PUP.HackKMS.AW

The detection of PUP.HackKMS.AW on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage. In this report, we will provide an overview of PUP.HackKMS.AW, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is PUP.HackKMS.AW?

PUP.HackKMS.AW is a type of potentially unwanted program that can install itself on your computer without your knowledge or consent. It may be bundled with other software, downloaded from untrusted sources, or spread through exploit kits. Once installed, PUP.HackKMS.AW can perform various malicious activities, including data collection, advertising, and potentially even facilitating the installation of more severe malware.

How PUP.HackKMS.AW Operates

PUP.HackKMS.AW operates by exploiting vulnerabilities in your system, often using social engineering tactics to trick users into installing it. It may disguise itself as a legitimate program or offer fake updates to gain access to your computer. Once inside, it can modify system settings, create unwanted registry entries, and even communicate with its command and control servers to receive further instructions. This can lead to a range of problems, including slowed system performance, unwanted pop-ups, and increased risk of infection by more severe malware.

Symptoms of Infection

Identifying the symptoms of PUP.HackKMS.AW infection can be challenging, as they may resemble those of other malware or system issues. However, common indicators include unexpected pop-ups, slowed browser performance, unfamiliar programs installed on your system, and changes to your homepage or search engine. You may also notice an increase in unwanted advertisements or suspicious system behavior, such as unfamiliar processes running in the background.

  • Unwanted pop-ups and advertisements
  • Slowed system or browser performance
  • Unfamiliar programs or toolbars installed
  • Changes to your homepage or search engine
  • Suspicious system behavior or unfamiliar processes

How to Remove PUP.HackKMS.AW

  1. Boot your computer in Safe Mode with Networking to prevent PUP.HackKMS.AW from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of PUP.HackKMS.AW.
  3. Uninstall any suspicious programs or applications that may be related to PUP.HackKMS.AW, taking care to follow the uninstallation instructions carefully to avoid causing further damage.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or modifications made by PUP.HackKMS.AW.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of PUP.HackKMS.AW have been removed.

Conclusion

Removing PUP.HackKMS.AW from your system requires careful attention to detail and a thorough understanding of its operating methods. By following the steps outlined in this report and maintaining good computing practices, such as regularly updating your software and avoiding untrusted sources, you can protect your computer from potentially unwanted programs like PUP.HackKMS.AW and ensure a safer, more secure online experience. Remember, vigilance and proactive measures are key to preventing malware infections and maintaining the health of your computer.

Analysis Report

General information

Family Name: PUP.HackKMS.AW
Signature status: No Signature

Known Samples

MD5: 7666686a171a110404b00a5413d880ca
SHA1: 09324d1653d40c51beae83e401307894078aaecc
SHA256: 867FBE615A52EA96D734D05FED415D4128B0DCBF42524AEC34653AA52F284BED
File Size: 5.65 KB, 5652 bytes
MD5: 42fb871b72b744bb69a44ea47430440c
SHA1: 8c916ec1474bc884cc0fe688747c00b0505cc3ec
SHA256: 61F32998B47FCBF64A41831B0979587F83F810DDF3AF59E58C2C16546AC36EAC
File Size: 5.65 KB, 5652 bytes
MD5: ea6e7b5b8f7f1c509070cc4a4c66ce04
SHA1: 2f5b3b599f2fbda14bffb381f6a86a97808af8eb
SHA256: DE2CDBF484C7E085037D2A49BB83F9786F8C058D83191BDD93F5B8AC19D14BEE
File Size: 5.65 KB, 5652 bytes
MD5: 648bc20a486b3a7592500b2b04e3b8ad
SHA1: 02fd882d13766ae3be27534c9e3639e86df73fe7
SHA256: BD278ECE9AD047263456AA8ACAFCD80441E537F41239C379A9820CAFE4E70E9A
File Size: 5.65 KB, 5652 bytes
MD5: d97283fd60d128dedfe5326174856a74
SHA1: f6dce73b9910c33b20232f7167294d521a0a733b
SHA256: 8E8294CF5ABF7C17A095F66DF7773A8A246FD8AF784A4A3A61762539BDFFFC06
File Size: 5.65 KB, 5652 bytes
Show More
MD5: eb6a2a3edcda01673c82eee52f1d714d
SHA1: 0f9283f877899c0cd49d4b58c275d7cd66521388
SHA256: 02221D91B96B03B32745ADDE094AE24B845C361E2EF745D2FACA21C77653FB60
File Size: 5.65 KB, 5652 bytes
MD5: 5076a7c73f7f878730385cf8a4007a89
SHA1: e54285fcc03e1b17fa5155ff861f3a132f87e734
SHA256: 14F6CE82E0C2109397FBB706E97EB7340C97959D6E19257F053743AB28E73094
File Size: 5.65 KB, 5652 bytes
MD5: ad2b9b26b8a2800cb70fe0bf6f81f28e
SHA1: 0f29d64580f5a54e59cc643940b3df6d65433a66
SHA256: B92490A208F780DF5892BD54A43BD5061462C167D5FC75F7F4771EC242F9007E
File Size: 5.65 KB, 5652 bytes
MD5: 701c70ec24e3e7e185e928a2d3ddd8e0
SHA1: 67b5fa0c3d468d31651c4eb3e918c8f8c145e563
SHA256: 5F05B0BF33E0A907CDBEC15D7FB989C494594BAF5432D3EB96E00C322782B004
File Size: 5.65 KB, 5652 bytes
MD5: ae22272798766d0a2ccb19785b4e7d74
SHA1: eed6db405313d85fd21aa1117012012f9b3259f2
SHA256: FCFDA22673FC7E26961B56E1BEDFCDFBA9225036C4E9A541DE5CEE19DFD6ECD3
File Size: 5.65 KB, 5652 bytes
MD5: 9bdcc269560435dd9da491231434178f
SHA1: a93cd62f6869cbcfcb53dde8182f9debdef6c5b2
SHA256: AF8AB35A07A4FEAA5B080C1810AD185FE9BDCABA49679882AF8FCDBA5E1AA0E4
File Size: 5.65 KB, 5652 bytes
MD5: 4deb9aa299e8859493d46e0dd7a46c6d
SHA1: 23bebdbf173073d642d062b651a5c26c4846930b
SHA256: 2775A22FE088B4519DA67CA4CA845D907A80F0B180EC5A426A9F44E965F0CF0B
File Size: 5.65 KB, 5652 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 8
Potentially Malicious Blocks: 8
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HackKMS.AW

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext

Related Posts

Trending

Most Viewed

Loading...