PUP.WireVPN.A

The detection of PUP.WireVPN.A on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. PUPs are software applications that, while not necessarily malicious, can still pose risks to your system and personal data. In this report, we will provide you with information on what PUP.WireVPN.A is, how it operates, its symptoms, and most importantly, how to remove it from your system.

What Is PUP.WireVPN.A?

PUP.WireVPN.A is classified as a potentially unwanted program, which means it is not considered malware in the traditional sense but can still cause problems for your computer. PUPs often find their way onto systems through bundled software downloads, where they are included alongside legitimate programs without the user's full knowledge or consent. These programs can range from adware that displays unwanted advertisements to more invasive applications that can compromise your system's security.

How PUP.WireVPN.A Operates

PUPs like PUP.WireVPN.A typically operate by integrating themselves into your system in a way that makes them difficult to detect and remove. They might alter system settings, install additional software, or even collect user data without explicit permission. The primary goal of many PUPs is to generate revenue for their creators, often through advertising or by selling collected data. However, their presence can also lead to system instability, slow performance, and increased vulnerability to other, more dangerous malware.

Symptoms of Infection

Symptoms of a PUP.WireVPN.A infection can vary but often include an increase in unwanted advertisements, pop-ups, or redirects to suspicious websites. You might also notice that your browser's homepage or default search engine has been changed without your consent. Furthermore, your system might become slower, or you might experience frequent crashes or freezes. In some cases, you might not notice any symptoms at all, which is why regular system scans are crucial for detecting and removing PUPs.

How to Remove PUP.WireVPN.A

  1. Enter Safe Mode with Networking to prevent PUP.WireVPN.A from interfering with the removal process. This mode allows you to use the internet to download removal tools while limiting the functionality of malicious programs.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. These tools are designed to detect and remove PUPs and other types of malware, including those that might be associated with PUP.WireVPN.A.
  3. Uninstall suspicious programs that you do not recognize or no longer need. Be cautious during this process, as some legitimate programs might be mistakenly removed. Always check the program's name and publisher to ensure you are uninstalling the correct application.
  4. Reset your browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, etc.) to their default settings. This action will remove any changes made by PUP.WireVPN.A, such as altered homepages or search engines, and will also delete temporary data that might be used to track your browsing habits.
  5. After completing the above steps, reboot your system and perform another scan to ensure that PUP.WireVPN.A has been completely removed. This final scan is crucial for verifying the effectiveness of the removal process.

Conclusion

Removing PUP.WireVPN.A from your system is a process that requires attention to detail and the use of proper removal tools. By following the steps outlined in this report, you should be able to eliminate this potentially unwanted program and restore your system to a secure and stable state. Remember, prevention is key; always be cautious when downloading software, and regularly scan your system for any signs of PUPs or other malware to protect your data and maintain your system's performance.

Analysis Report

General information

Family Name: PUP.WireVPN.A
Signature status: No Signature

Known Samples

MD5: 108a061fa51be3e29de78529212f3986
SHA1: a879aa286d83fc39666760d8a0614791d5efe419
SHA256: 90AC4B522BCE556890668C6501662C4A3620693400BECCF9FBCE3098855750C6
File Size: 2.57 MB, 2569216 bytes
MD5: b9be46af4d2ff8fa8b803d48f5cb563a
SHA1: fc036cd22c7c478c8a3b2a5146a0b77681546f7f
SHA256: 71E96AF1A6891C2874D943A1A8B0A941C37C5F214D7AC35ECF1FEA1170020FA2
File Size: 2.98 MB, 2976768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • HealthService
  • upWire
Legal Copyright
  • HealthService
  • upWire
Product Name
  • HealthService
  • upWire
Product Version
  • 3.6.0.3
  • 1.0.0.4

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 4,370
Potentially Malicious Blocks: 295
Whitelisted Blocks: 4,075
Unknown Blocks: 0

Visual Map

0 0 0 0 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x x x x 0 x x 0 x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 x x x x x x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 x x x 0 x 0 0 x x x x x x x x x x x x x 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 x x 0 0 x x 0 0 x 0 x x 0 x 0 0 x x 0 0 x 0 x x x x x x x x 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 x 0 x x x 0 x 0 x x 0 x x x x 0 x x x x 0 x 0 x x 0 x x x x x x x x 0 x x x x x x 0 0 0 x x x 0 0 x x x 0 0 x x x x x x x x x x 0 x 0 x 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 0 x 0 x x x x x 0 0 x x x 0 x 0 0 x 0 x x 0 x 0 0 x x 0 x x x x x x x 0 x x x x 0 x 0 0 x 0 x x 0 x 0 x 0 x 0 0 x x 0 x x 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 x x x x x 0 0 0 0 0 0 x 0 0 x 0 x x 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • WireVPN.A

Files Modified

File Attributes
c:\users\user\downloads\log\a879aa286d83fc39666760d8a0614791d5efe419_000256921620260619-232736.6448.log Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSAStartup
Service Control
  • OpenSCManager
  • OpenService
  • StartServiceCtrlDispatcher
User Data Access
  • GetComputerName
  • GetUserObjectInformation
Anti Debug
  • NtQuerySystemInformation
  • OutputDebugString
Encryption Used
  • BCryptOpenAlgorithmProvider
Network Winsock
  • accept
  • bind
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • getpeername
  • getsockname
  • recv
  • send
Show More
  • setsockopt
  • socket

Shell Command Execution

C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall delete rule name="HealthService"
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall delete rule name="HealthService"
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall add rule name="HealthService" dir=out action=allow program="C:\Windows\SysWOW64\health\HealthService.exe"
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall add rule name="HealthService" dir=out action=allow program="C:\Windows\SysWOW64\health\HealthService.exe"
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall add rule name="HealthService" dir=in action=allow program="C:\Windows\SysWOW64\health\HealthService.exe"
Show More
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall add rule name="HealthService" dir=in action=allow program="C:\Windows\SysWOW64\health\HealthService.exe"
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall delete rule name="HealthSvc"
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall delete rule name="HealthSvc"
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall add rule name="HealthSvc" dir=out action=allow program="C:\Windows\SysWOW64\health\HealthSvc.exe"
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall add rule name="HealthSvc" dir=out action=allow program="C:\Windows\SysWOW64\health\HealthSvc.exe"
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall add rule name="HealthSvc" dir=in action=allow program="C:\Windows\SysWOW64\health\HealthSvc.exe"
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall add rule name="HealthSvc" dir=in action=allow program="C:\Windows\SysWOW64\health\HealthSvc.exe"

Related Posts

Trending

Most Viewed

Loading...