PUP.PowerRun

The detection of PUP.PowerRun on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it to prevent further problems.

What Is PUP.PowerRun?

PUP.PowerRun is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as damaging as other types of malware, such as viruses or Trojans, it can still cause significant issues with your system. PUPs are often installed unintentionally, and they can lead to a range of problems, including slowed system performance, unwanted advertisements, and potential security vulnerabilities.

How PUP.PowerRun Operates

PUPs like PUP.PowerRun typically operate by installing themselves on a system without the user's full knowledge or consent. They may be bundled with other software, or they may be installed through exploits in vulnerable applications. Once installed, PUPs can collect user data, display unwanted advertisements, and even install additional malware. They may also modify system settings and configure themselves to start automatically when the system boots.

Symptoms of Infection

If your system is infected with PUP.PowerRun, you may notice a range of symptoms. These can include slowed system performance, unwanted pop-up advertisements, and new toolbars or extensions in your web browser. You may also notice that your system is configured to start certain programs automatically, or that your default search engine or homepage has been changed. Additionally, you may see suspicious programs or processes running in the background, consuming system resources.

  • Unwanted advertisements and pop-ups
  • Slow system performance
  • New toolbars or extensions in your web browser
  • Changes to system settings and configurations
  • Suspicious programs or processes running in the background

How to Remove PUP.PowerRun

  1. Boot your system in Safe Mode with Networking to prevent PUP.PowerRun from loading and to give you access to the internet for downloading removal tools.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or PUPs that may be present.
  3. Uninstall any suspicious programs that were installed around the time the PUP was detected. Be cautious and only uninstall programs that you are certain are not needed or are malicious.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by the PUP.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that all malware and PUPs have been removed.

Conclusion

Removing PUP.PowerRun from your system is crucial to preventing further issues and ensuring your computer's security and performance. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this potentially unwanted program and protect your system from similar threats in the future. Remember to always be cautious when installing software and to monitor your system for any suspicious activity to prevent PUPs and other malware from infecting your computer.

Analysis Report

General information

Family Name: PUP.PowerRun
Signature status: No Signature

Known Samples

MD5: cf22c17ca19f7c31dbf098683d458b9c
SHA1: 1a51bd6efd4b8ddf12ff456a54f55102fbd3f986
File Size: 842.99 KB, 842994 bytes
MD5: 41e1e078871a73b1ccb5842a8517a2b8
SHA1: 9bfcb1c13dadc06128ef6fd6791dbac81f6c0210
File Size: 543.66 KB, 543661 bytes
MD5: 1a6bf240f43808ff58b98bdf3b85524c
SHA1: d9e0b62548153f132887c39f72befcbd4b453f9c
SHA256: E58B3F06F81E9F454922E56F20875AB5CF5A7D0F99524E02B7603F46B1F831F7
File Size: 843.73 KB, 843733 bytes
MD5: d8949a1bdbf7b72369296f3ef39f59a1
SHA1: 1d750a9d018dd9a953b4f36bc4c5401045a32bee
SHA256: DA011EABF65A8CFB44705B62140AC963C82E25727825E949EB81F47C806FCCBD
File Size: 899.74 KB, 899742 bytes
MD5: 5acc6239eb4321ad197f30e30bb17307
SHA1: 591e997fc3cc0a1146646057e9ddeff4aad9d10c
SHA256: 1A23326D5628EC55B9F8033CCDC1324C36D3A7536CDC7E2C44056049134E69C7
File Size: 894.02 KB, 894016 bytes
Show More
MD5: 05af406f46a08be6ebdd86c282f746e9
SHA1: 8b87d60415c0ead149be5883fb15f52a9c2e899d
SHA256: B9DE9C1E9D6723CD6915474FB67BA878F445431CA6C0338F5F567E298E19A06B
File Size: 1.05 MB, 1054979 bytes
MD5: 75d9dd5c5da200748ad280e4d2580bba
SHA1: 623908159b8a9815db2f2e754ca691b76d22684e
SHA256: C72D2EE2333BA87E962ADF00E441468C96B72F5609905B3C91C9758EA26E995E
File Size: 1.67 MB, 1673760 bytes
MD5: 6eb1baa41c8731fd84bcde7081f0d940
SHA1: 36dfc44315b2c5e649b1bbaea322e6ca6b1e7264
SHA256: 47E0AA5F1B337D02C800F91D5360431E5B9883299722AB25E74F6DB3ECF40B5F
File Size: 2.08 MB, 2082848 bytes
MD5: 15c3d5d3bbde6b7b20954d870adb0c7d
SHA1: 1204dba6aa49b03abb3f79b5a31101a31c1b0cb9
SHA256: CB14A3D093C2B4B2BE0EE5E123EBAFFCD7D5F681D222F97A5341D6C6D65C1E2D
File Size: 833.56 KB, 833560 bytes
MD5: 121a7cadbeea06d5544df7786b3309f2
SHA1: 47e2188597ba3d77ff1ebb977329be21ab00e6e2
SHA256: 77F356F648B91916E9BD1711F11B67A1986FC26CEEAA915AADD53D0A266BE65A
File Size: 999.03 KB, 999033 bytes
MD5: 409e1c6995725b25551809484a8e1f45
SHA1: 00b2651355689bc73a47b523f56243a13c03dc4c
SHA256: 50436566C22D4E7AC32B9BE8D78CC5245234BE14824313B41165FF324BB07F88
File Size: 789.62 KB, 789624 bytes
MD5: 82fa1feb495fe325ee10a856ce62c2e8
SHA1: 292a7cf11809edf7860f7dc9c5da410ec946d79b
SHA256: 56DB4A91890041FC193FA87BB28B0750F6B251C904D49CAAA4298A0D9435A34E
File Size: 1.08 MB, 1076224 bytes
MD5: 0682814a4296f8ef67399ebac1d9c354
SHA1: db00beefcdb88ece77abf235a139c8c50206ab80
SHA256: 11C05C4E2D9ABFF3048A175AED285ACA0E1EAC2CBECF8614C3B2F0D3316C6A87
File Size: 831.82 KB, 831818 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 3.60.582.30
  • 1.4.0.15
Coder By BlueLife
Comments
  • AnWave Personal Development Project
  • DefenderRemover
  • NVIDIA Power Management Panel
  • PowerRun v1.4
  • PowerRun v1.6
Company Name
  • AnWave Macer's Tools
  • Gallery Inc
  • Microsoft
  • NVIDIA Corporation
  • www.sordum.org
File Description
  • Defender Remover
  • Microsoft Defender Uninstaller (Part of AnWave)
  • NVIDIA Power Management Panel
  • PowerRun
  • PowerRun v1.4
File Version
  • 13.0
  • 12.8.4
  • 12.8.3
  • 12.8
  • 12.7.0.0
  • 12.4.1
  • 3.60.582.30
  • 1.6.0.0
  • 1.4.0.15
  • 1.4.0.0
Show More
  • 1.00
Internal Name
  • MDU.exe
  • NVPMan.exe
  • Win
Legal Copyright
  • (C) 2016-2022 NVIDIA Corporation. All rights reserved.
  • (C) Gallery Inc.
  • AnWave Copyright © Simonmacer 2024
  • Copyright © 2016-2020 www.sordum.org All Rights Reserved.
  • Gallery Inc.
Legal Trademarks
  • AnWave Macer's Tools
  • NVIDIA Corporation
Original Filename
  • MDU.exe
  • NVPMan.exe
  • PowerRun.exe
  • Win.exe
Product Name
  • AnWave Personal Development Project
  • Defender Remover
  • DefenderRemover
  • NVIDIA Power Management
  • Win
Product Version
  • 13.0
  • 12.8.4
  • 12.8.3
  • 12.8
  • 12.4.1
  • 3.60.582.30
  • 1.6.0.0
  • 1.4.0.15
  • 1.00

Digital Signatures

Signer Root Status
AnWave Software and Simon Macer Project AnWave Software and Simon Macer Project Self Signed
Sordum Software Sordum Software Hash Mismatch

File Traits

  • big overlay
  • HighEntropy
  • WriteProcessMemory
  • x64
  • x86

Block Information

Similar Families

  • Autoit
  • Bitcoinminer.BDA
  • Bitcoinminer.BDB
  • Bitcoinminer.DJE
  • Rugmi.T

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
\device\namedpipe\pshost.134228115379821550.8436.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\anwaverootinstall\require\simonmacer.pfx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7r5v6f8k.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\7r5v6f8k.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\powerrun.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\powerrun.exe Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removedefender.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removedefender.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removeshellassociation.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_defender\removeshellassociation.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp\remove_securitycomp.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\remove_securitycomp\remove_securitycomp.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\removesechealthapp.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\removesechealthapp.ps1 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\script_run.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs14e6.tmp\script_run.bat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender\disable_def.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\disable_defender\disable_def.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender\enable_def.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\enable_defender\enable_def.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\firewall Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\firewall Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\add firewall menu.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\add firewall menu.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\remove firewall menu.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\firewall\remove firewall menu.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\antivirus_d.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\antivirus_d.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\defender anti-phishing_d.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\defender anti-phishing_d.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\exploit guard_d.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\exploit guard_d.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\security health_d.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\security health_d.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\smartappcontrol_d.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\smartappcontrol_d.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\windows security center_d.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.disablerscript\windows security center_d.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\antivirus_e.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\antivirus_e.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\defender anti-phishing_e.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\defender anti-phishing_e.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\security health_e.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\security health_e.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\windows security center_e.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.enablerscript\windows security center_e.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable lsa protection.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable lsa protection.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable microsoft vulnerabile driver blocklist.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable microsoft vulnerabile driver blocklist.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable smartscreen.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable smartscreen.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable uac.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable uac.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable vbs.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\disable vbs.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\no more delay and timeouts.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\no more delay and timeouts.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\security health.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\security health.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\windows settings page visibility.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\galleryinc.melodyscript.defenderremover.extras\windows settings page visibility.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\oscdimg.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\oscdimg.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\powerrun.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\powerrun.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender and security center notifications.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender and security center notifications.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender policies.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable defender policies.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable tamper protection.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\disable tamper protection.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\lockdown windows defender security center.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\lockdown windows defender security center.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of anti-phishing services.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of anti-phishing services.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of sechealthui.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of sechealthui.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows defender antivirus.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows defender antivirus.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows security action center.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\removal of windows security action center.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove defender tasks.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove defender tasks.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove security and maintenance.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove security and maintenance.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove services.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove services.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove shell association.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove shell association.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove startup entries.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove startup entries.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows defender firewall rules.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows defender firewall rules.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows webthreat.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remove windows webthreat.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remover of defender context menu.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\remove_defender\remover of defender context menu.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\script_run.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\script_run.bat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\winwim.cmd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs413b.tmp\winwim.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\powerrun.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\powerrun.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\nomoredelayandtimeouts.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\nomoredelayandtimeouts.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removedefender.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removedefender.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removeshellassociation.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_defender\removeshellassociation.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp\remove_securitycomp.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\remove_securitycomp\remove_securitycomp.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\removesechealthapp.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\removesechealthapp.ps1 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\script_run.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs45bf.tmp\script_run.bat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\files_removal.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\files_removal.bat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\powerrun.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\powerrun.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disable mitigation.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disable mitigation.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disable smartscreen.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disable smartscreen.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disableantivirusprotection.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disableantivirusprotection.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disabledefenderpolicies.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\disabledefenderpolicies.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removalofwindowsdefenderantivirus.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removalofwindowsdefenderantivirus.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removedefendertasks.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removedefendertasks.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removerofdefendercontextmenu.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removerofdefendercontextmenu.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removeservices.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removeservices.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removeshellassociation.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removeshellassociation.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removesignatureupdates.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removesignatureupdates.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removestartupentries.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removestartupentries.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removewindowswebthreat.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\removewindowswebthreat.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\windowssettingspagevisibility.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_defender\windowssettingspagevisibility.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_securitycomp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_securitycomp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_securitycomp\remove_securitycomp.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\remove_securitycomp\remove_securitycomp.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\removesechealthapp.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\removesechealthapp.ps1 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\script_run.bat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa15.tmp\script_run.bat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\powerrun.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\powerrun.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disableantivirusprotection.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disableantivirusprotection.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderandsecuritycenternotifications.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderpolicies.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\disabledefenderpolicies.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\nomoredelayandtimeouts.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\nomoredelayandtimeouts.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removalofwindowsdefenderantivirus.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zsa2d2.tmp\remove_defender\removalofwindowsdefenderantivirus.reg Synchronize,Write Attributes

134 additional files are not displayed above.

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 俆ꦎ⚖ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 竞⚛ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ಲ䪩茔ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ����� RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
Show More
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtLockFile
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnlockFile
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady

130 additional items are not displayed above.

Service Control
  • ControlService
  • OpenSCManager
  • OpenService
Keyboard Access
  • GetAsyncKeyState
  • GetKeyState
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx
Cert Store Read
  • CertEnumCertificatesInStore
  • CertOpenStore
Cert Store Write
  • CertAddCertificateContextToStore
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

.\Script_Run.bat
WriteConsole: ------ Defender
WriteConsole: Select an option
WriteConsole:
WriteConsole: Do you want to r
Show More
WriteConsole: If you PC have a
WriteConsole: After confirmati
WriteConsole: A backup and/or
WriteConsole: [Y] Remove Windo
WriteConsole: [A] Remove Windo
WriteConsole: [S] Disable All
C:\WINDOWS\system32\choice.exe choice /C:yas /N
WriteConsole: (NULL)
C:\Users\Sqljlniy\AppData\Local\Temp\{2C6E2BE6-1CB4-4E15-8576-CBF76CA4FD6A}\Script_Run.bat
WriteConsole: Defender Remover
WriteConsole: 592ce29595c2aa20e294a4e28c90e295
WriteConsole: 4e2ce29494e2959720e294a4e28c90e2
WriteConsole: 452ce29595c2aa20e294a4e28c90e295
WriteConsole: 482ce29595c2aa20e294a4e28c90e295
WriteConsole: 492ce29595c2aa20e294a4e28c90e295
WriteConsole: 462ce29595c2aa20e294a4e28c90e295
WriteConsole: 472ce29595c2aa20e294a4e28c90e295
WriteConsole: 522ce29494e2959720e294a4e28c90e2
WriteConsole: 552ce29595c2aa20e294a4e28c90e295
WriteConsole: 4a2ce29595c2aa20e294a4e28c90e295
WriteConsole: e2959de29692e294bce2949ce2959fe2
WriteConsole: e29691cea6e2959de29599e2959fe295
C:\WINDOWS\system32\mode.com mode con cols=70 lines=25
WriteConsole: Access is denied
WriteConsole: e2959fceb4e295a4c3ade29598c2b1e2
WriteConsole: e295a9e2959fe29596c2b1e295a5c2ac
WriteConsole: e2959acf84e295a3e2889ae29480cf80
WriteConsole: 28e294a4e295a6e2959ce294bce29692
WriteConsole: e2959ae29596e2959ae295a7e29594e2
WriteConsole: e2959cc2bfe295a5ce98e295a9e295a3
WriteConsole: 5b595d20e295a5e2959ee29482c2b220
WriteConsole: 5b415d20e295a5e2959ee29482c2b220
WriteConsole: 5b535d20e2959ce2889ae29599e2949c
C:\WINDOWS\system32\mode.com mode con cols=80 lines=25
C:\WINDOWS\system32\net.exe net session
WriteConsole: e2959fceb4e2959fe289a4e295a3e296
C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "Start-Process 'C:\Users\Zybjmzbz\appdata\local\temp\7zsa15.tmp\script_run.bat' -Verb RunAs"

Related Posts

Trending

Most Viewed

Loading...