PUP.Crack.TF
The detection of PUP.Crack.TF on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent further problems.
Table of Contents
What Is PUP.Crack.TF?
PUP.Crack.TF is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as harmful as other types of malware, such as viruses or Trojans, it can still cause significant issues with your system. PUPs are often installed unintentionally by users, usually when they download and install software from untrusted sources or click on suspicious links.
How PUP.Crack.TF Operates
PUP.Crack.TF, like other PUPs, operates by installing itself on your system and then performing various unwanted actions. These actions can include displaying unwanted advertisements, collecting user data, and modifying system settings. In some cases, PUPs can also install additional malware or create backdoors for other malicious programs to exploit. The primary goal of PUP.Crack.TF is to generate revenue for its creators, often at the expense of the user's system performance and security.
Symptoms of Infection
If your system is infected with PUP.Crack.TF, you may notice several symptoms. These can include a significant decrease in system performance, unwanted advertisements and pop-ups, and changes to your browser settings or homepage. You may also notice that your system is slow to respond or that certain programs are not functioning correctly. In some cases, you may even notice that your system is crashing or freezing frequently.
- Unwanted advertisements and pop-ups
- Changes to browser settings or homepage
- Slow system performance
- System crashes or freezes
- Unexplained changes to system settings
How to Remove PUP.Crack.TF
- Boot your system in Safe Mode with Networking to prevent PUP.Crack.TF from loading and to allow for a more effective removal process.
- Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware, including PUP.Crack.TF.
- Uninstall any suspicious programs that may be related to PUP.Crack.TF. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by PUP.Crack.TF.
- Reboot your system and perform another scan with your anti-malware tool to ensure that PUP.Crack.TF has been completely removed.
Conclusion
Removing PUP.Crack.TF from your system is crucial to prevent further issues and protect your personal data. By following the steps outlined above, you can effectively remove this potentially unwanted program and restore your system to a safe and secure state. It's also essential to practice safe computing habits, such as avoiding suspicious downloads and links, to prevent future infections. Remember to always use reputable anti-malware tools and keep your system and software up to date to ensure the best possible protection against malware and other online threats.
Analysis Report
General information
| Family Name: | PUP.Crack.TF |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
efcc8ca7ae516aabfac2adc6a18c8f3f
SHA1:
a987f2ef1ec6a167b5ec0449616733c66f96dd4f
SHA256:
34BC3E81E0426603F6B974C91C2B58A8BC15C82B3291A44033337E48F27D9D77
File Size:
7.79 MB, 7794325 bytes
|
|
MD5:
87b333f27f9243b37b74d3892bfd35dd
SHA1:
828a8a7d678363d489ec4cb15b6c7c4a3178c5db
SHA256:
349CE9D1921E289E4C6A3B59B8A8BC8B14493029A3F9B7754CB025E214A45A9B
File Size:
74.75 KB, 74752 bytes
|
|
MD5:
92ac7f1a1a3250b9cc99f92634d44455
SHA1:
77a88e355c74168f189e22ac61968337ac80121e
SHA256:
49C17DE629D9D3B013759B3755C8E168BCC42FD7C070C47C0F619A57F0DBEC91
File Size:
7.79 MB, 7793602 bytes
|
|
MD5:
b37d15353437f26573a9a22cff59366b
SHA1:
cd2d51b975e90e860874aacfff4e7bed951a2859
SHA256:
D8D0C2F2471C2C67FDE40AD9506387797D192983257067976E19A4D0AED123F3
File Size:
7.83 MB, 7829998 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have resources
- File doesn't have security information
- File has exports table
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
Show More
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | MAGNiTUDE & m0nkrus |
| File Description |
|
| File Version |
|
| Internal Name | AdskNLM |
| Legal Copyright |
|
| Original Filename | AdskNLM.exe |
| Private Build |
|
| Product Name | Autodesk Cracked NLM |
| Product Version |
|
File Traits
- dll
- ntdll
- x64
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe | Generic Read,Write Attributes |
| \device\namedpipe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\adskflex.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\adskflex.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\delnowmic.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\delnowmic.ps1 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\licenses.lic | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\licenses.lic | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\netapi32.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\netapi32.dll | Synchronize,Write Attributes |
Show More
| c:\users\user\appdata\local\temp\adsk-nlm\nlm.mst | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\nlm.mst | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\nlm11-19-4-1-ipv4-ipv6-win64.msi | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\nlm11-19-4-1-ipv4-ipv6-win64.msi | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\unnamed.json | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\unnamed.json | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\version.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\version.dll | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\version_old.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\adsk-nlm\version_old.dll | Synchronize,Write Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 镄ࡶ쒵ǜ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 闰 ȁ ਪˣ 鈯ˣ 遙̃ 豤̃ অˣ 炑̃ 龡^ 濖̃ 賬̃ 獖} 偫~ 엦1 ˣ 邯̃ 뫯ʃd ᵂċ ᵆċe Ђ 엦1 ¶i ꙥr ֢ | RegNtPreCreateKey |
Show More
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 듭ष쒵ǜ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 闱 ȁ ਪˣ 鈯ˣ 遙̃ 豤̃ অˣ 炑̃ 龡^ 濖̃ 賬̃ 獖} 偫~ 엦1 ˣ 邯̃ 뫯ʃd ᵂċ ᵆċe Ђ 엦1 ¶i ꙥr ֢ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ᭨흵ǜ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | � * � /�� Y� d� � � �ރ �p ��^ �o � ee Vs} kP~ ��1 �� 7 � �� ﺃ e e�� ��1 �� f e�� i / e�� r G � v | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 睕ᰤ흵ǜ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | � * � /�� Y� d� � � �ރ �p ��^ �o � ee Vs} kP~ ��1 �� 7 � �� ﺃ e e�� ��1 �� f e�� i / e�� r G � v | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 놾0ǝ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | k� * � /�� Y� d� � � �ރ �p ��^ �o � > |