PUP.FastViewer

The detection of PUP.FastViewer on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent future infections.

What Is PUP.FastViewer?

PUP.FastViewer is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in the classical sense but can still cause significant disruptions to your system and potentially expose you to more severe security risks. PUPs often find their way onto computers through bundled software installations, where they are included alongside legitimate programs without the user's full knowledge or consent.

How PUP.FastViewer Operates

PUPs like PUP.FastViewer typically operate by installing themselves on a computer and then proceeding to perform a variety of unwanted actions. These can include displaying unwanted advertisements, collecting user data without consent, altering browser settings, and slowing down the system by consuming resources. In some cases, PUPs can also serve as vectors for more malicious software, making them a significant security concern.

Symptoms of Infection

The symptoms of a PUP.FastViewer infection can vary but often include an increase in unwanted pop-ups or advertisements, changes to your web browser's homepage or search engine, and a general slowdown in computer performance. You might also notice that your browser is redirecting you to unexpected websites or that there are unfamiliar programs installed on your computer. Recognizing these symptoms is crucial for taking prompt action against the infection.

How to Remove PUP.FastViewer

  1. Restart your computer in Safe Mode with Networking. This will help prevent PUP.FastViewer from interfering with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This tool can help identify and remove the PUP and any associated malware.
  3. Manually uninstall any suspicious programs that you do not recognize or need. Be cautious during this process, as some legitimate programs might be mistakenly removed.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any unwanted changes made by the PUP, such as altered homepages or search engines.
  5. After completing the above steps, reboot your computer and perform another scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing PUP.FastViewer from your system is crucial to restoring your computer's security and performance. By following the steps outlined above and maintaining vigilance in your online activities, you can help protect your system from similar threats in the future. Regularly updating your operating system, browsers, and security software, as well as being cautious with downloads and email attachments, are key practices in preventing PUP infections. Remember, a proactive approach to computer security is your best defense against potentially unwanted programs and more severe malware threats.

Analysis Report

General information

Family Name: PUP.FastViewer
Packers: PECompact v2.20
Signature status: Root Not Trusted

Known Samples

MD5: b20319625434effad0caab530263b07a
SHA1: a98ee925974d75b12284751a195a7fa2bab7b744
SHA256: 3B91ABF275A2E46E26F79BBFC385D126AC8E99CFABD350CA9B1AADFDC4262580
File Size: 645.58 KB, 645584 bytes
MD5: b0bbb36530338386c1ab6a0d4c014144
SHA1: 4059108c27d1ad9108edde92536e995263c88a19
SHA256: 4381BD5F4527FE779272D53AD7096989BFD3E1ED6331CF3151C155298C4D2F10
File Size: 1.58 MB, 1579064 bytes
MD5: 1a148bd3387f974d463654438bbf13d0
SHA1: 2e319279dfa30fae75ac2c73ca12c6d8ec381fd7
SHA256: AAAB6DFB28E091100543C84741C53D9E38CBEA8CB7C79254AC81240DE8B701C2
File Size: 512.48 KB, 512480 bytes
MD5: 438fe44c1da47d7923f207cb3f3ca428
SHA1: 08e5e92982af2bcf4615ddb7c9b8236e8787eb19
SHA256: 24FB274F23E295D4EAB9EE5BF53DB13EC22F3FB3C38E649798AFF42DFEE777F7
File Size: 1.12 MB, 1117968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has been packed
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Fastviewer.com
File Description
  • fastviewer
  • FastViewer
File Version
  • 3.20.0003
  • 3.00.0022
  • 02.60.0000
Internal Name
  • fastviewer
  • FastViewer.exe
Legal Copyright
  • (c) FastViewer GmbH. All rights reserved.
  • Copyright © 2006-2008 FastViewer.com
Original Filename
  • fastviewer.EXE
  • FastViewer.exe
Product Name FastViewer
Product Version
  • 3.20.0003
  • 3.00.0022
  • 02.60.0000

Digital Signatures

Signer Root Status
FastViewer GmbH und Co KG Thawte Premium Server CA Root Not Trusted

Block Information

Total Blocks: 10,306
Potentially Malicious Blocks: 36
Whitelisted Blocks: 3,801
Unknown Blocks: 6,469

Visual Map

? ? 0 ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 0 ? 0 ? 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 0 0 ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? ? 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 ? ? 0 ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 x ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? 0 ? ? ? 0 ? 0 ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 ? 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 0 0 ? 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? 0 0 0 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? x ? ? 0 ? ? ? ? x ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 緁聙偯ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ȑ胀偯ǜ RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetAsyncKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Terminate
  • TerminateProcess

Shell Command Execution

open C:\WINDOWS\system32\cmd.exe /c del "C:\Users\Ecggpgmz\\fvw.2009-??-??T??-??-??.stream.bin"
open C:\WINDOWS\system32\cmd.exe /c del "C:\Users\Ecggpgmz\\fvw.2009-??-??T??-??-??.report.txt"
WriteConsole: Could Not Find C

Related Posts

Trending

Most Viewed

Loading...