PUP.HackKMS.DJ
The detection of PUP.HackKMS.DJ on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. PUPs are software applications that, while not necessarily malicious, can still cause significant disruptions and pose risks to your personal data and system integrity. It is essential to address this issue promptly to prevent potential harm.
Table of Contents
What Is PUP.HackKMS.DJ?
PUP.HackKMS.DJ is identified as a potentially unwanted program, which means it is not a virus or malware in the traditional sense but can still exhibit undesirable behaviors. PUPs often find their way onto systems through bundled software downloads, where they are included alongside legitimate applications, or through deceptive marketing tactics that trick users into installing them. Once installed, PUP.HackKMS.DJ may perform various unwanted actions, such as displaying unwanted advertisements, collecting user data without consent, or altering system settings for its benefit.
How PUP.HackKMS.DJ Operates
PUPs like PUP.HackKMS.DJ typically operate by integrating themselves into the system in a way that makes them difficult to detect and remove. They may create entries in the system registry, add startup items, or install extensions in web browsers to ensure persistence. Their primary goal is often to generate revenue for their developers through pay-per-click advertising, data selling, or by promoting other PUPs or malware. Understanding how PUP.HackKMS.DJ operates is crucial for effective removal and prevention of future infections.
Symptoms of Infection
Symptoms of a PUP infection can vary but commonly include an increase in unwanted advertisements (pop-ups, banners, etc.), unexpected changes in browser settings (homepage, search engine, etc.), slowdowns in system performance, and the presence of unknown or suspicious programs. Users may also notice that their web searches are being redirected to unwanted sites or that they are being prompted to install additional, suspicious software. Recognizing these symptoms early can help in taking prompt action against the PUP.
How to Remove PUP.HackKMS.DJ
- Enter Safe Mode with Networking to prevent PUP.HackKMS.DJ from loading and to make the removal process safer and more effective.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components related to PUP.HackKMS.DJ.
- Uninstall suspicious programs that you do not recognize or that were installed around the time you noticed the infection. Be cautious and only remove programs you are sure are not needed.
- Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any unwanted extensions or settings changes made by PUP.HackKMS.DJ.
- After completing the above steps, reboot your system and perform another scan with your anti-malware tool to ensure that all remnants of PUP.HackKMS.DJ have been removed.
Conclusion
Removing PUP.HackKMS.DJ requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining vigilance in your computing practices, you can effectively remove this PUP and protect your system from similar threats in the future. It's also important to keep your operating system, browsers, and security software up to date, as newer versions often include better protections against PUPs and other forms of malware. Staying informed and proactive is key to ensuring your digital security and privacy.
Analysis Report
General information
| Family Name: | PUP.HackKMS.DJ |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
a1996b0087323908132a654f137d26c2
SHA1:
9e00d3cc6c7dcbf3dc2fef004a4fcaa3d9a6085b
SHA256:
51CF120D6DC4CC2152B96549734FD40ADEFB5BB25E18CBF67888D69986C41DF0
File Size:
495.28 KB, 495281 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- No Version Info
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 445 |
|---|---|
| Potentially Malicious Blocks: | 0 |
| Whitelisted Blocks: | 438 |
| Unknown Blocks: | 7 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Trojan.Downloader.Gen.M
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe | Generic Read,Write Attributes |
| \device\namedpipe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0 | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\__tmp_rar_sfx_access_check_6835958 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\act.cmd | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\act.cmd | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\autorun.apm | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\autorun.apm | Synchronize,Write Attributes |
Show More
| c:\users\user\appdata\local\temp\rarsfx0\chk.cmd | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\chk.cmd | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\choice.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\choice.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\cscript.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\cscript.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\help.txt | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\help.txt | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\hidcon.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\hidcon.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\instsrv.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\instsrv.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\keymng.cmd | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\keymng.cmd | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\kmservice.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\kmservice.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\kmsins.cmd | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\kmsins.cmd | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\ospp.vbs | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\ospp.vbs | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\osppc.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\osppc.dll | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\ospprearm.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\ospprearm.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\portqry.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\portqry.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\rearm.cmd | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\rearm.cmd | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\rest.cmd | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\rest.cmd | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\service.inf | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\service.inf | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\slerror.xml | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\slerror.xml | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\rarsfx0\srvany.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\rarsfx0\srvany.exe | Synchronize,Write Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 毷枦ǜ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m �� �v(�1�1HO @V� H[uc�w �P� ����� ��� �m� � �V �$�� ) � B1_ �`� ��� | RegNtPreCreateKey |
Show More
| HKCU\software\microsoft\ctf\msutb::left | ঔ | RegNtPreCreateKey |
| HKCU\software\microsoft\ctf\msutb::top | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m �� �v%�(�1�1HO @V� H[ua$c�w �P� ����� ��� �m� � �V �$�� ) � B1_ �i� �`� ��� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m �� �v%�(�1�1HO @V� H[ua$c�w e�v�P� ����� ��� �m� � �V �$�� ) � B1_ �i� �`� ��� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m �� �v%�(�1�1HO @V� H[ua$c�w e�vw�n�P� ����� ��� �m� � �V �$�� ) � B1_ �i� �`� ��� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m �� �v%�(�1�1HO @V� H[ua$c�w e�vw�n�P� ����� ��� � ��m� � �V �$�� ) � B1_ �i� �`� ��� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m �� �v%�(�1�1HO @V� H[ua$c�w e�vw�n�P� �x� �����7�M�� ��� � ��j��m� � �IV �V �$���(!�^ ��j �) � B1_ `�V�i� �`� ��3��� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 鴄 ȁ 獖} | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m ! �� �v%�(�,=� 1�1HO @V� H[uN� a$c�w e�vw�ny�9 �P� �x� �����7�M�� ��� � ��j��m� � �IV �V �$���(!�^ ��j �) � B1_ `�V�i� �`� ��3��� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m " |