PUP.Xtron System Care

Published:
Last updated:

Threat Scorecard

Popularity Rank: 4,088
Threat Level: 10 % (Normal)
Infected Computers: 929
First Seen: July 20, 2019
Last Seen: October 4, 2026
OS(es) Affected: Windows

The detection of PUP.Xtron System Care on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's performance and security. It is essential to understand the nature of this threat and take appropriate measures to remove it and prevent future infections.

What Is PUP.Xtron System Care?

PUP.Xtron System Care is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may exhibit undesirable behavior, such as displaying unwanted advertisements, collecting user data, or modifying system settings. While PUPs are not typically considered malware, they can still pose a significant threat to your system's security and performance.

How PUP.Xtron System Care Operates

PUP.Xtron System Care may operate by installing itself on your system through various means, such as bundled software installations, drive-by downloads, or social engineering tactics. Once installed, it may begin to display unwanted advertisements, collect user data, or modify system settings to facilitate its operations. PUPs like PUP.Xtron System Care may also attempt to deceive users into purchasing or installing additional software or services.

Symptoms of Infection

Systems infected with PUP.Xtron System Care may exhibit a range of symptoms, including unwanted advertisements, slow system performance, and modified system settings. You may also notice unfamiliar programs or icons on your system, or experience frequent crashes or errors. In some cases, PUPs like PUP.Xtron System Care may also attempt to hijack your browser or display fake alerts and warnings.

  • Unwanted advertisements or pop-ups
  • Slow system performance or crashes
  • Modified system settings or unfamiliar programs
  • Frequent errors or warnings
  • Browser hijacking or redirection

How to Remove PUP.Xtron System Care

  1. Boot your system in Safe Mode with Networking to prevent PUP.Xtron System Care from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove any associated malware or PUPs.
  3. Uninstall any suspicious programs or applications that may be related to PUP.Xtron System Care, taking care to review the list of installed programs carefully.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that PUP.Xtron System Care has been completely removed and that no additional threats are present.

Conclusion

Removing PUP.Xtron System Care from your system is crucial to maintaining your computer's security and performance. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and ensure a safe and secure computing experience. Remember to always be cautious when installing software or clicking on links, and to keep your anti-malware tools and operating system up to date to protect against the latest threats.

SpyHunter Detects & Remove PUP.Xtron System Care

File System Details

PUP.Xtron System Care may create the following file(s):
# File Name MD5 Detections
1. xpssetup.exe.6rq5qyc.partial ea0ca998d1561fc6319bc43b3436d443 3
2. xcpsetup (1.0.1.125).exe f32c6cf1a7b2c40072483f36846e8d78 1
3. xcpsetup[1].exe 73d62317d648b0aca1cebbc0b34b3c6e 1
4. xcpsetup (1.0.1.125) 2.exe aa9622286b1f65a468861e03dd7c096d 1
5. xscsetup (1.0.0.15).exe b0a73df45f7b79c6f2b948be12ef2787 0
6. xcpsetup (1.0.2.3).exe 9ac8cd3615bf01210077104cbad62c53 0
7. xcpsetup (1.0.2.3) 2.exe a9bd811a19d8d2f25a7870d7882169f9 0
8. xcpsetup (1.0.2.3) 3.exe bd4efea534abde4db8a4e54d785930dc 0
9. xcpsetup (1.0.2.3) 4.exe a86c05f0b1a7db3edecac51648a834ec 0
10. xscsetup (1.0.0.14) 5.exe c702a104aff7f5234f9d12d50e895767 0
11. xscsetup (1.0.0.1) 12.exe 69f448f2da8ced425ded0553920e8de2 0
12. xcpsetup (1.0.0.15) 2.exe 820eecfa62e6f4ee9dd64c0c1cb9b25f 0
13. xscsetup (1.0.0.24) 10.exe 3e3514b51191bd7994e72f2bfd980a5f 0
14. xcpsetup (1.0.1.100).exe e743cb75bb6cb87f5914307ce2b5de6b 0
15. xcpsetup (1.0.2.40).exe d06647357c2100bfa02a2b563f0a1532 0
16. xcpsetup (1.0.2.40) 2.exe 5ee4fb30edec1e9381e1f743d676df6a 0
17. xcpsetup (1.0.2.40) 3.exe 399e40306d64169055bfb56064495cd0 0
18. xcpsetup (1.0.2.40) 4.exe 8a2f3a523ec082af381666bb791c5372 0
19. xcpsetup (1.0.2.40) 5.exe 8b6b538243f5365d77c59a6974507ab9 0
20. xcpsetup (1.0.2.40) 6.exe 7a4a4eea7da2c64a5d9304d9592391d5 0
21. xcpsetup (1.0.2.5).exe 0578b927e32a730b1475190d9f3fc03a 0
22. xcpsetup (1.0.2.5) 2.exe b9e196821165f0c2783bb8b53d678c66 0
23. xcpsetup (1.0.2.5) 3.exe 19115367870cca50b248e42bc1243948 0
24. xcpsetup (1.0.2.5) 4.exe 0e55794b6d92fc4a38b0f05e4b7c0135 0
25. xcpsetup (1.0.2.40) 7.exe 06de41cf263525b41a10da95e95a2027 0
26. xpssetup (1.0.3.8) 2.exe 3101634d61113f692c53721ef7a645de 0
27. xcpsetup (1.0.2.40) 8.exe b38fd81275a103364840ae9680d81ca2 0
28. xcpsetup (1.0.3.7).exe 4796af8e636d334f0bfb6b2204a75c19 0
29. xcpsetup (1.0.1.135).exe ceed21ff7a5867f685e0f3cbe3ae8e97 0
More files

Analysis Report

General information

Family Name: PUP.Xtron System Care
Signature status: Self Signed

Known Samples

MD5: 420ba85d85fe534f45d4b6acc0e24a3c
SHA1: 98c22d2ef517f69c1caffdb56a9b2ea44da00ab8
File Size: 236.10 KB, 236096 bytes
MD5: 563de6e0e003bbbf344528e7d25d8d7c
SHA1: 46a504455343657e70fb69c1a0cc1cf7c1f18015
SHA256: 3472DB4C440FBD01170E9254C5526AB733B3D9C4894186BF47512F0A2D7D33FC
File Size: 568.36 KB, 568360 bytes
MD5: 77dae21f571762db20d0926bec50369a
SHA1: 010e26184dfab245eef91c1fe81f244af33650c6
SHA256: AEF04F1AC2F8916289A22AF8EBF0AC22037E2ABE49FA69943E523D4686B138F4
File Size: 616.01 KB, 616008 bytes
MD5: 3e8e0022a1418ac90f8999e88bd101b1
SHA1: c1496a2bdace6766d13d84f2c6e9f064d273aed9
SHA256: C84CC4769958A7747A6F13B314164D09932D5B3244FB6D4F7018EBE90A3391C9
File Size: 62.66 KB, 62664 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.5.0.6
Comments This installation was built with Inno Setup.
Company Name
  • Open source hosted on CodePlex
  • www.avast.com
File Description
  • Avast Free-Antivirus
  • HTML Renderer
  • Web~ Discover Setup
File Version
  • Avast Free-Antivirus
  • 1.5.0.6
  • 1.0.0.0
Internal Name
  • HtmlRenderer.dll
  • Interop.IWshRuntimeLibrary
Legal Copyright
  • Copyright © 2008
  • © www.avast.com
Original Filename
  • HtmlRenderer.dll
  • Interop.IWshRuntimeLibrary.dll
Product Name
  • Assembly imported from type library 'IWshRuntimeLibrary'.
  • Avast Free-Antivirus
  • HTML Renderer
  • Web~ Discover
Product Version
  • 3.0.1.33
  • 3.0.0.96
  • 1.5.0.6
  • 1.0.0.0

Digital Signatures

Signer Root Status
Wincare utilities COMODO RSA Code Signing CA Hash Mismatch
Wincare utilities COMODO RSA Code Signing CA Self Signed
CLOVER PC UTILITIES Sectigo RSA Code Signing CA Self Signed
QUANTUM TECHNOLOGIES Sectigo RSA Code Signing CA Self Signed
QUANTUM TECHNOLOGIES Sectigo RSA Code Signing CA Self Signed

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-0tpvj.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-0tpvj.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-0tpvj.tmp\isxdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-699g6.tmp\010e26184dfab245eef91c1fe81f244af33650c6_0000616008.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-dq3bc.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-dq3bc.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-dq3bc.tmp\isxdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-qj9kv.tmp\46a504455343657e70fb69c1a0cc1cf7c1f18015_0000568360.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\bch.bat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\tvb.bat Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� xykP~�ރ���E��^۴�}��Vs} kP~ ��1}�����dB F e@G��13��h�n�}e��e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 闱ȁਪˣ鈯ˣ遙̃豤̃অˣ炑̃濖̃賬̃ 獖}偫~엦1਷ˣ邯̃뫯ʃdᵂċᵆċeЂ엦1¶iꙥžr֢ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
Network Urlomon
  • URLDownloadToFile
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

"C:\Users\Ydwwkgln\AppData\Local\Temp\is-QJ9KV.tmp\46a504455343657e70fb69c1a0cc1cf7c1f18015_0000568360.tmp" /SL5="$7002E,169923,119296,c:\users\user\downloads\46a504455343657e70fb69c1a0cc1cf7c1f18015_0000568360"
open schtasks.exe /create /tn ppvst /tr "C:\Users\Ydwwkgln\AppData\Roaming\tvb.bat" /sc onlogon /RL Highest /F
"C:\Users\Nlwztsfm\AppData\Local\Temp\is-699G6.tmp\010e26184dfab245eef91c1fe81f244af33650c6_0000616008.tmp" /SL5="$70300,169923,119296,c:\users\user\downloads\010e26184dfab245eef91c1fe81f244af33650c6_0000616008"
open schtasks.exe /create /tn ds_w /tr "C:\Users\Nlwztsfm\AppData\Roaming\bch.bat" /sc onlogon /RL Highest /F