PUP.Crypto Tab

The detection of PUP.Crypto Tab on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Crypto Tab?

PUP.Crypto Tab is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in nature but can still cause problems for users. PUPs can be installed on a system without the user's knowledge or consent, often through bundled software downloads or deceptive installation practices. Once installed, PUP.Crypto Tab may exhibit behaviors that are undesirable, such as displaying unwanted advertisements, collecting user data, or consuming system resources.

How PUP.Crypto Tab Operates

PUP.Crypto Tab operates by installing itself on a system and then executing its payload. This payload can include a range of activities, such as displaying advertisements, collecting user data, or installing additional malware. PUP.Crypto Tab may also modify system settings or configuration files to ensure its persistence and evade detection. In some cases, PUP.Crypto Tab may be designed to interact with other malware or PUPs, creating a more complex and challenging threat landscape.

Symptoms of Infection

The symptoms of a PUP.Crypto Tab infection can vary, but common indicators include unwanted advertisements or pop-ups, slow system performance, and unusual network activity. Users may also notice that their browser settings have been modified or that unfamiliar programs are installed on their system. In some cases, PUP.Crypto Tab may cause system crashes or freezes, or generate fake error messages or alerts.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Unusual network activity
  • Modified browser settings
  • Unfamiliar programs installed on the system

How to Remove PUP.Crypto Tab

  1. Boot your system in Safe Mode with Networking to prevent PUP.Crypto Tab from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.Crypto Tab and any associated malware.
  3. Uninstall any suspicious programs that may be related to PUP.Crypto Tab, taking care to review installation dates and program descriptions.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any modifications made by PUP.Crypto Tab.
  5. Reboot your system and perform a follow-up scan to ensure that PUP.Crypto Tab has been completely removed.

Conclusion

Removing PUP.Crypto Tab from your system requires a combination of technical knowledge and caution. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this potentially unwanted program and prevent future infections. It is essential to remain vigilant and to regularly scan your system for malware to ensure your computer and personal data remain secure.

Analysis Report

General information

Family Name: PUP.Crypto Tab
Signature status: No Signature

Known Samples

MD5: 526f78d19e7d9d08651eca15e2532e7b
SHA1: 8aa1c6620033239b7e2d19f3efebf1052b0d7849
SHA256: 64C8C7417F0534D1C073234BC7EDAE49B24F7F6CBE8928E5E5C3A8841BA505D8
File Size: 3.63 MB, 3633576 bytes
MD5: 9072bcdf71c72f4656594491d52e10c6
SHA1: 79fdf9a3ac6314e244ab8fc5cab31c8cfa5e0835
SHA256: 1C83A3E1FA241F6822DDFF9A6ACD15FE55B4B1297315297C34E297BA7584E3FD
File Size: 7.38 MB, 7375784 bytes
MD5: e79702c422f684880645dbf81564be34
SHA1: 6c6e13cad4a6a4d4c636c9aa929d5737bcfe82b1
SHA256: 6CD6B285C85F7F957B6242D3A44C6753EC1451AF0B9D35555F3B79E1954C60F4
File Size: 1.49 MB, 1492992 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name The Chromium and CryptoTab Browser Authors
Company Short Name The Chromium and CryptoTab Browser Authors
File Description
  • CryptoTab Browser Installer
  • CryptoTabUpdater
File Version
  • 109.0.5414.120
  • 1.0.0.6
Internal Name setup
Last Change 168eebf2055fd26ca8c71787b7b3f9fe7c90d13d-refs/branch-heads/5414@{#1459}
Legal Copyright
  • Copyright (C) CRYPTOCOMPANY OU 2023
  • Copyright 2023 The Chromium and CryptoTab Browser Authors. All rights reserved.
Official Build 1
Product Name
  • CryptoTab Browser Installer
  • CryptoTabUpdater
Product Short Name CryptoTab Browser Installer
Product Version
  • 109.0.5414.120
  • 1.0.0.6

Digital Signatures

Signer Root Status
CRYPTOCOMPANY OÜ DigiCert EV Code Signing CA (SHA2) Hash Mismatch
CRYPTOCOMPANY OÜ DigiCert EV Code Signing CA (SHA2) Self Signed
CRYPTOCOMPANY OÜ DigiCert EV Code Signing CA (SHA2) Self Signed

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 3,091
Potentially Malicious Blocks: 12
Whitelisted Blocks: 745
Unknown Blocks: 2,334

Visual Map

? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 ? ? 0 0 ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? x ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 0 0 0 ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 ? ? ? ? 0 ? 0 0 ? 0 ? 0 ? 0 ? ? 0 ? ? ? 0 ? 0 ? 0 ? ? ? 0 0 ? ? 0 0 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? 0 ? ? ? 0 ? ? 0 ? 0 0 ? 0 ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? x ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 0 ? ? ? 0 ? ? 0 ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 ? ? 0 0 ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? 0 0 ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? 0 ? ? ? 0 0 ? ? ? 0 ? ? 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKCU\software\cryptotab browser::current_version_setup 2.4.15 RegNtPreCreateKey
HKCU\software\cryptotab browser::current_version_setup_path c:\users\user\downloads\8aa1c6620033239b7e2d19f3efebf1052b0d7849_0003633576 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
Show More
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState