PUP.Sheed Antivirus

Threat Scorecard

Popularity Rank: 8,463
Threat Level: 10 % (Normal)
Infected Computers: 15,965
First Seen: May 10, 2016
Last Seen: October 24, 2025
OS(es) Affected: Windows

SpyHunter Detects & Remove PUP.Sheed Antivirus

File System Details

PUP.Sheed Antivirus may create the following file(s):
# File Name MD5 Detections
1. shgrprot.exe 7199220c863ef4cb946f23d4706c5dfa 3,880
2. shgr.exe.backup 288a2f8e1f7c7516a7f83d0f14678f06 3,214
3. SheedUi.exe.backup f74f39eb4ee347381dc10573014afcac 689
4. SheedUI.exe 69e0d043ce319b270713f409026ac201 269
5. shgr.exe 1b671e50074e5cff41515f8d15e742fc 131
6. Setup.exe 5245add845258524a11eac8bf9f5249f 105
More files

Registry Details

PUP.Sheed Antivirus may create the following registry entry or registry entries:
CLSID
{F289930E-697C-432A-8C13-08DB3BAD1A62}
File name without path
http_sheedantivirus.ir_0.localstorage
http_sheedantivirus.ir_0.localstorage-journal
Sheed Antivirus.lnk
Sheed Healer.lnk
sheedmon64.sys
SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\SheedShlExt
SOFTWARE\Classes\Installer\Products\BAD68E7B143030440B0FE27B38F4A5CD
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Sheed AntiVirus
SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F289930E-697C-432A-8C13-08DB3BAD1A62}
SOFTWARE\Sheed
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Sheed AntiVirus
SOFTWARE\Wow6432Node\Sheed
SYSTEM\ControlSet001\Enum\Root\LEGACY_ARTAFILTER
SYSTEM\ControlSet001\Enum\Root\LEGACY_SHEEDMON
SYSTEM\ControlSet001\services\ArtaFilter
SYSTEM\ControlSet001\services\ShavProt
SYSTEM\ControlSet001\services\SheedAV
SYSTEM\ControlSet001\services\SheedMon
SYSTEM\ControlSet002\Enum\Root\LEGACY_ARTAFILTER
SYSTEM\ControlSet002\Enum\Root\LEGACY_SHEEDMON
SYSTEM\ControlSet002\services\ArtaFilter
SYSTEM\ControlSet002\services\ShavProt
SYSTEM\ControlSet002\services\SheedAV
SYSTEM\ControlSet002\services\SheedMon
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ARTAFILTER
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SHEEDMON
SYSTEM\CurrentControlSet\services\ArtaFilter
SYSTEM\CurrentControlSet\services\ShavProt
SYSTEM\CurrentControlSet\services\SheedAV
SYSTEM\CurrentControlSet\services\SheedMon

Directories

PUP.Sheed Antivirus may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Sheed AntiVirus
%ProgramFiles%\Sheed AntiVirus
%ProgramFiles(x86)%\Sheed AntiVirus

Analysis Report

General information

Family Name: PUP.Sheed Antivirus
Signature status: Hash Mismatch

Known Samples

MD5: 744d37ba0ae56bdbe95ec89e2752897d
SHA1: 74f5145faf243bc299fd86e657593b87b3bc4b33
SHA256: 126763454B3BE6D8DF507C14919BD6C14207F63DFCE4E04C929DF6F131C1141C
File Size: 254.63 KB, 254631 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have relocations information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Digital Signatures

Signer Root Status
Sheed Afzar Rayaneh Company, Ltd. Certum Extended Validation Code Signing CA SHA2 Hash Mismatch

Block Information

Total Blocks: 577
Potentially Malicious Blocks: 4
Whitelisted Blocks: 475
Unknown Blocks: 98

Visual Map

? ? ? ? 0 0 ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? 0 0 ? ? 0 0 ? ? 0 ? 0 0 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 ? ? ? 0 0 0 ? 0 ? ? 0 ? x x 0 0 0 x x 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 ? ? ? ? 0 0 ? ? ? ? 0 0 0 2 0 1 ? ? ? ? 1 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? 2 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 2 3 1 0 0 0 1 1 1 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 2 2 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\program files\common files\system\symsrv.dll Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\74f5145faf243bc299fd86e657593b87b3bc4b33_0000254631.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...