Threat Database Cracks PUP.Crack.TF

PUP.Crack.TF

The detection of PUP.Crack.TF on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent further problems.

What Is PUP.Crack.TF?

PUP.Crack.TF is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as harmful as other types of malware, such as viruses or Trojans, it can still cause significant issues with your system. PUPs are often installed unintentionally by users, usually when they download and install software from untrusted sources or click on suspicious links.

How PUP.Crack.TF Operates

PUP.Crack.TF, like other PUPs, operates by installing itself on your system and then performing various unwanted actions. These actions can include displaying unwanted advertisements, collecting user data, and modifying system settings. In some cases, PUPs can also install additional malware or create backdoors for other malicious programs to exploit. The primary goal of PUP.Crack.TF is to generate revenue for its creators, often at the expense of the user's system performance and security.

Symptoms of Infection

If your system is infected with PUP.Crack.TF, you may notice several symptoms. These can include a significant decrease in system performance, unwanted advertisements and pop-ups, and changes to your browser settings or homepage. You may also notice that your system is slow to respond or that certain programs are not functioning correctly. In some cases, you may even notice that your system is crashing or freezing frequently.

  • Unwanted advertisements and pop-ups
  • Changes to browser settings or homepage
  • Slow system performance
  • System crashes or freezes
  • Unexplained changes to system settings

How to Remove PUP.Crack.TF

  1. Boot your system in Safe Mode with Networking to prevent PUP.Crack.TF from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware, including PUP.Crack.TF.
  3. Uninstall any suspicious programs that may be related to PUP.Crack.TF. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by PUP.Crack.TF.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that PUP.Crack.TF has been completely removed.

Conclusion

Removing PUP.Crack.TF from your system is crucial to prevent further issues and protect your personal data. By following the steps outlined above, you can effectively remove this potentially unwanted program and restore your system to a safe and secure state. It's also essential to practice safe computing habits, such as avoiding suspicious downloads and links, to prevent future infections. Remember to always use reputable anti-malware tools and keep your system and software up to date to ensure the best possible protection against malware and other online threats.

Analysis Report

General information

Family Name: PUP.Crack.TF
Signature status: No Signature

Known Samples

MD5: efcc8ca7ae516aabfac2adc6a18c8f3f
SHA1: a987f2ef1ec6a167b5ec0449616733c66f96dd4f
SHA256: 34BC3E81E0426603F6B974C91C2B58A8BC15C82B3291A44033337E48F27D9D77
File Size: 7.79 MB, 7794325 bytes
MD5: 87b333f27f9243b37b74d3892bfd35dd
SHA1: 828a8a7d678363d489ec4cb15b6c7c4a3178c5db
SHA256: 349CE9D1921E289E4C6A3B59B8A8BC8B14493029A3F9B7754CB025E214A45A9B
File Size: 74.75 KB, 74752 bytes
MD5: 92ac7f1a1a3250b9cc99f92634d44455
SHA1: 77a88e355c74168f189e22ac61968337ac80121e
SHA256: 49C17DE629D9D3B013759B3755C8E168BCC42FD7C070C47C0F619A57F0DBEC91
File Size: 7.79 MB, 7793602 bytes
MD5: b37d15353437f26573a9a22cff59366b
SHA1: cd2d51b975e90e860874aacfff4e7bed951a2859
SHA256: D8D0C2F2471C2C67FDE40AD9506387797D192983257067976E19A4D0AED123F3
File Size: 7.83 MB, 7829998 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name MAGNiTUDE & m0nkrus
File Description
  • Autodesk 2020-2024 Cracked NLM Installer
  • Autodesk 2020-2026 Cracked NLM Installer
File Version
  • 10.0.0.0
  • 9.0.0.0
Internal Name AdskNLM
Legal Copyright
  • Copyright © 2022-2024 MAGNiTUDE & m0nkrus
  • Copyright © 2022-2025 MAGNiTUDE & m0nkrus
Original Filename AdskNLM.exe
Private Build
  • March 25, 2025
  • November 15, 2024
Product Name Autodesk Cracked NLM
Product Version
  • 10.0.0.0
  • 9.0.0.0

File Traits

  • dll
  • ntdll
  • x64

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\adskflex.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\adskflex.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\adsk-nlm\delnowmic.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\delnowmic.ps1 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\adsk-nlm\licenses.lic Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\licenses.lic Synchronize,Write Attributes
c:\users\user\appdata\local\temp\adsk-nlm\netapi32.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\netapi32.dll Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\adsk-nlm\nlm.mst Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\nlm.mst Synchronize,Write Attributes
c:\users\user\appdata\local\temp\adsk-nlm\nlm11-19-4-1-ipv4-ipv6-win64.msi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\nlm11-19-4-1-ipv4-ipv6-win64.msi Synchronize,Write Attributes
c:\users\user\appdata\local\temp\adsk-nlm\unnamed.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\unnamed.json Synchronize,Write Attributes
c:\users\user\appdata\local\temp\adsk-nlm\version.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\version.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\adsk-nlm\version_old.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\adsk-nlm\version_old.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 镄ࡶ쒵ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 闰ȁ ਪˣ鈯ˣ遙̃豤̃অˣ炑̃龡^濖̃賬̃獖}偫~엦1਷ˣ邯̃뫯ʃdᵂċᵆċeЂ엦1¶iꙥžr֢ RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 듭ष쒵ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 闱ȁ ਪˣ鈯ˣ遙̃豤̃অˣ炑̃龡^濖̃賬̃獖}偫~엦1਷ˣ邯̃뫯ʃdᵂċᵆċeЂ엦1¶iꙥžr֢ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ᳾᭨흵ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � * �/��Y�d�� ��ރ�p��^�o�eeVs}kP~��1��7 ���ﺃee����1��fe��i/e��rG�v RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 睕ᰤ흵ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � * �/��Y�d�� ��ރ�p��^�o�eeVs}kP~��1��7 ���ﺃee����1��fe��i/e��rG�v RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ᫞놾0ǝ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 k� * �/��Y�d�� ��ރ�p��^�o�>Vs}kP~��1��7 ���ﺃee����1(��fe��iUe��rG�se�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 付뉔0ǝ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 m� * �/��Y�d�� ��ރ�p��^�o�@Vs}kP~��1��7 ���ﺃee����1(��fe��iUe��rG�se�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 볘댄0ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 膨댉0ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 䎈덌0ǝ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
Show More
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssignProcessToJobObject
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelIoFileEx
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateJobObject
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateNamedPipeFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort

30 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
  • WriteConsole
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

"c:\users\user\downloads\a987f2ef1ec6a167b5ec0449616733c66f96dd4f_0007794325" -sfxwaitall:0 "sc" stop AdskLicensingService
(NULL) sc stop AdskLicensingService
WriteConsole: [SC] OpenService
"c:\users\user\downloads\a987f2ef1ec6a167b5ec0449616733c66f96dd4f_0007794325" -sfxwaitall:0 "taskkill" /im AdskLicensingAgent.exe /f
(NULL) taskkill /im AdskLicensingAgent.exe /f
Show More
WriteConsole: ERROR: The proce
"c:\users\user\downloads\a987f2ef1ec6a167b5ec0449616733c66f96dd4f_0007794325" -sfxwaitall:0 "cmd" /c echo D | xcopy /hkry "C:\Users\Vrnildgt\AppData\Local\Temp\Adsk-NLM\version.dll" "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingAgent"
"c:\users\user\downloads\77a88e355c74168f189e22ac61968337ac80121e_0007793602" -sfxwaitall:0 "sc" stop AdskLicensingService
"c:\users\user\downloads\77a88e355c74168f189e22ac61968337ac80121e_0007793602" -sfxwaitall:0 "taskkill" /im AdskLicensingAgent.exe /f
"c:\users\user\downloads\77a88e355c74168f189e22ac61968337ac80121e_0007793602" -sfxwaitall:0 "cmd" /c echo D | xcopy /hkry "C:\Users\Ddsqgbgs\AppData\Local\Temp\Adsk-NLM\version.dll" "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingAgent"
"c:\users\user\downloads\cd2d51b975e90e860874aacfff4e7bed951a2859_0007829998" -sfxwaitall:0 "sc" stop AdskLicensingService
"c:\users\user\downloads\cd2d51b975e90e860874aacfff4e7bed951a2859_0007829998" -sfxwaitall:0 "taskkill" /im AdskLicensingAgent.exe /f
"c:\users\user\downloads\cd2d51b975e90e860874aacfff4e7bed951a2859_0007829998" -sfxwaitall:0 "cmd" /c echo D | xcopy /hkry "C:\Users\Ixbcjrnx\AppData\Local\Temp\Adsk-NLM\version.dll" "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingAgent"
(NULL) cmd /c echo D | xcopy /hkry "C:\Users\Ixbcjrnx\AppData\Local\Temp\Adsk-NLM\version.dll" "C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingAgent"
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /S /D /c" echo D "

Related Posts

Trending

Most Viewed

Loading...