PUP.Easy Ad Blocker

Threat Scorecard

Popularity Rank: 2,776
Threat Level: 10 % (Normal)
Infected Computers: 3,630
First Seen: July 8, 2023
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of PUP.Easy Ad Blocker on your system indicates the presence of a potentially unwanted program (PUP) that may be causing unwanted advertisements or other issues. It is essential to understand the nature of this threat and take appropriate steps to remove it from your computer to prevent potential harm.

What Is PUP.Easy Ad Blocker?

PUP.Easy Ad Blocker is a type of potentially unwanted program that is designed to display advertisements or modify your browsing experience in some way. While it may not be as malicious as other types of malware, it can still cause problems and compromise your system's security. PUPs like PUP.Easy Ad Blocker often get installed on your system without your knowledge or consent, usually through bundled software or deceptive downloads.

How PUP.Easy Ad Blocker Operates

Once installed, PUP.Easy Ad Blocker can operate in various ways, including displaying pop-up ads, modifying your browser's settings, or collecting your browsing data. It may also install additional components or plugins to extend its functionality. In some cases, PUPs can even install other malware or PUPs on your system, leading to further complications. The primary goal of PUP.Easy Ad Blocker is to generate revenue for its creators, often at the expense of your browsing experience and system security.

Symptoms of Infection

If your system is infected with PUP.Easy Ad Blocker, you may notice various symptoms, including an increase in pop-up ads or banners, unexpected browser redirects, or changes to your browser's homepage or search engine. You may also experience slower system performance or crashes, as the PUP consumes system resources. In some cases, you may even notice unfamiliar programs or toolbars installed on your system.

  • Increased pop-up ads or banners
  • Unexpected browser redirects
  • Changes to browser settings, such as homepage or search engine
  • Slower system performance or crashes
  • Unfamiliar programs or toolbars installed on your system

How to Remove PUP.Easy Ad Blocker

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.Easy Ad Blocker and any associated components.
  3. Uninstall any suspicious programs or applications that may be related to the PUP.
  4. Reset your browser settings, including Chrome, Firefox, and Edge, to their default values to remove any modifications made by the PUP.
  5. Reboot your system and perform another scan to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.Easy Ad Blocker from your system is crucial to prevent potential harm and restore your browsing experience. By following the steps outlined above, you can effectively remove this PUP and protect your system from similar threats in the future. It is essential to remain vigilant and take proactive measures to secure your system, including keeping your operating system and software up to date, using reputable anti-malware tools, and being cautious when downloading software or clicking on links from unknown sources.

SpyHunter Detects & Remove PUP.Easy Ad Blocker

File System Details

PUP.Easy Ad Blocker may create the following file(s):
# File Name MD5 Detections
1. weab.exe 8fb1ff7748158755ad104cfc003070fc 440
2. installer.exe d1aa5fe81edb300e6ceefd29510932ec 331
3. $RISAB18.exe fd62a3510ff7da8ee3c376b4685b84aa 167
More files

Analysis Report

General information

Family Name: PUP.Easy Ad Blocker
Signature status: Self Signed

Known Samples

MD5: aec6c727ca5d9b1cf84288af738d3d44
SHA1: 667cae4734782771a19d01780aa0ab9af19b8852
File Size: 3.38 MB, 3377240 bytes
MD5: 5b20c00abea03df88c44cd11d0e79a92
SHA1: a07cabab8ebd504ce01f4d8c005f69d9e3b1c27c
SHA256: D1BF9C474F26A6E7AAF23ED6C150C57DAC5673CC61CE66FDCECF473F414DEF91
File Size: 5.86 MB, 5857088 bytes
MD5: b60ff9cdad58e65bd1a7199961ca51a4
SHA1: 91f01a266f5064e743180e1f57c5547519381e08
SHA256: 5D81EB5B265A1AB2DDEFC41D9662E7C71EEF93E72D4A578C7CF95C37CD8AA04F
File Size: 2.65 MB, 2650264 bytes
MD5: 3e39bb5f3540c47efff1a2702736ab43
SHA1: 17bef2ff7d40be143627b263ef3e8f64b4a4d10a
SHA256: 873B3FA81DC5D8515B6E1317F2C1A4511B659DFF1BE1491A296D4D981E468752
File Size: 3.38 MB, 3377240 bytes
MD5: e09e700657854533e66093114d73d5f9
SHA1: ccb27432fffa81a33362b18a54ec1e013e3e5f94
SHA256: C82CAA9F46FC532B460368E4D73B3C645232C7783194FFA44B08D43489413948
File Size: 5.86 MB, 5857136 bytes
Show More
MD5: 2e03f75f927588bf913730f79a1c09a5
SHA1: 824947364c4ce8c34769730c08625ed46e545f99
SHA256: 1ADD8CD5485AE556E1BFAC12C9490F5F786669204C7A7709A9120B5B57458C76
File Size: 3.38 MB, 3377240 bytes
MD5: 3cffe04a45bd4093f7eb0832a9c0f8ad
SHA1: 6ed2e5c191982cb7c7ad6e311ae61bd7443f7d2e
SHA256: F69BB74A0B072656A31333C09137035A37765924A38CB58E223A951F0351CA6F
File Size: 2.65 MB, 2650336 bytes
MD5: 9e4eaf855b9a64c9068c34c158ba5522
SHA1: 8ccdb4a8cd8682cc026dada2980beb575a1b0226
SHA256: 5040A2F3C3642C577015CEABEB0875847323538A985F6F8A8A9AA3A39EDDD2B7
File Size: 5.86 MB, 5857088 bytes
MD5: 74cc680659d6da3c9efe8c79026b48e2
SHA1: 1a9d9386e4be702d8dd7232fb4c17bb6a627a483
SHA256: 6C7769F6C350C68BFEA96D2C8911DBDE7325388EC530EE9265EA3B5C8A4B360E
File Size: 3.02 MB, 3024472 bytes
MD5: bebb51da42349b00f0ef42b708fe9faa
SHA1: 2a4e951fe85118df7231dd447baaa4e7c4c7f9d5
SHA256: 04B81728712981E1B9BEB2EC322557453F07EB14B531F460809DD978C3A550F9
File Size: 2.65 MB, 2650440 bytes
MD5: 20b6759093b8bbbd8224af32792b1f5f
SHA1: db35277f19b7b2617d53115a8b88ddaaa984cfc4
SHA256: C105B4DD09A07AE42B7060899F2C0D8395D3C3104E5131B28C643D42F0CECBC0
File Size: 2.65 MB, 2650192 bytes
MD5: 15ca8b53c075876f4d20393c49b38748
SHA1: b7a9f7270ff6aae6878bb412b0c8b4ac255b2750
SHA256: 812DE76A367DBF4B2C7D6CB7B0C2735CA750041D491682D7F9A8586FF6A2AF5B
File Size: 2.66 MB, 2660965 bytes
MD5: 67826e0965cef8309586d00b1bb629f7
SHA1: 822d2bc83012273c7db705d1b5ff34ec410177ad
SHA256: B0965826CC14BB0C7DEA0184E8D24BEE1DFDD5614911F8BCDF61C671B0DC961B
File Size: 2.65 MB, 2650064 bytes
MD5: 43ec49ae47f5b7986693b8b1d6b0c647
SHA1: 6777c95eb5674d319688ce0829353536d800f540
SHA256: A286D5C14C3F7DCF71A7EDDA522925168EDEC38965A655A74FD62C4BDAEFB062
File Size: 2.79 MB, 2788806 bytes
MD5: 2d610497dba16a2d8d57d199105b172f
SHA1: 66c23281138bfd23fa10ca7e273cd211996388aa
SHA256: E47D662C2F90235CA8435D9D531E2D5F280091193D763A02E958D69F402C6DC0
File Size: 2.86 MB, 2862220 bytes
MD5: e667f3049898ff618cea3970239c7ec4
SHA1: 0c78d7d344ae2f84e6bc604addb6b634d51e36fb
SHA256: D42D524F6F3A7DD059C8199D32541689F914B0BAD7B378C313DD7DEDEC0A877A
File Size: 2.52 MB, 2521184 bytes
MD5: ff045e957860d8f9ef9de702f1ee7cb9
SHA1: 162d7babf48f172b24b3f85973a99e0fea6517d2
SHA256: BAABEECE992F300395104546F5AD71C2153AE0E88E4F9BE8DB087EABB310958E
File Size: 2.65 MB, 2650424 bytes
MD5: b10416b93e3861dcd7804d12d827a7c9
SHA1: 572545017b7ce1b40113d559d3aa8a47b84d2de9
SHA256: 5F8BDBEB4A7C43883F053670DEB21766F9CBACAAB8159D7627B860DEE959184B
File Size: 2.65 MB, 2650448 bytes
MD5: a08eb96b0e1aa79bec8bc8f696decb7a
SHA1: f0a4f0e14370fac8ec15c24ca934600d4d33c224
SHA256: C9D4F3C78795E70443B00A961AA5A6316A779CA83B47AE8210CE4658F6FF1DFC
File Size: 2.65 MB, 2650088 bytes
MD5: de4e6f20a126c887e4d1882ce07ef3ad
SHA1: e8cdd9bc8cb5db1ede128822cd47c9a7551414d9
SHA256: 8B9B174873ABE205D93FC90FA37C3DBE7C70C1C6F4357CBF227F580800FA7AAF
File Size: 3.38 MB, 3377240 bytes
MD5: fd9da9b251762a5ea270e58d403c154e
SHA1: 9795f9006eea2870b87225ada866a28a7f6638f9
SHA256: 6C271766A6D145AEC8BC844BFB15F32EB60B730AAC13C9630F0294E3820936CE
File Size: 5.86 MB, 5857120 bytes
MD5: fb7ab825764200ed1312f96e78dc6427
SHA1: 9cdc9ccd74e8abb1d91a0dcd8ba68931f354191c
SHA256: 6A0CAA9234EBB4365E138D512ABAECBF886E10A9698871BBF8874BF912F706C4
File Size: 5.86 MB, 5857064 bytes
MD5: e9d9959c311718fd54b70a4cc1c1d534
SHA1: 9ea0e0da40631de6f3600ff86c168d2f26030819
SHA256: 7C2478632E7D6C1B8030CA07FB5035F62D3387330DF22CEB46CBF0BBB437119A
File Size: 5.86 MB, 5856952 bytes
MD5: 227e4dd7903dcc9bbc1b703cc255cf30
SHA1: a329ec7ff3446a8f9bb967764576816efffc234c
SHA256: 833166EEBB3A211599B57F283588CCC346FDA61B63CA2563612FA72D0614F5B7
File Size: 5.86 MB, 5857128 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
File Description
  • IMDownloader Installer
  • Parlem Installazione
  • Setup/Uninstall
File Version
  • 51.1052.0.0
  • 5.3.12.3318
  • 2.4.0.9160
  • 2.4.0.9134
  • 2.4.0.9073
  • 1.00
Internal Name TJprojMain
Original Filename TJprojMain.exe
Product Name
  • IMDownloader
  • Nerkato
  • Project1
Product Version
  • 5.3.12.3318
  • 2.4.0.9160
  • 2.4.0.9134
  • 2.4.0.9073
  • 1.00

Digital Signatures

Signer Root Status
INNOVA MEDIA internetne storitve d.o.o. GlobalSign GCC R45 EV CodeSigning CA 2020 Self Signed

Block Information

Similar Families

  • Agent.FDD
  • Banker.LH
  • Banker.R
  • Injector.AK
  • Lumma.GFD
Show More
  • Ousaban.V
  • Rugmi.IA
  • Sheloader.A
  • Stealer.KF

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-3r2bb.tmp\ccb27432fffa81a33362b18a54ec1e013e3e5f94_0005857136.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-4d0s7.tmp\db35277f19b7b2617d53115a8b88ddaaa984cfc4_0002650192.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-79ae1.tmp\572545017b7ce1b40113d559d3aa8a47b84d2de9_0002650448.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-7gto4.tmp\9ea0e0da40631de6f3600ff86c168d2f26030819_0005856952.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-895bj.tmp\a329ec7ff3446a8f9bb967764576816efffc234c_0005857128.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-au399.tmp\9cdc9ccd74e8abb1d91a0dcd8ba68931f354191c_0005857064.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-d6550.tmp\6ed2e5c191982cb7c7ad6e311ae61bd7443f7d2e_0002650336.tmp Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\is-eiahq.tmp\822d2bc83012273c7db705d1b5ff34ec410177ad_0002650064.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-f4ita.tmp\a07cabab8ebd504ce01f4d8c005f69d9e3b1c27c_0005857088.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jeveo.tmp\2a4e951fe85118df7231dd447baaa4e7c4c7f9d5_0002650440.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-lmufg.tmp\9795f9006eea2870b87225ada866a28a7f6638f9_0005857120.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-mftr0.tmp\162d7babf48f172b24b3f85973a99e0fea6517d2_0002650424.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-n43dc.tmp\91f01a266f5064e743180e1f57c5547519381e08_0002650264.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-oterc.tmp\f0a4f0e14370fac8ec15c24ca934600d4d33c224_0002650088.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-q6nga.tmp\0c78d7d344ae2f84e6bc604addb6b634d51e36fb_0002521184.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ski9f.tmp\8ccdb4a8cd8682cc026dada2980beb575a1b0226_0005857088.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg �� �v xy ����T��������%����3bBx��#��$kF%�&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1�1HO5,]=�@V�A��B��G�IH[uH�pJ��N$N�U_*X�\te_�za$b"hc�wc�zh�ri��j�bk` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg �� �v xy ����T��������%����3bBx��#��$kF%�&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1�1HO5,]=�@V�A��B��G�IH[uH�pJ��N$N�U_*X�\te_�za$b"hc�wc�ze�vh�ri��j�b RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tXjg�8 �� �v �Z ����T�������dc�%����3bBx�<��#�#��$kF%�&� &�-(�(X�(�)E)�`*J*9*�"+�[,��-!R0P%1`1�1HO1�D5,]9ߔ=�@V�A��B��G�IH[uH�pI��K��N$N�O�`R20U_* RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tXjg�8 �� �v �Z ����T�������dc�%����3bBx�<��#�#��$kF%�&� &�-(�(X�(�)E)�`*J*9*�"+�[,��-!R0P%1`1�1HO1�D5,]9ߔ=�@V�A��B��G�IH[uH�pI��K��N$N�O�`R20U_* RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

"C:\Users\Ygnyfxct\AppData\Local\Temp\is-F4ITA.tmp\a07cabab8ebd504ce01f4d8c005f69d9e3b1c27c_0005857088.tmp" /SL5="$5005E,4807120,845824,c:\users\user\downloads\a07cabab8ebd504ce01f4d8c005f69d9e3b1c27c_0005857088"
"C:\Users\Vejodllr\AppData\Local\Temp\is-N43DC.tmp\91f01a266f5064e743180e1f57c5547519381e08_0002650264.tmp" /SL5="$1025C,1598636,845824,c:\users\user\downloads\91f01a266f5064e743180e1f57c5547519381e08_0002650264"
"C:\Users\Xqbuogfc\AppData\Local\Temp\is-3R2BB.tmp\ccb27432fffa81a33362b18a54ec1e013e3e5f94_0005857136.tmp" /SL5="$30142,4807120,845824,c:\users\user\downloads\ccb27432fffa81a33362b18a54ec1e013e3e5f94_0005857136"
"C:\Users\Mrenzbdr\AppData\Local\Temp\is-D6550.tmp\6ed2e5c191982cb7c7ad6e311ae61bd7443f7d2e_0002650336.tmp" /SL5="$3013E,1598636,845824,c:\users\user\downloads\6ed2e5c191982cb7c7ad6e311ae61bd7443f7d2e_0002650336"
"C:\Users\Hjelfugl\AppData\Local\Temp\is-SKI9F.tmp\8ccdb4a8cd8682cc026dada2980beb575a1b0226_0005857088.tmp" /SL5="$60052,4807120,845824,c:\users\user\downloads\8ccdb4a8cd8682cc026dada2980beb575a1b0226_0005857088"
Show More
"C:\Users\Bzwuslgb\AppData\Local\Temp\is-JEVEO.tmp\2a4e951fe85118df7231dd447baaa4e7c4c7f9d5_0002650440.tmp" /SL5="$1D07D2,1598767,845824,c:\users\user\downloads\2a4e951fe85118df7231dd447baaa4e7c4c7f9d5_0002650440"
"C:\Users\Githwazy\AppData\Local\Temp\is-4D0S7.tmp\db35277f19b7b2617d53115a8b88ddaaa984cfc4_0002650192.tmp" /SL5="$22028A,1598543,845824,c:\users\user\downloads\db35277f19b7b2617d53115a8b88ddaaa984cfc4_0002650192"
"C:\Users\Wimrlkpo\AppData\Local\Temp\is-EIAHQ.tmp\822d2bc83012273c7db705d1b5ff34ec410177ad_0002650064.tmp" /SL5="$3032A,1598543,845824,c:\users\user\downloads\822d2bc83012273c7db705d1b5ff34ec410177ad_0002650064"
"C:\Users\Okdqdhwl\AppData\Local\Temp\is-Q6NGA.tmp\0c78d7d344ae2f84e6bc604addb6b634d51e36fb_0002521184.tmp" /SL5="$6017C,1584344,832512,c:\users\user\downloads\0c78d7d344ae2f84e6bc604addb6b634d51e36fb_0002521184"
"C:\Users\Gkowumwe\AppData\Local\Temp\is-MFTR0.tmp\162d7babf48f172b24b3f85973a99e0fea6517d2_0002650424.tmp" /SL5="$80244,1598660,845824,c:\users\user\downloads\162d7babf48f172b24b3f85973a99e0fea6517d2_0002650424"
"C:\Users\Ngbobngt\AppData\Local\Temp\is-79AE1.tmp\572545017b7ce1b40113d559d3aa8a47b84d2de9_0002650448.tmp" /SL5="$90294,1598767,845824,c:\users\user\downloads\572545017b7ce1b40113d559d3aa8a47b84d2de9_0002650448"
"C:\Users\Zpmhudcn\AppData\Local\Temp\is-OTERC.tmp\f0a4f0e14370fac8ec15c24ca934600d4d33c224_0002650088.tmp" /SL5="$6035A,1598543,845824,c:\users\user\downloads\f0a4f0e14370fac8ec15c24ca934600d4d33c224_0002650088"
"C:\Users\Fsqtpyqy\AppData\Local\Temp\is-LMUFG.tmp\9795f9006eea2870b87225ada866a28a7f6638f9_0005857120.tmp" /SL5="$90318,4807120,845824,c:\users\user\downloads\9795f9006eea2870b87225ada866a28a7f6638f9_0005857120"
"C:\Users\Cnsyttyq\AppData\Local\Temp\is-AU399.tmp\9cdc9ccd74e8abb1d91a0dcd8ba68931f354191c_0005857064.tmp" /SL5="$C0366,4807120,845824,c:\users\user\downloads\9cdc9ccd74e8abb1d91a0dcd8ba68931f354191c_0005857064"
"C:\Users\Qoosmqud\AppData\Local\Temp\is-7GTO4.tmp\9ea0e0da40631de6f3600ff86c168d2f26030819_0005856952.tmp" /SL5="$D0164,4807120,845824,c:\users\user\downloads\9ea0e0da40631de6f3600ff86c168d2f26030819_0005856952"
"C:\Users\Gvcltzgu\AppData\Local\Temp\is-895BJ.tmp\a329ec7ff3446a8f9bb967764576816efffc234c_0005857128.tmp" /SL5="$A0356,4807120,845824,c:\users\user\downloads\a329ec7ff3446a8f9bb967764576816efffc234c_0005857128"

Related Posts

Trending

Most Viewed

Loading...