PUP.Globalhop

The detection of PUP.Globalhop on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to address this detection to prevent potential harm to your system and data.

What Is PUP.Globalhop?

PUP.Globalhop is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems, such as displaying unwanted advertisements, collecting user data, or modifying system settings. The term "PUP" is a broad category that encompasses various types of software, including adware, browser hijackers, and other unwanted programs.

How PUP.Globalhop Operates

PUP.Globalhop, like other PUPs, may operate by installing itself on your system through various means, such as bundled software downloads, infected websites, or exploited vulnerabilities. Once installed, it may start displaying unwanted advertisements, collecting user data, or modifying system settings to suit its purposes. PUPs can also slow down your system, cause crashes, and increase the risk of malware infections.

Symptoms of Infection

Some common symptoms of PUP.Globalhop infection include unwanted advertisements, pop-ups, and browser redirects. You may also notice that your system is running slower than usual, or that your browser settings have been modified without your consent. Additionally, you may see unfamiliar programs or icons on your system, or receive unexpected notifications and alerts. If you notice any of these symptoms, it is essential to take immediate action to remove the PUP from your system.

How to Remove PUP.Globalhop

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a more effective removal process.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of PUP.Globalhop and other potential threats.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or modifications.
  5. Reboot your system and run another full scan with your anti-malware tool to ensure that all remnants of PUP.Globalhop have been removed.

Conclusion

Removing PUP.Globalhop from your system is crucial to prevent potential harm and maintain your system's performance and security. By following the steps outlined above, you can effectively remove the PUP and prevent future infections. It is also essential to practice safe computing habits, such as avoiding suspicious downloads, using reputable anti-malware tools, and keeping your system and software up to date. By taking these precautions, you can protect your system and data from potential threats and maintain a safe and secure computing environment.

Analysis Report

General information

Family Name: PUP.Globalhop
Signature status: Hash Mismatch

Known Samples

MD5: 1e3b76e670627671b2edb10dedabe42a
SHA1: f488db582bc6890c1277e523a725829bc72a0dbb
SHA256: D9AB0C6EC300B57C22252495725BC6EA327D2EBFCF4BD1EF67F5201AEE372068
File Size: 7.56 MB, 7559015 bytes
MD5: 65e3441cb480632812889325a5198d6e
SHA1: 9094f1378a54b54f504262e86db6e9be8a576cb7
SHA256: 53FBDB2A8849168D753B44281931C962A4336EF264B878F10DAA10284ADC3FE5
File Size: 4.16 MB, 4161904 bytes
MD5: bfdb336737fdcb3b2bde7585030b4081
SHA1: daf2de18b8ebef23b9ada3d6e1030eb276f37a67
SHA256: B1EBE87E0A675A985628DFC69D667D9D5EC76727CAA21A7256107F20B53A6168
File Size: 1.24 MB, 1238080 bytes
MD5: 6d7660dd2852b3e6dcd1d34f968b2ae3
SHA1: 89a54959472c4a3ef03d9a55b370f4a3f6665b63
SHA256: A95EFAE7376DD734FA278C566332AC10E18C27E8FF4D255D3DEAB04100D08062
File Size: 7.56 MB, 7558143 bytes
MD5: a74008ee5e44ffed6720ce1b16b88571
SHA1: 8f8930e37a4ea1d8e0672a2f13cd8c007e0a4deb
SHA256: A401CABD159AC8A285B8E9F74C3CB07A55594BFFBF21E208C1D743530E424CF1
File Size: 7.35 MB, 7353727 bytes
Show More
MD5: 8592331f54bedf5c9827925da342f1c4
SHA1: 4e617ff5bed29f76f33dd1f71f1379f3ea9cefcc
SHA256: A01BA04764D8CE04C17E51F4E5367922FB63997969C884FFF3788174BDD7F4A1
File Size: 7.56 MB, 7560063 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File has exports table
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.3.0
Comments
  • Application launcher file
  • This installation was built with Inno Setup.
Company Name
  • Globalhop
  • Walliant
File Description
  • Globalhop library
  • Globalhop sdk
  • Taskbarify launcher
  • Walliant Setup
File Version
  • 2.0.0.0
  • 1.0.7.0
  • 1.0.3.0
Internal Name
  • classic
  • Taskbarify.exe
Legal Copyright
  • Copyright © 2022 Walliant
  • © Globalhop
Original Filename
  • classic.dll
  • Taskbarify.exe
Product Name
  • Taskbarify
  • Taskbarsystems
  • Viewndow
  • Walliant
Product Version
  • 2.0.0.0
  • 1.0.7.0
  • 1.0.3.0

Digital Signatures

Signer Root Status
Globalhop Ltd DigiCert SHA2 Assured ID Code Signing CA Hash Mismatch
Globalhop Ltd DigiCert SHA2 Assured ID Code Signing CA Self Signed
Cleversort FZ-LLC DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Cleversort FZ-LLC DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
Cleversort FZ-LLC DigiCert Trusted Root G4 Root Not Trusted
Show More
Cleversort FZ-LLC DigiCert Trusted Root G4 Hash Mismatch
Cleversort FZ-LLC Sectigo Public Code Signing Root R46 Hash Mismatch
Cleversort FZ-LLC Sectigo Public Code Signing Root R46 Hash Mismatch

Block Information

Total Blocks: 743
Potentially Malicious Blocks: 4
Whitelisted Blocks: 737
Unknown Blocks: 2

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Lumma.XC
  • ShellcodeRunner.DB
  • ShellcodeRunner.DC
  • ShellcodeRunner.E
  • Snatch.A
Show More
  • Ulise.BB

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-53tli.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-53tli.tmp\consent.rtf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-tiqgh.tmp\9094f1378a54b54f504262e86db6e9be8a576cb7_0004161904.tmp Generic Write,Read Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\698460a0b6e60f2f602361424d832905_8bb23d43de574e82f2bee0df0ec47eeb Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\8ec9b1d0abbd7f98b401d425828828ce_f35f3d6b27e0ccb850e6d0eb17c8b4d9 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\c8e534ee129f27d55460ce17fd628216_1130d9b25898b0db0d4f04dc5b93f141 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\698460a0b6e60f2f602361424d832905_8bb23d43de574e82f2bee0df0ec47eeb Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\8ec9b1d0abbd7f98b401d425828828ce_f35f3d6b27e0ccb850e6d0eb17c8b4d9 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\c8e534ee129f27d55460ce17fd628216_1130d9b25898b0db0d4f04dc5b93f141 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
Show More
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\systemcertificates\authroot\certificates\ddfb16cd4931c973a2037d3fc83a4d7d775d05e4::blob x�`/���7�S.uI0N��K���j8�XCPx �c,j��C�7�Mf �6o�TTJ�h��91�~�S@0>0 `�H��l00 +�7<�0g� 00 +�7<� 402+++++ 2DigiCert RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\ddfb16cd4931c973a2037d3fc83a4d7d775d05e4::blob \�� y��,��Up��7���I1�s�}?�:M}w]��mƢ3�3���AI'�Y����q]dL�.g?纘�Ob U/{�񧯞l�rO��r@ǎv���� ș� 2DigiCert Trusted Root G4 402 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Network Winhttp
  • WinHttpOpen
Keyboard Access
  • GetKeyState
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f488db582bc6890c1277e523a725829bc72a0dbb_0007559015.,LiQMAxHB
"C:\Users\Pivxmsoz\AppData\Local\Temp\is-TIQGH.tmp\9094f1378a54b54f504262e86db6e9be8a576cb7_0004161904.tmp" /SL5="$90214,3256217,830976,c:\users\user\downloads\9094f1378a54b54f504262e86db6e9be8a576cb7_0004161904"
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 1512
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\89a54959472c4a3ef03d9a55b370f4a3f6665b63_0007558143.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8f8930e37a4ea1d8e0672a2f13cd8c007e0a4deb_0007353727.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4e617ff5bed29f76f33dd1f71f1379f3ea9cefcc_0007560063.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...