PUP.Onestats

The detection of PUP.Onestats on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent future infections.

What Is PUP.Onestats?

PUP.Onestats is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as malicious as other types of malware, such as viruses or Trojans, it can still cause problems for your computer and compromise your personal data. PUPs are often installed unintentionally by users, usually as a result of downloading and installing freeware or shareware programs that bundle additional software.

How PUP.Onestats Operates

PUP.Onestats operates by installing itself on your computer and then proceeding to collect data about your browsing habits, search history, and other online activities. This data can be used for a variety of purposes, including targeted advertising and marketing. In some cases, PUPs can also be used to install additional malware or unwanted programs on your computer, which can further compromise your security and performance.

PUPs like PUP.Onestats can be particularly problematic because they often use deceptive tactics to install themselves on your computer. They may pretend to be legitimate programs or claim to offer useful functions, but in reality, they are designed to benefit the creators at the expense of the user.

Symptoms of Infection

If your computer is infected with PUP.Onestats, you may notice a range of symptoms, including slow performance, unwanted pop-ups and advertisements, and changes to your browser settings. You may also notice that your computer is taking longer to start up or shut down, or that certain programs are not functioning properly. In some cases, you may not notice any symptoms at all, which is why it's essential to regularly scan your computer for malware and other threats.

  • Unwanted pop-ups and advertisements
  • Changes to browser settings, such as a new homepage or default search engine
  • Slow performance or freezing
  • Unexplained changes to system settings or files

How to Remove PUP.Onestats

  1. Boot your computer in Safe Mode with Networking to prevent PUP.Onestats from loading and to give you more control over the removal process
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your computer and detect any malware or other threats
  3. Uninstall any suspicious programs or applications that may be related to PUP.Onestats
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge
  5. Reboot your computer and perform another scan to ensure that the threat has been fully removed

Conclusion

Removing PUP.Onestats from your computer is an essential step in protecting your security and performance. By following the steps outlined above, you can help to ensure that your computer is free from this and other malware threats. It's also important to take steps to prevent future infections, such as being cautious when downloading and installing software, avoiding suspicious links and emails, and regularly scanning your computer for malware. By taking these precautions, you can help to keep your computer safe and secure.

Analysis Report

General information

Family Name: PUP.Onestats
Signature status: Self Signed

Known Samples

MD5: 7c832ed4600d59e873eb4c3238713b79
SHA1: 15e89df5bbce707c6a17bc9354cebc713fd34eb6
SHA256: 79E93426045FA17D24282986722CD3086A5237AD06B42916BC55A041E29E3913
File Size: 3.10 MB, 3102120 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.1.0.0
File Description GTALauncher
File Version 1.1.0.0
Internal Name ZoneLauncher.exe
Legal Copyright Copyright © 2020
Original Filename ZoneLauncher.exe
Product Name GTALauncher
Product Version 1.1.0.0

Digital Signatures

Signer Root Status
Leonid Kokarev Sectigo RSA Code Signing CA Self Signed
Leonid Kokarev USERTrust RSA Certification Authority Root Not Trusted

Block Information

Total Blocks: 28
Potentially Malicious Blocks: 0
Whitelisted Blocks: 24
Unknown Blocks: 4

Visual Map

0 ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.DRJ
  • MSIL.Krypt.CCO
  • MSIL.Mamut.DE
  • MSIL.Mamut.DG

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\07cef2f654e3ed6050ffc9b6eb844250_e6095cd2aecc9011bcd0d7b421356b17 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\d7833c286363ad25c70511661a83d581_19da2fb9101e161e04a9ae0e16e29c76 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\07cef2f654e3ed6050ffc9b6eb844250_e6095cd2aecc9011bcd0d7b421356b17 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\d7833c286363ad25c70511661a83d581_19da2fb9101e161e04a9ae0e16e29c76 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k=8�jg �v ��T�����Bx#��$kF&� &�-(�(X�)�`*J-!R1�1HO@V�G�IH�pb"hc�zh�ri��j�bk`k�ql(�q�XrnJtǤu�~vy��P��/�����b:����6�X�����.�a ���j�� [�m�Ù��]��gi���=��$�a��8���Κ RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 隞̃耀꧌Şż RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcDisconnectPort
  • ntdll.dll!NtAlpcQueryInformation
Show More
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx

9 additional items are not displayed above.

User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 1852

Related Posts

Trending

Most Viewed

Loading...