PUP.HackKMS.DJ

The detection of PUP.HackKMS.DJ on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. PUPs are software applications that, while not necessarily malicious, can still cause significant disruptions and pose risks to your personal data and system integrity. It is essential to address this issue promptly to prevent potential harm.

What Is PUP.HackKMS.DJ?

PUP.HackKMS.DJ is identified as a potentially unwanted program, which means it is not a virus or malware in the traditional sense but can still exhibit undesirable behaviors. PUPs often find their way onto systems through bundled software downloads, where they are included alongside legitimate applications, or through deceptive marketing tactics that trick users into installing them. Once installed, PUP.HackKMS.DJ may perform various unwanted actions, such as displaying unwanted advertisements, collecting user data without consent, or altering system settings for its benefit.

How PUP.HackKMS.DJ Operates

PUPs like PUP.HackKMS.DJ typically operate by integrating themselves into the system in a way that makes them difficult to detect and remove. They may create entries in the system registry, add startup items, or install extensions in web browsers to ensure persistence. Their primary goal is often to generate revenue for their developers through pay-per-click advertising, data selling, or by promoting other PUPs or malware. Understanding how PUP.HackKMS.DJ operates is crucial for effective removal and prevention of future infections.

Symptoms of Infection

Symptoms of a PUP infection can vary but commonly include an increase in unwanted advertisements (pop-ups, banners, etc.), unexpected changes in browser settings (homepage, search engine, etc.), slowdowns in system performance, and the presence of unknown or suspicious programs. Users may also notice that their web searches are being redirected to unwanted sites or that they are being prompted to install additional, suspicious software. Recognizing these symptoms early can help in taking prompt action against the PUP.

How to Remove PUP.HackKMS.DJ

  1. Enter Safe Mode with Networking to prevent PUP.HackKMS.DJ from loading and to make the removal process safer and more effective.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components related to PUP.HackKMS.DJ.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time you noticed the infection. Be cautious and only remove programs you are sure are not needed.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any unwanted extensions or settings changes made by PUP.HackKMS.DJ.
  5. After completing the above steps, reboot your system and perform another scan with your anti-malware tool to ensure that all remnants of PUP.HackKMS.DJ have been removed.

Conclusion

Removing PUP.HackKMS.DJ requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining vigilance in your computing practices, you can effectively remove this PUP and protect your system from similar threats in the future. It's also important to keep your operating system, browsers, and security software up to date, as newer versions often include better protections against PUPs and other forms of malware. Staying informed and proactive is key to ensuring your digital security and privacy.

Analysis Report

General information

Family Name: PUP.HackKMS.DJ
Signature status: No Signature

Known Samples

MD5: a1996b0087323908132a654f137d26c2
SHA1: 9e00d3cc6c7dcbf3dc2fef004a4fcaa3d9a6085b
SHA256: 51CF120D6DC4CC2152B96549734FD40ADEFB5BB25E18CBF67888D69986C41DF0
File Size: 495.28 KB, 495281 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 445
Potentially Malicious Blocks: 0
Whitelisted Blocks: 438
Unknown Blocks: 7

Visual Map

0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.Downloader.Gen.M

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0 Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\__tmp_rar_sfx_access_check_6835958 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\act.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\act.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\autorun.apm Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\autorun.apm Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\rarsfx0\chk.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\chk.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\choice.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\choice.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\cscript.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\cscript.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\help.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\help.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\hidcon.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\hidcon.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\instsrv.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\instsrv.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\keymng.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\keymng.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\kmservice.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\kmservice.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\kmsins.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\kmsins.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\ospp.vbs Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\ospp.vbs Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\osppc.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\osppc.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\ospprearm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\ospprearm.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\portqry.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\portqry.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\rearm.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\rearm.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\rest.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\rest.cmd Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\service.inf Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\service.inf Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\slerror.xml Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\slerror.xml Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rarsfx0\srvany.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rarsfx0\srvany.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 毷枦ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �� �v(�1�1HO@V�H[uc�w�P����������m���V�$��)�B1_�`���� RegNtPreCreateKey
Show More
HKCU\software\microsoft\ctf\msutb::left RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::top RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �� �v%�(�1�1HO@V�H[ua$c�w�P����������m���V�$��)�B1_�i��`���� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �� �v%�(�1�1HO@V�H[ua$c�we�v�P����������m���V�$��)�B1_�i��`���� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �� �v%�(�1�1HO@V�H[ua$c�we�vw�n�P����������m���V�$��)�B1_�i��`���� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �� �v%�(�1�1HO@V�H[ua$c�we�vw�n�P������������m���V�$��)�B1_�i��`���� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �� �v%�(�1�1HO@V�H[ua$c�we�vw�n�P��x������7�M��������j��m���IV�V�$���(!�^��j�)�B1_`�V�i��`���3��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴄ȁ獖} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m! �� �v%�(�,=�1�1HO@V�H[uN�a$c�we�vw�ny�9�P��x������7�M��������j��m���IV�V�$���(!�^��j�)�B1_`�V�i��`���3��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m" �� �v ��%�(�,=�1�1HO@V�H[uN�a$c�we�vw�ny�9�P��x������7�M��������j��m���IV�V�$���(!�^��j�)�B1_`�V�i��`���3��� RegNtPreCreateKey

Windows API Usage

Category API
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess

Shell Command Execution

(NULL) C:\Users\Hswzxflp\AppData\Local\Temp\RarSFX0\act.cmd
WriteConsole: Microsoft (R) Wi
WriteConsole: Copyright (C) Mi
WriteConsole: ================
WriteConsole:
Show More
C:\WINDOWS\system32\reg.exe REG QUERY HKLM\SOFTWARE\Microsoft\Office
C:\WINDOWS\system32\find.exe find /i "14.0"
WriteConsole: Microsoft Office
WriteConsole: Este activador e
C:\WINDOWS\system32\reg.exe REG QUERY "HKLM\SYSTEM\CurrentControlSet\Services\KMService" /v DisplayName
C:\WINDOWS\system32\findstr.exe findstr /i KMService
C:\WINDOWS\system32\tasklist.exe tasklist /fi "imagename eq KMService.exe"
C:\WINDOWS\system32\find.exe find /i /n "KMService.exe"
WriteConsole:

Related Posts

Trending

Most Viewed

Loading...