PUP.KeyViewer
The detection of PUP.KeyViewer on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. PUPs are software applications that, while not necessarily malicious, can still cause significant disruptions and pose risks to your personal data and system integrity. Understanding what PUP.KeyViewer is, how it operates, and the symptoms it causes is crucial for effective removal and prevention of future infections.
Table of Contents
What Is PUP.KeyViewer?
PUP.KeyViewer is categorized as a potentially unwanted program, which means it is not classified as malware in the traditional sense but can still exhibit undesirable behavior. PUPs often find their way onto systems through bundled software downloads, where they are included alongside legitimate applications without the user's full knowledge or consent. Once installed, PUP.KeyViewer may perform a variety of actions that are not in the best interest of the user, such as displaying unwanted advertisements, collecting user data, or modifying system settings.
How PUP.KeyViewer Operates
The operation of PUP.KeyViewer typically involves integrating itself into the system in a way that makes it difficult to detect and remove. It may install additional components or modify system files to ensure its persistence. PUPs like PUP.KeyViewer often have the capability to communicate with remote servers, from which they can receive updates, send collected data, or download additional unwanted software. This communication can lead to further system compromises and increased risk of malware infections.
Symptoms of Infection
Systems infected with PUP.KeyViewer may exhibit a range of symptoms, including but not limited to, an increase in unwanted pop-ups or advertisements, unexpected changes in browser settings or homepage, slowdowns in system performance, and the presence of unfamiliar programs or toolbars. Users may also notice that their browsing data is being collected or that they are being redirected to unwanted websites. These symptoms can significantly disrupt the user experience and pose security risks.
How to Remove PUP.KeyViewer
- Boot your computer in Safe Mode with Networking to prevent PUP.KeyViewer from loading and to give you internet access for downloading removal tools.
- Download and install a reputable anti-malware tool, such as SpyHunter, which is capable of detecting and removing PUPs and other types of malware. Perform a full scan of your system to identify all components of PUP.KeyViewer.
- Uninstall any suspicious programs that were installed around the time you noticed the infection. Be cautious and only uninstall programs that you are certain are not needed.
- Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any changes made by PUP.KeyViewer, such as altered homepages or search engines.
- Reboot your computer and perform another scan with your anti-malware tool to ensure that all components of PUP.KeyViewer have been removed. This step is crucial for verifying the effectiveness of the removal process.
Conclusion
Removing PUP.KeyViewer from your system requires a thorough approach to ensure all its components are eliminated. By following the steps outlined above and maintaining good computing practices, such as regularly updating your operating system and applications, using strong antivirus software, and being cautious with downloads and email attachments, you can protect your system from PUPs and other types of malware. Remember, prevention is key, and staying informed about the latest threats and best practices for computer security is essential for safeguarding your digital life.
Analysis Report
General information
| Family Name: | PUP.KeyViewer |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
dde142fbeb37c54679a0ea122a2011e4
SHA1:
b7f8dfe6caa5d7f2e364cc66ad109a8c514e9c59
File Size:
51.16 KB, 51164 bytes
|
|
MD5:
5dacea3525718bbc1159b40b06831a13
SHA1:
0f01da459f776de9b9ac8e3acf6af335946d72a3
SHA256:
8B3AAFD9196A074EEE355D394BFFC84033762D5402F7048E49FA6B17CFC61F60
File Size:
26.11 KB, 26112 bytes
|
|
MD5:
bdb00015b4bc13da57874cd499afff51
SHA1:
3054892b7d5d652a24b3818cfe90e07f96022368
SHA256:
914121E504FE31A8C19D925B570BA832AB3C429B120ECDFB9F0245E58AAE1A21
File Size:
51.16 KB, 51164 bytes
|
|
MD5:
48ec9aecff5ab939ea57ae69f264ad2f
SHA1:
4962bd97bb420df17a99c2ed62087739472873df
SHA256:
C0FC2F52126BE2CC24E1C8556C835A8D538E5B1BC8D3806395801AED3A7BA7AE
File Size:
50.85 KB, 50848 bytes
|
|
MD5:
7f597fd0a7bf2e961be2705986698a32
SHA1:
7af9b7786337d34598fdb7912362e5c3d40cd5d8
SHA256:
280E8D82B7E4A7ED044968604756DDB939B81832A6FA176277844437133F90C8
File Size:
50.85 KB, 50848 bytes
|
Show More
|
MD5:
344709a2f2fd788236f1f5ffa997cd46
SHA1:
8cbbbf4973f7b7e22620148d898c060280512080
SHA256:
59E23515978DD7DF6FFA6175F2D37251E44EA671FE7FC431540F30DD9450DDCF
File Size:
48.85 KB, 48848 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- Installer Manifest
- nosig nsis
- No Version Info
- Nullsoft Installer
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 75 |
|---|---|
| Potentially Malicious Blocks: | 0 |
| Whitelisted Blocks: | 75 |
| Unknown Blocks: | 0 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.MH
- Agent.MI
- Agent.MU
- Autorun.LA
- Chapak.HBBB
Show More
- FakeAV.AU
- Makoob.A
- Parite.F
- Trojan.Downloader.Gen.BQ
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\temp\nsb256e.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsb256e.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsb256e.tmp\system.dll | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsgf481.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsgf481.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsgf481.tmp\system.dll | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsl255d.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsp2d4d.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsp2d4d.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp2d4d.tmp\system.dll | Synchronize,Write Attributes |
Show More
| c:\users\user\appdata\local\temp\nsp5769.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsp5769.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp5769.tmp\system.dll | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsqf470.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsze9d4.tmp | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\nsze9d4.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsze9d4.tmp\system.dll | Synchronize,Write Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\wow6432node\microsoft\windows nt\currentversion\softwareprotectionplatform\activation::manual | RegNtPreCreateKey | |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Users\Dynbcegf\AppData\Local\Temp\nsp5769.tmp\ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | S� ? xy # kP~ �ރ # ��� ��^ # ۴� c }� � Vs} � kP~ 0 �)� � ��1 �� d ��� d # BF F e < ��1 � �� h �n� } # e�� # e�� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �N � r�i ��*� ���8\x��B +� �� �6 �} ���� 7� xy �� �� ۀ>�=���� � B� O�� ���x �%�� �8�5�� ��Bx �� � ���\ �!IN� sb � !>!wz #@�#��#�O$kF$�� $¨%:� %f�%� | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52 *1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62 *1\??\C:\P | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 闩 ȁ 獖} | RegNtPreCreateKey |
Show More
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | k - �vT�����(�(X�*J1�1HO @V� A��G�IH[uH�p^��_�zh�rk�qq�Xvy�{b��P� �jI��� ����6����.���j���*�[�m� ƾB�]� �IV ӂa ����$�Ac�8წ���&M�^ ��=�S.SLB1_ T�Vw�`�V��3��%������ �A | RegNtPreCreateKey |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4 *1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352 *1\??\C:\P | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | �� xy * � /�� Y� d� � � �ރ �p ��^ �o � [ Vs} kP~ ��1 1 �� 7 � �� ﺃ e e�� ��1 �� h �n� i e�� r [ � v | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | l � 8�tX�jg�8 �6 �v�Z xy �� T������ ���5����Bx !wz #�#��$kF%:� %`� &� (�(X�)E)�`*J*9+�[,��-!R/9� /��1`1�1HO 1�D5�09ߔ<.:>3� @V� F?G�IH[uH�pH�� I��J�� K��N$R20U_*V � X� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 鳼 ȁ ਪˣ 鈯ˣ 遙̃ 豤̃ অˣ 炑̃ 龡^ 濖̃ 賬̃ 攘ť 獖} 偫~ 엦1 ˣ 邯̃ 뫯ʃe ꙥဈ 엦18 ¶f ꙥi 5 ꙥr / ֢v ꙥ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m _ jg �� �v �� T������%�� Bx �<#��(�(X�(�)�`*J*9*�"-!R1�1HO 5,]@V� A��G�IH[uH�pN$N� ^��_�zb"hc�w h�rj�bk`k�ql(�lR q�Xr�BsU�vy�w�ny�9 {b�~D�P� �������7�M�b:�� ��� ����6�� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 鴅 ȁ 獖} 偫~ 엦1e ꙥ ¶i ꙥr ֢v ꙥ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m U tX �� �v�ZT�����Bx �<#��&� (�(X�*J*9*�"1`1�1HO =� @V� A��G�IH[uH�pN$N� Z^� ^��_�zb"hc�w j�bk`k�qk�8 l(�lR q�Xr�BtǤw�n{b��P� ����!�����7�� ��3�M�b:�� ��� ������O� ��.� � | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Process Shell Execute |
|
| User Data Access |
|
| Anti Debug |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\Users\Dynbcegf\AppData\Local\Temp\gkey.exe
|
C:\Users\Fbdifovb\AppData\Local\Temp\gkey.exe
|
C:\Users\Ndmqahzf\AppData\Local\Temp\gkey.exe
|
C:\Users\Nzasdrra\AppData\Local\Temp\gkey.exe
|
C:\Users\Nxhvyrvb\AppData\Local\Temp\gkey.exe
|