af10fd93469cf612db221bb2727bf7c6cef6902
SHA256: E2FB2D0A4FC675002A6161B8A2A01E7F8DA72BE2E3617DC785D4288583E9BC68
File Size: 3.94 MB, 3941408 bytes
MD5: 6721a540148423c28075225cafed4deb
SHA1: 2bcee8e241f24cf18c8427a827ef446ed48b1a7e
SHA256: 92EDFD67674167A129E248D95851B895DFE602EAA8E9808D9E4DF5A1EAB63F9D
File Size: 781.31 KB, 781312 bytes
MD5: 84ecba08c07746fc8fa83a66dae084a9
SHA1: 5f8044ef3e19d1fe296f1e9bb388457e692f2159
SHA256: 52B6D9546BD6B7EDE77B3600F6CBA985E394D02C3DEC0A9342FD4688CD6309C8
File Size: 128.46 KB, 128464 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Eicon Networks
  • Microsoft Corporation
File Description
  • Auto Check Utility
  • CloudExperienceHost Broker
  • DeploymentAgent.exe
  • DiskPart
  • Diva for Windows - Version 7.7 AMD64
  • EM
  • Host Process for Network Driver Configuration Plugins
  • Wireless Background Task
File Version
  • 10.0.26100.8328 (WinBuild.160101.0800)
  • 10.0.26100.7019 (WinBuild.160101.0800)
  • 10.0.22621.3527 (WinBuild.160101.0800)
  • 10.0.22621.2506 (WinBuild.160101.0800)
  • 10.0.22000.318 (WinBuild.160101.0800)
  • 10.0.22000.1 (WinBuild.160101.0800)
  • 6.1.7601.17514 (win7sp1_rtm.101119-1850)
  • 4.1.4.12
  • 1.8
Internal Name
  • AutoChk
  • CloudExperienceHost Broker
  • DeploymentAgent.exe
  • diskpart.exe
  • EM
  • NetCfgNotifyObjectHost.exe
  • WiFiTask.exe
  • xlog
Legal Copyright
  • (C) Eicon Networks Corporation 1991-2006
  • Copyright (c) Microsoft Corporation. All rights reserved.
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • AutoChk.Exe
  • CloudExperienceHostBroker.exe
  • DeploymentAgent.exe
  • diskpart.exe
  • EM.exe
  • NetCfgNotifyObjectHost.exe
  • WiFiTask.exe
  • xlog.exe
Product Name
  • Diva for Windows - Version 7.7 AMD64
  • Microsoft® Windows® Operating System
  • Windows App SDK
Product Version
  • Diva for Windows - Version 7.7 product/w2k/divafor/2/ms_cd 106-12
  • 10.0.26100.8328
  • 10.0.26100.7019
  • 10.0.22621.3527
  • 10.0.22621.2506
  • 10.0.22000.318
  • 10.0.22000.1
  • 6.1.7601.17514
  • 1.8

File Traits

  • 2+ executable sections
  • No Version Info
  • ntdll
  • x64

Block Information

Total Blocks: 675
Potentially Malicious Blocks: 208
Whitelisted Blocks: 452
Unknown Blocks: 15

Visual Map

? x 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x x 0 x 0 x 0 x 0 0 x 0 0 0 0 0 0 x x 0 0 x x x 0 0 x x 0 x 0 0 0 x x 0 x 0 x 0 x 0 0 0 0 0 x 0 x x 0 0 0 0 0 x 0 x 1 ? 0 0 0 x 0 0 x 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 1 0 0 0 x x 0 0 x 0 0 0 0 x x 0 x x x x 0 0 x 0 x x x 0 1 0 0 0 x 0 x 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 x 0 x 0 0 0 0 0 0 x x x 0 0 0 0 x x 0 0 0 x x ? 0 x x 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x x x x x 0 x 0 0 0 x 0 0 0 0 x ? 0 0 0 0 0 x 0 x 0 x 0 0 0 x 0 x 0 x 0 0 0 x x 0 0 0 0 x 0 ? x 0 0 0 0 0 0 0 x x 0 0 x x 0 0 x x x x 0 0 x 0 x x 0 x 0 x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 x 0 x 0 x 0 x 0 0 0 0 x x 0 x 0 0 x x 0 0 0 x x 0 0 0 x 0 x x 0 0 0 0 0 0 x 0 x x x 0 0 0 0 x x 0 1 0 0 0 x 0 x x 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 x 0 x x 0 x 0 0 x 0 0 0 0 x 0 x 0 x 0 0 0 0 0 x x x 0 0 0 0 x x 0 x 0 x x x x 0 0 x 0 x x x 0 0 0 x x x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x x 0 0 x 0 0 x x 0 0 0 0 0 0 x 0 x 0 x 0 x x 0 0 0 0 0 x 0 x 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 x x 0 x 0 0 x x 0 x x x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 1 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x x 1 0 x 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Patched.D

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
Show More
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState