PUP.Fusion.C

The detection of PUP.Fusion.C on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. This type of software is designed to operate without the user's full knowledge or consent, often leading to unwanted changes in browser settings, the installation of additional unwanted programs, or the display of intrusive advertisements.

What Is PUP.Fusion.C?

PUP.Fusion.C is categorized as a potentially unwanted program, which means it is not necessarily malicious in nature but can still cause significant disruptions to your computing experience. PUPs like PUP.Fusion.C are often bundled with other software or downloaded from the internet, sometimes without the user's explicit consent. They can lead to a range of issues, from slowing down your computer to exposing you to more serious security risks by creating vulnerabilities that other malware can exploit.

How PUP.Fusion.C Operates

PUPs typically operate by integrating themselves into your system and browser settings, allowing them to collect data, display advertisements, or change your browser's homepage and default search engine without your permission. They may also install additional software or toolbars that you don't need, further cluttering your system and potentially opening doors for more malicious activities. The operation of PUP.Fusion.C is likely aimed at generating revenue for its creators through pay-per-click advertising, data collection, or by selling your browsing history to third parties.

Symptoms of Infection

Symptoms of a PUP.Fusion.C infection can vary but commonly include an increase in unwanted advertisements or pop-ups, changes to your browser's settings, the installation of unknown programs or toolbars, and a general slowdown in your computer's performance. You might also notice that your browser's homepage has changed or that you are being redirected to unwanted websites. In some cases, the presence of a PUP can lead to more severe issues, such as data breaches or the infection of your system with more dangerous malware.

How to Remove PUP.Fusion.C

  1. Enter Safe Mode with Networking to prevent PUP.Fusion.C from loading and to give you a clean environment to perform removal steps.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove all components related to PUP.Fusion.C.
  3. Manually uninstall any suspicious programs that you have installed recently or that you do not recognize. Be cautious and ensure you are removing the correct programs to avoid causing system instability.
  4. Reset your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, etc.) to their default settings to remove any unwanted changes made by PUP.Fusion.C.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all traces of PUP.Fusion.C have been removed.

Conclusion

Removing PUP.Fusion.C from your system is crucial to restoring your computer's performance and protecting your personal data. By following the steps outlined above and maintaining good computing practices, such as regularly scanning your system for malware and being cautious with downloads and email attachments, you can significantly reduce the risk of future infections. Remember, prevention is key, so ensure your antivirus software is up to date, and consider using additional security tools to provide layered protection against various types of threats.

Analysis Report

General information

Family Name: PUP.Fusion.C
Signature status: No Signature

Known Samples

MD5: 32829d04a087f620c874175df39b90bc
SHA1: ec3099e444443e301643f8a5b97a19cadb66ad99
File Size: 3.02 MB, 3016140 bytes
MD5: ae07043d69648aa19f80a375519558bd
SHA1: b08f0f259aa577ea518ecc2d19e39d10348f18ed
SHA256: 1E458582081739248976B7CAF5FF7E2FB3D85F7CF9C14C1239F7FCAEB05EAF64
File Size: 1.93 MB, 1930408 bytes
MD5: facf8e1a224f0b2cf1ee1c4c110ecec2
SHA1: a9ec7b950ffeb0a174cd886a5429f2fb8be9d888
SHA256: 6410A6ACB415B90AB7EB8046EF4CA269C95D6B1248C0E7A95A51641B9E55B67D
File Size: 938.68 KB, 938680 bytes
MD5: e6d65500db23228f18a72ca5aedcbb4f
SHA1: d5110e9385800a189c3e14437a7154d3195ec5b0
SHA256: 2523239E9D80D4C3443E51408D0FAB2B7E2D707241633C70ACF63FD87214DC95
File Size: 1.02 MB, 1017856 bytes
MD5: 3fc9a285f10cfa15633128471f0c145d
SHA1: 870afeae19ad0c7a829cd88564eb93d0fafca217
SHA256: 262244B303DB69AC0C3EA6E10BC2BD81292774C5D1880EDD21F748B60BEC9AA9
File Size: 5.25 MB, 5253120 bytes
Show More
MD5: 8daa24ce8f5aab3bad46c179a309305a
SHA1: f3f1f5f8d28353ea0874653c9bc3c6cfff7780bd
SHA256: 91CC07F84935A597212B58CAAFE943CF6DEAD4B51F771DB487507E190BBF0506
File Size: 6.34 MB, 6342365 bytes
MD5: ee19dec0cf50e70108d8cc07a7a78a00
SHA1: 5cd581b602b692a7d5f977395dc61f36187d9b1d
SHA256: 8B5332480DC124AF53E78D50A5AF20F833010CEDF36C6DA293FC3515C18998D3
File Size: 9.04 MB, 9037136 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • GOM Player Setup File (2016-08-18 16:21:49)
  • This installation was built with Inno Setup.
Company Name
  • Burnaware
  • Canneverbe Limited
  • Ellora Assets Corporation
  • Gretech Corporation
File Description
  • CDBurnerXP
  • Freemake YouTube To MP3 Boom Setup
  • GOM Player Setup File
  • PDF Shaper Free Installation
File Version
  • 7.1.0.0
  • 4.5.7.6623
  • 2.3
  • 1.0.5.15
Legal Copyright
  • 2001-2014 Canneverbe Limited
  • Copyright(C) Since 2003 Gretech Corporation.
  • Copyright © 2016 Burnaware.
Product Name
  • CDBurnerXP
  • Freemake YouTube To MP3 Boom
  • GOM Player
  • PDF Shaper Free
Product Version
  • 7.1.0.0
  • 4.5.7.6623
  • 2.3.6.5260
  • 1.0.4

Digital Signatures

Signer Root Status
Burnaware COMODO RSA Code Signing CA Self Signed
Canneverbe Limited DigiCert SHA2 Assured ID Code Signing CA Hash Mismatch
Ellora Assets Corp GlobalSign CodeSigning CA - SHA256 - G3 Self Signed
RealNetworks, Inc. thawte SHA256 Code Signing CA Self Signed

File Traits

  • dll
  • HighEntropy
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\detect64.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\detect64.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\experimentalscene.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\experimentalscene.bmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\is-24e3l.tmp\f3f1f5f8d28353ea0874653c9bc3c6cfff7780bd_0006342365.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-2fs2t.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-2fs2t.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-2fs2t.tmp\fusion.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\is-59a1u.tmp\5cd581b602b692a7d5f977395dc61f36187d9b1d_0009037136.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-ukotn.tmp\b08f0f259aa577ea518ecc2d19e39d10348f18ed_0001930408.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nse123.tmp\advsplash.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nse123.tmp\fusion.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nse123.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nse123.tmp\modern-wizard.bmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nse123.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nse123.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nspc5.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\setup log 2025-09-14 #001.txt Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Keyboard Access
  • GetKeyState

Shell Command Execution

"C:\Users\Ydzxllvk\AppData\Local\Temp\Detect64.exe"
"C:\Users\Roitmfhm\AppData\Local\Temp\is-UKOTN.tmp\b08f0f259aa577ea518ecc2d19e39d10348f18ed_0001930408.tmp" /SL5="$10278,1438622,399872,c:\users\user\downloads\b08f0f259aa577ea518ecc2d19e39d10348f18ed_0001930408"
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a9ec7b950ffeb0a174cd886a5429f2fb8be9d888_0000938680.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d5110e9385800a189c3e14437a7154d3195ec5b0_0001017856.,LiQMAxHB
"C:\Users\Ajrhnajq\AppData\Local\Temp\is-24E3L.tmp\f3f1f5f8d28353ea0874653c9bc3c6cfff7780bd_0006342365.tmp" /SL5="$1503AE,5672589,502272,c:\users\user\downloads\f3f1f5f8d28353ea0874653c9bc3c6cfff7780bd_0006342365"
Show More
"C:\Users\Gurvrfpc\AppData\Local\Temp\is-59A1U.tmp\5cd581b602b692a7d5f977395dc61f36187d9b1d_0009037136.tmp" /SL5="$190472,8536962,189952,c:\users\user\downloads\5cd581b602b692a7d5f977395dc61f36187d9b1d_0009037136"