PUP.KDE.A

The detection of PUP.KDE.A on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent future infections.

What Is PUP.KDE.A?

PUP.KDE.A is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in nature but can still cause problems for users, such as displaying unwanted advertisements, collecting personal data, or modifying system settings without consent. PUPs can be installed on a system through various means, including bundled software downloads, infected websites, or exploited vulnerabilities.

How PUP.KDE.A Operates

PUP.KDE.A, like other PUPs, can operate in various ways to achieve its goals. It may display unwanted advertisements, redirect browser searches, or collect user data, such as browsing history and personal information. In some cases, PUPs can also install additional malware or create backdoors for remote access. The primary objective of PUP.KDE.A is to generate revenue for its creators, often at the expense of the user's privacy and system performance.

Symptoms of Infection

Systems infected with PUP.KDE.A may exhibit various symptoms, including unwanted pop-ups, slow system performance, and unexpected changes to browser settings or search results. Users may also notice unfamiliar programs or toolbars installed on their system, or experience frequent crashes or freezes. In some cases, PUP.KDE.A may also collect and transmit user data, such as login credentials or credit card information, to its creators or third-party entities.

  • Unwanted advertisements or pop-ups
  • Slow system performance or crashes
  • Unexpected changes to browser settings or search results
  • Unfamiliar programs or toolbars installed on the system
  • Collection and transmission of user data

How to Remove PUP.KDE.A

  1. Boot your system in Safe Mode with Networking to prevent PUP.KDE.A from loading and to allow for a clean removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.KDE.A and any associated malware.
  3. Uninstall any suspicious programs or applications that may be related to PUP.KDE.A, taking care to follow the uninstallation instructions carefully.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any modifications made by PUP.KDE.A.
  5. Reboot your system and perform a follow-up scan to ensure that PUP.KDE.A has been completely removed and that no additional threats are present.

Conclusion

Removing PUP.KDE.A from your system is crucial to preventing further damage and protecting your personal data. By following the steps outlined above and maintaining good security practices, such as regularly updating your operating system and software, using strong antivirus protection, and being cautious when downloading software or clicking on links, you can help prevent future infections and keep your system secure. Remember to always be vigilant when online and to report any suspicious activity to the relevant authorities.

Analysis Report

General information

Family Name: PUP.KDE.A
Signature status: No Signature

Known Samples

MD5: 76ee65badce8e9adcfe67940f5a6357c
SHA1: 02abf6350e3cc73274d065c8b40186455d887033
File Size: 1.43 MB, 1431161 bytes
MD5: f5848c3d9036db994034a737573fd3be
SHA1: f3e62d018776df4ea9ad00e9b9f543d0eb7033fe
SHA256: 68DC64285B8E7DC8A5A362E65BC3E4781447E63529BEDAF47D9544CBA99410F6
File Size: 1.84 MB, 1841664 bytes
MD5: e6a94a064ba8d985720684b24383678e
SHA1: 7a0b95da48f329483fc28331b608cfd2d3e46b8d
SHA256: E4BB04BF7560B09FCF8043C087ED95F6A464F8E9697F7B9017A739B197ED4EDB
File Size: 304.13 KB, 304128 bytes
MD5: 919371ce5dcf9a7fe3d9cf7d1eabdd12
SHA1: 3cc0ef68bb7bbee258bfc1537b3b089132a5cb0c
SHA256: 0484BAF83DF42312F65079D7425BB8E9942C7D0D3AC50D0EB13DDAE56CAFE4BE
File Size: 383.49 KB, 383488 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name UG North
File Description
  • DriverInterface
  • Kernel Driver Utility
File Version
  • 1.4.5.2512
  • 1.00
  • 1.0.0.0
Internal Name
  • DriverInterface.dll
  • Hamakaze.exe
  • TJprojMain
Legal Copyright
  • Copyright © 2020 - 2025 KDU Project
  • Copyright © 2023
Original Filename
  • DriverInterface.dll
  • Hamakaze.exe
  • TJprojMain.exe
Product Name
  • DriverInterface
  • KDU
  • Project1
Product Version
  • 1.4.5.2512
  • 1.00
  • 1.0.0.0

File Traits

  • fptable
  • HighEntropy
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 915
Potentially Malicious Blocks: 108
Whitelisted Blocks: 611
Unknown Blocks: 196

Visual Map

? ? ? 0 x 0 0 0 ? ? ? x x ? ? ? ? x 0 x ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? x x ? 0 x x x ? x x ? x x 0 0 0 0 ? ? x x ? ? ? ? ? x ? ? ? ? ? ? x x ? x x 0 0 0 0 ? ? x 0 0 ? 0 x ? ? x x ? x 0 0 x ? ? 0 0 ? 0 ? ? x x 0 ? x x 0 ? 0 ? ? ? ? x ? x 0 ? ? x x 0 ? ? 0 0 0 ? ? x ? x x 0 0 0 0 ? ? x 0 ? ? ? x x x ? x x x 0 ? ? 0 0 0 ? ? 0 0 ? 0 ? ? x x 0 ? ? ? x x x ? ? 0 0 ? ? ? ? ? 0 0 ? ? x x x x x x x x x ? 0 0 0 0 0 ? ? x ? x x x x x x ? ? x ? x x x 0 0 0 0 x 0 ? ? x x x x x x ? x 0 ? ? 0 ? ? ? ? 0 ? ? x x x x 0 0 ? 0 ? ? ? x x 0 ? ? ? ? x x ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? x 1 x ? x ? 0 x 0 ? ? x x x x 0 0 ? ? ? ? ? x x ? x ? x x ? ? x 1 ? ? ? x ? ? ? ? ? x x ? ? ? ? ? ? ? x x x ? ? ? ? ? ? ? ? ? ? ? 0 ? x ? 1 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 霤ꔼ⛯ǜ RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
Show More
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemEnvironmentValueEx
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall

10 additional items are not displayed above.

Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c cls

Related Posts

Trending

Most Viewed

Loading...