Threat Database Hacktool PUP.Keygen.I

PUP.Keygen.I

The detection of PUP.Keygen.I on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent future infections.

What Is PUP.Keygen.I?

PUP.Keygen.I is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that is not necessarily malicious but can still cause problems for users, such as displaying unwanted advertisements, collecting personal data, or installing additional unwanted programs. The "Keygen" part of the name suggests that this PUP may be related to key generators, which are often used to crack or pirate software.

How PUP.Keygen.I Operates

PUPs like PUP.Keygen.I typically operate by exploiting vulnerabilities in software or by tricking users into installing them. They may be bundled with other programs, or they may be downloaded from untrusted sources. Once installed, PUP.Keygen.I can start to exhibit unwanted behavior, such as displaying pop-up ads, altering browser settings, or installing additional software. In some cases, PUPs can also collect personal data, such as browsing history or login credentials, and transmit it to third-party servers.

Symptoms of Infection

If your system is infected with PUP.Keygen.I, you may notice a range of symptoms, including unwanted advertisements, slow system performance, and unexpected changes to your browser settings. You may also notice that your browser is redirecting you to unfamiliar websites, or that new toolbars or extensions have been installed without your consent. In some cases, you may also experience system crashes or freezes, or receive alerts from your antivirus software indicating that a threat has been detected.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Changes to browser settings or homepage
  • New toolbars or extensions installed without consent
  • System crashes or freezes
  • Antivirus alerts indicating a detected threat

How to Remove PUP.Keygen.I

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or software that may be related to the PUP.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any unwanted changes or extensions.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the PUP has been completely removed.

Conclusion

Removing PUP.Keygen.I from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above, you can help to ensure that your system is clean and free from this potentially unwanted program. It is also essential to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using reputable antivirus software, and being cautious when downloading software or clicking on links from untrusted sources.

Analysis Report

General information

Family Name: PUP.Keygen.I
Signature status: No Signature

Known Samples

MD5: 953a619c1821e8901b21d4ef05f0ad45
SHA1: 97b9b939386833589d6f4ac517c9b7a2b4cc4b12
File Size: 58.37 KB, 58368 bytes
MD5: 37e8f8a772a0acc1a9ca2f575e457286
SHA1: 5f76950f4f06f83a4c197536fbaf372db63142fd
SHA256: 25255EE36CEEE5F40417283141EF3A02944563C59AB55A1915CED41382F9D10A
File Size: 268.26 KB, 268262 bytes
MD5: 402fe46fad9c99d767502ec512893684
SHA1: a78e8824b79167861467505a2301f15b0cb1bb16
SHA256: D127C7A4B0F4C33348F34133B392837FE4965650AA02D316F718209D5DACD1CD
File Size: 83.46 KB, 83456 bytes
MD5: 32881944ed2ab940c14bb77c2772139f
SHA1: 7816fcf9bac6ce8679b27367d2b0d1dfcb98e134
SHA256: 087BB9340D1E04AA6607629EE9EB23CD25D1CE02BFC9166CD4B0233F03EC753F
File Size: 57.60 KB, 57603 bytes
MD5: efe26fdf99c06d390d7ed57393da7206
SHA1: 2f196bac1ccd11cb1ad97860c113315eb5c96066
SHA256: 0A9F3052AD454FA3FE7C573A64E3DC7EEBE0D4C0FF65423A790E5AE02F007903
File Size: 76.29 KB, 76288 bytes
Show More
MD5: b4eb925499780b0ad07cae139bf0967b
SHA1: 5a0de23aea8d1c789509a99961162c734abb62cd
SHA256: 98F374FE2B72491FC6CA60EA22C60C096376AC5F8047B37887D369885EA57076
File Size: 97.79 KB, 97792 bytes
MD5: 387432105435dfa91ddf431a21013a45
SHA1: 37c9bb6043d6fedab6ae0134804625bb5d34d073
SHA256: 750C9171DF3C0F53262917361E8D6D968947AFE817823E4E647B18FA40604AA0
File Size: 417.95 KB, 417946 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Elcor Software
  • Microsoft
File Description Registry Backup for Windows 7-Vista-XP
File Version
  • 9.3.6.1
  • 1.00
Internal Name
  • RegBackup
  • Win
Legal Copyright Copyright © Elcor Software 2001-2010
Legal Trademarks Registry Backup is a registered trademark of Elcor Software
Original Filename
  • RegBackup.exe
  • Win.exe
Product Name
  • Registry Backup for Windows 7-Vista-XP
  • Win
Product Version
  • 9.3.6.1
  • 1.00

File Traits

  • .UPX
  • 00 section
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • upx
  • UPX!
  • x86

Block Information

Total Blocks: 1,081
Potentially Malicious Blocks: 17
Whitelisted Blocks: 617
Unknown Blocks: 447

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? 0 ? 0 0 0 0 0 ? ? x ? x 0 0 0 0 0 0 0 x ? 0 0 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x x 0 0 x 0 ? x x x 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? 0 0 0 ? 0 0 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? 0 0 ? 0 ? 0 0 0 ? ? 0 ? ? ? ? 0 x ? ? ? 0 0 0 0 0 ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 ? ? 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? 0 ? 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 ? ? ? ? x 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? x ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 0 ? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx
Keyboard Access
  • GetAsyncKeyState
  • GetKeyState