PUP.WinTweak
The detection of PUP.WinTweak on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it to prevent further damage.
Table of Contents
What Is PUP.WinTweak?
PUP.WinTweak is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as malicious as other types of malware, such as viruses or Trojans, it can still cause problems with your system and compromise your privacy. PUPs are often installed unintentionally by users, usually as a result of downloading and installing free software or clicking on suspicious links.
How PUP.WinTweak Operates
PUP.WinTweak operates by installing itself on your system and then proceeding to carry out various unwanted activities. These can include displaying unwanted advertisements, collecting your personal data, and modifying your system settings without your consent. In some cases, PUPs can also install additional malware or create backdoors for other malicious programs to enter your system.
PUPs like PUP.WinTweak can be particularly difficult to detect and remove because they often disguise themselves as legitimate programs or system files. They may also use various tactics to evade detection by security software, such as encrypting their files or using code obfuscation techniques.
Symptoms of Infection
If your system is infected with PUP.WinTweak, you may notice various symptoms, including slower system performance, unwanted pop-ups and advertisements, and changes to your system settings. You may also notice that your browser homepage or search engine has been changed without your consent, or that new toolbars or extensions have been installed.
- Unwanted advertisements and pop-ups
- Changes to system settings and browser configurations
- Slow system performance and crashes
- Unexplained changes to your browser homepage or search engine
How to Remove PUP.WinTweak
- Boot your system in Safe Mode with Networking to prevent PUP.WinTweak from loading and to allow you to download and install removal tools.
- Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove PUP.WinTweak and any other malware that may be present.
- Uninstall any suspicious programs or applications that you do not recognize or that were installed without your consent.
- Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any changes made by PUP.WinTweak.
- Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that PUP.WinTweak has been completely removed.
Conclusion
Removing PUP.WinTweak from your system requires careful attention to detail and a thorough understanding of the threat. By following the steps outlined above, you can help to ensure that your system is completely clean and free of malware. It is also essential to take preventative measures to avoid future infections, such as being cautious when downloading and installing software, avoiding suspicious links and emails, and keeping your operating system and security software up to date.
Analysis Report
General information
| Family Name: | PUP.WinTweak |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
8a508b7d83dd832d517d5a1b7380bc04
SHA1:
b8262287be1c5d1a2e84216941f7078558f6da71
SHA256:
E4A3FE530F1F1E1B5B33E652F0AC8461E7CD27DBC8BE1E72C630448914627EA0
File Size:
1.87 MB, 1865728 bytes
|
|
MD5:
431e2c04d72c4875ea262000604cf9c1
SHA1:
9646569b176ddc1ee34321c01126833c9cc33f03
SHA256:
1A1BE3936A4AA9C1F7D6F72A8F86281DDD5F2365474D3832B5E76877040C7999
File Size:
1.85 MB, 1851392 bytes
|
|
MD5:
39933d0971ce36c5e6cc5a53f4bd12ff
SHA1:
39b3cdf01d3e025f96d4c93e4ba3ba0fc3455070
SHA256:
AC933A2A22B2F508A47E282E164DD34155814A7FCB70123022CA60A5B6A4A5A4
File Size:
555.31 KB, 555308 bytes
|
|
MD5:
111e0185ac9a8dca1d6a917d2e3cf596
SHA1:
a3e68ebb8127fc5a3197841e8fffaa27c92ba50c
SHA256:
02167772B58E9EF15CDE7BFEE0595F054ACDED37318CAD79BAD0952302FA717C
File Size:
82.51 KB, 82506 bytes
|
|
MD5:
cabae35fe4c7cdc79f779076d960cf9c
SHA1:
c0dc3650d91d9a7da5560b3d6406e46a42ce08f9
SHA256:
EBC9A10E8F121999B395C9495112C50528736B24897569DECE337C88F37354FF
File Size:
1.41 MB, 1411143 bytes
|
Show More
|
MD5:
0baf1ee5ef6b430ffd8fdadcbd6ddd6c
SHA1:
1e5b577a1d62f5a0ed1a29732a1e10041cb6cb91
SHA256:
B732E09BD5F1BADD0F23E69F860DEAF3D65F7C43E3D9449C707CFD82C897493F
File Size:
3.17 MB, 3166592 bytes
|
|
MD5:
8160adba015afa1eef0082049442c162
SHA1:
db1f8c10f748625f90eb8b037dcab3d0792eb0a4
SHA256:
ABA31DC7547E505703A4046EFB3C38B783681BD37FBEA3888C7DA04A5CD2EC8B
File Size:
1.31 MB, 1312768 bytes
|
|
MD5:
8ce63ffe901236d744768a4aeb528a0e
SHA1:
1197099dd7b1a0c9ba1b6bbdec8a316b4c648fa7
SHA256:
578552D45F2A1442F0F4707B89082F656B5D222DF99D4616C27DDD1DEA77454B
File Size:
1.85 MB, 1851392 bytes
|
|
MD5:
86ba171fb0cada8f04b211c303c556ea
SHA1:
75308e14e2ca2389f3b3cb4d5de4979e68f00dd3
SHA256:
4FDAAB5B50009289EAB455F24EC1195B685EA06ED5EB3AF4820FC6ACD0614679
File Size:
3.17 MB, 3166592 bytes
|
|
MD5:
7a1f1a3cd4479a15a4f5e042965cfe15
SHA1:
76b14cea09bee9d7008d716b820e754a9eed3073
SHA256:
91FCD04E2F17FACFBF5E5EF930CFB6F7DD0421D464B856A8D51551715E3EDC91
File Size:
1.27 MB, 1272320 bytes
|
|
MD5:
79c64599b7a67cbae56754bf06924fa6
SHA1:
561996069813eae5cef726bb78b2f3978e3502f8
SHA256:
9304E624B7E2303F10F05DE1BE047B79FE02B0DC03D748EFEB6984262F7FD2C2
File Size:
854.93 KB, 854935 bytes
|
|
MD5:
1318b3c8a454ed0dbb168c523d0143d3
SHA1:
30dc4aaa0972ee74822c27f56b3e927c34551978
SHA256:
8FF2F73681914603FF02C7EAB4670D583CD22F8AACE9455A09CA1FC646BB4EA5
File Size:
1.28 MB, 1275904 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has been packed
- File has exports table
- File has TLS information
- File is 32-bit executable
- File is 64-bit executable
Show More
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Legal Trade Marks | AdobeGenP |
| Legal Trademarks | Acronis |
| Original Filename |
|
| Product Name |
|
| Product Version |
|
| Program I D | com.embarcadero.ISORUN |
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| Eagle123 Soft | Eagle123 Soft | Hash Mismatch |
File Traits
- Installer Manifest
- nosig nsis
- Nullsoft Installer
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 4,495 |
|---|---|
| Potentially Malicious Blocks: | 0 |
| Whitelisted Blocks: | 4,495 |
| Unknown Blocks: | 0 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.LA
- Agent.LKC
- Chapak.HBX
- CobaltStrike.GI
- CobaltStrike.GIA
Show More
- Injector.AK
- Kryptik.DEK
- Lokorrito.C
- MSILZilla.TC
- Rozena.XC
- Sheloader.A
- Sheloader.C
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\temp\2k10\adrivers | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\e64 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\e64\snapman.sys | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\e64\snapman.sys | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\e64\zdrvinst.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\e64\zdrvinst.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\e86 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\e86\snapman.sys | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\e86\snapman.sys | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\fltsrv.sys | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\2k10\adrivers\fltsrv.sys | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\snapman.sys | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\snapman.sys | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\snapman.wcs | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\snapman.wcs | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\volume_tracker.sys | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\volume_tracker.sys | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\x64 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\x64\fltsrv.sys | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\x64\fltsrv.sys | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\x64\snapman.sys | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\x64\snapman.sys | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\x64\volume_tracker.sys | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\x64\volume_tracker.sys | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\x64\zdrvinst.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\x64\zdrvinst.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\zdrvinst.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\2k10\adrivers\zdrvinst.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\aut404c.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\aut43a6.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\autb74f.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsx6e5.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\rarsfx0 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\__tmp_rar_sfx_access_check_4472937 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\adobegenp.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\adobegenp.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\config.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\config.ini | Generic Write,Read Attributes |
| c:\users\user\downloads\config.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\config.ini | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Anti Debug |
|
| User Data Access |
|
| Other Suspicious |
|
| Keyboard Access |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
(NULL) C:\Users\Jejvyfar\AppData\Local\Temp\RarSFX0\AdobeGenP.exe
|