Home Possibly Unwanted Program PUP.Power Spy

PUP.Power Spy

Posted: September 7, 2020

Threat Metric

Threat Level: 1/10
Infected PCs: 124
First Seen: September 8, 2020
Last Seen: October 5, 2022
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Local\Temp\vmware-goldeneye\VMwareDnD\40a183e7\Deceptor\63b8a8da4781646ab5d7ecc83686ed2e35f86a0d638bdf6a067a742eca632911.exe File name: 63b8a8da4781646ab5d7ecc83686ed2e35f86a0d638bdf6a067a742eca632911.exe
Size: 3.26 MB (3269365 bytes)
MD5: fefd4b7efbbc5cef08d50fe23d9246e7
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\vmware-goldeneye\VMwareDnD\40a183e7\Deceptor\63b8a8da4781646ab5d7ecc83686ed2e35f86a0d638bdf6a067a742eca632911.exe
Group: Malware file
Last Updated: May 25, 2023
%PROGRAMFILES(x86)%\PW2\Appdata.exe File name: Appdata.exe
Size: 299 KB (299008 bytes)
MD5: 53acbac9f6339785e8319378719981d6
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PW2\Appdata.exe
Group: Malware file
Last Updated: May 25, 2023
%PROGRAMFILES(x86)%\PW2\setup.exe File name: setup.exe
Size: 1.03 MB (1032192 bytes)
MD5: 5d74ef20c7ce8d751c2b080ee4e796e9
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PW2\setup.exe
Group: Malware file
Last Updated: May 25, 2023
Appdata4.exe File name: Appdata4.exe
Size: 299 KB (299008 bytes)
MD5: 0c4b7a2339edef44edf43af6f4ea0121
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 25, 2023
load4.exe File name: load4.exe
Size: 57.34 KB (57344 bytes)
MD5: 4e26bfd2719f113ee5af273fb5bcbdfe
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 25, 2023
setup4.exe File name: setup4.exe
Size: 1.03 MB (1032192 bytes)
MD5: 5a6f8a6e27a2aa66da7873846816877f
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 25, 2023
setup [3 ].exe File name: setup [3 ].exe
Size: 1.03 MB (1032192 bytes)
MD5: bce2fd1460e430ab34aa6bc8af3b656d
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 25, 2023
C:\Users\<username>\AppData\Local\Temp\vmware-goldeneye\VMwareDnD\40a183e7\Deceptor\82fa375d81f80a5548870be16d7b7e5d774b9a1fdd77ea3ec890832b53d8437e.exe File name: 82fa375d81f80a5548870be16d7b7e5d774b9a1fdd77ea3ec890832b53d8437e.exe
Size: 3.06 MB (3063802 bytes)
MD5: a9c66474305145caf8f906184ec37bda
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\vmware-goldeneye\VMwareDnD\40a183e7\Deceptor\82fa375d81f80a5548870be16d7b7e5d774b9a1fdd77ea3ec890832b53d8437e.exe
Group: Malware file
Last Updated: May 25, 2023
%SYSTEMDRIVE%\Users\<username>\Desktop\Noriben-master\power.exe File name: power.exe
Size: 3.26 MB (3269109 bytes)
MD5: b2a4fbea06c8ac5cc93743044ad95175
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\Desktop\Noriben-master\power.exe
Group: Malware file
Last Updated: May 25, 2023
setup [7].exe File name: setup [7].exe
Size: 1.04 MB (1048576 bytes)
MD5: e651605671672948c60a27f51cbc15f7
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 25, 2023
C:\Users\<username>\AppData\Local\Temp\vmware-goldeneye\VMwareDnD\40a183e7\Deceptor\8916485abc22fb24c5c039f32a3b31f9f27791b5a9c186be9fe6ce974c5be221.exe File name: 8916485abc22fb24c5c039f32a3b31f9f27791b5a9c186be9fe6ce974c5be221.exe
Size: 3.06 MB (3061995 bytes)
MD5: 33ba1533cd72e42f229651be90111801
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\vmware-goldeneye\VMwareDnD\40a183e7\Deceptor\8916485abc22fb24c5c039f32a3b31f9f27791b5a9c186be9fe6ce974c5be221.exe
Group: Malware file
Last Updated: May 25, 2023
C:\Program Files (x86)\PW2\setup.exe File name: setup.exe
Size: 1.03 MB (1032192 bytes)
MD5: 2238da1103812beb94cb79f49e2ed847
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\PW2\setup.exe
Group: Malware file
Last Updated: May 25, 2023

Registry Modifications

The following newly produced Registry Values are:

HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}power spy_is1

Additional Information

The following directories were created:
%programfiles%\pw2

Related Posts

Loading...