PUP.HackKMS.F
The detection of PUP.HackKMS.F on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.
Table of Contents
What Is PUP.HackKMS.F?
PUP.HackKMS.F is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as harmful as other types of malware, such as viruses or Trojans, it can still cause problems with your system and compromise your personal data. PUPs are often installed unintentionally, and they can be difficult to remove without the right tools and knowledge.
How PUP.HackKMS.F Operates
PUP.HackKMS.F, like other PUPs, can operate in various ways, including modifying system settings, displaying unwanted advertisements, and collecting user data. It may also attempt to connect to remote servers to download additional malware or update its own components. In some cases, PUPs can be used to distribute other types of malware, making them a significant threat to your system's security.
Symptoms of Infection
If your system is infected with PUP.HackKMS.F, you may experience a range of symptoms, including slow system performance, unwanted pop-ups and advertisements, and changes to your browser settings. You may also notice that your system is crashing or freezing frequently, or that your personal data is being collected and transmitted without your consent. In some cases, PUPs can also cause issues with your system's stability and security, making it vulnerable to other types of malware.
- Unwanted changes to your system settings
- Display of unwanted advertisements and pop-ups
- Collection and transmission of personal data
- Slow system performance and crashes
- Changes to your browser settings and homepage
How to Remove PUP.HackKMS.F
- Boot your system in Safe Mode with Networking to prevent PUP.HackKMS.F from loading and to allow you to download and install removal tools.
- Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove PUP.HackKMS.F and any other malware that may be present.
- Uninstall any suspicious programs that may be related to PUP.HackKMS.F, and be cautious when installing new software to avoid unintentionally installing PUPs.
- Reset your browser settings, including Chrome, Firefox, and Edge, to their default values to remove any changes made by PUP.HackKMS.F.
- Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that PUP.HackKMS.F has been completely removed.
Conclusion
Removing PUP.HackKMS.F from your system requires careful attention to detail and the use of reputable removal tools. By following the steps outlined above, you can help to ensure that your system is free from this potentially unwanted program and prevent future infections. It is also essential to be cautious when installing new software and to keep your operating system and security software up to date to protect against the latest threats.
Analysis Report
General information
| Family Name: | PUP.HackKMS.F |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
8e1a461b615ced87e4256dcf7aa72fae
SHA1:
9ed14e98fe946b678c8754ecc3118eb1ec6c6adf
SHA256:
BA4B36725A5A50D0B04FA52B63C72A717BCEDC2C1B9D9B536F33AED54DCE237A
File Size:
3.04 MB, 3043840 bytes
|
|
MD5:
37c8132d3968578793cf95e2764c434a
SHA1:
55ec7e5651db6ea4dfcd265a466d1cd12e08da3d
SHA256:
FAEE6714AE77B06A454B280E94ABAB8AE1F4D36A981040617FBA3B5AF7936AC5
File Size:
9.60 MB, 9603868 bytes
|
|
MD5:
8867a8b370e982308e4dd4522c9d873e
SHA1:
24fbbb79774ff7f6cfe6a74a18bdee64fe29a81e
SHA256:
FE6B01D72FAB1FCFF74AA488B8A4E29AECB2D4128A598584FEB4664F5D35E0C4
File Size:
7.57 MB, 7572992 bytes
|
|
MD5:
0c127bc8fa6496aa0aa6064362cc639e
SHA1:
8bf10a323a7dbed486afa1d96c354e824ce307a0
SHA256:
82E35F7FF1F22234F86A6B739AC27A83444EFE07C60CFBB54BE39DC63B63EDF4
File Size:
7.77 MB, 7772672 bytes
|
|
MD5:
55b0fe6bdcf167a2ccf79f617326e5fb
SHA1:
d83edb614c6e237a1bd4991393d9a45b4e330c4f
SHA256:
535B984AD759CECC619AFD5125C2941B3C216CE941846AA9CA794D5A558B9B27
File Size:
3.05 MB, 3048448 bytes
|
Show More
|
MD5:
ca800495e75d561288f4ae95e33fcb2d
SHA1:
e44fc7c9ce7e220dafa65c9f25ecc4799b374f23
SHA256:
E1352A7F676288BDFF766F513C6FE08B0A242F4B0F3A3C81106FEE6A5CC63813
File Size:
3.81 MB, 3809280 bytes
|
|
MD5:
141bd0171bec447d65a6e4f760496e42
SHA1:
06ac0ea4a6a0bb2f70da8ea69d2f6c5d572dedd3
SHA256:
CA603EA07DC1F8FDC47C70AB2FCB9D970CE915E6DC3A1261D625F551626A5671
File Size:
6.16 MB, 6163968 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | Synaptics |
| File Description |
|
| File Version | 1.0.0.4 |
| Product Name | Synaptics Pointing Device Driver |
| Product Version | 1.0.0.0 |
File Traits
- 2+ executable sections
- HighEntropy
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 2,323 |
|---|---|
| Potentially Malicious Blocks: | 323 |
| Whitelisted Blocks: | 1,881 |
| Unknown Blocks: | 119 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- HackKMS.D
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe | Generic Read,Write Attributes |
| \device\namedpipe | Generic Write,Read Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable | Synchronize,Write Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\__tmp_rar_sfx_access_check_2927656 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsauto x64.exe | Generic Write,Read Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsauto x64.exe | Synchronize,Write Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsauto.exe | Generic Write,Read Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsauto.exe | Synchronize,Write Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsautolite.ini | Generic Write,Read Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\kmsautolite.ini | Synchronize,Write Attributes |
Show More
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\readme_en.txt | Generic Write,Read Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\readme_en.txt | Synchronize,Write Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\sacc.bat | Generic Write,Read Attributes |
| c:\program files (x86)\_kmsauto lite v1.8.8.0 portable\sacc.bat | Synchronize,Write Attributes |
| c:\programdata\synaptics | Synchronize,Write Attributes |
| c:\programdata\synaptics\rcxbf6d.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\programdata\synaptics\synaptics.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\programdata\synaptics\synaptics.exe | Synchronize,Write Attributes |
| c:\programdata\synaptics\synaptics.exe | Synchronize,Write Data |
| c:\users\user\appdata\local\temp\gmzhumt.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\roaming\winsl | Synchronize,Write Attributes |
| c:\users\user\appdata\roaming\winsl\l4\10\2026 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\._cache_e44fc7c9ce7e220dafa65c9f25ecc4799b374f23_0003809280 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\._cache_e44fc7c9ce7e220dafa65c9f25ecc4799b374f23_0003809280 | Synchronize,Write Attributes |
| c:\users\user\downloads\24fbbb79774ff7f6cfe6a74a18bdee64fe29a81e_0007572992 | Synchronize,Write Attributes |
| c:\users\user\downloads\aact.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\kmsautolite.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\microsoft\windows script host\settings::enabled | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 䐜୩竌ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 䐜୩竌ǜ | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 㴝煹窽ǜ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | /k 8��8tXz��B�8 �� �6 �v z5� �Z xy �� T�B� ������ � ���� �5����ee +��Bx �<5 � �!wz "Wc#�#��$kF$�� %"�%:� %�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9� /��0P%1` | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | �� 2 xy * � /�� Y� d� kP~ �� � � �ރ �p ��^ �o � ��z ee) Vs} kP~ ��1 � �� 7 � �� ﺃ e e�� ��1 �� f e�� h | RegNtPreCreateKey |
Show More
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | 0k 8��8tXz��B�8 �� �6 �v z5� �Z xy �� T�B� ������ � ���� �5����ee +��Bx �<5 � �!wz "Wc#�#��$kF$�� %"�%:� %�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9� /��0P%1` | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 딱뀅負ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | '����� | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe | 揨쏁ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ꧮ揭쏁ǜ | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries | `$�!�:i�� +00�� �Gs]XM���"�2� � FX D�':D��exA-� �LG=�A��J� �C� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | k 8��81��B�8 �6 �v y��Z xy �� �a ۀT��� B� ����� 1���� �5����eeBx �<�� �� �R �7 �!wz "M)"Wc#�#��$kF$�� %"�%:� %�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=� ,��/9� /�� | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\run::synaptics pointing device driver | C:\ProgramData\Synaptics\Synaptics.exe | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | � xy * � /�� Y� d� kP~ � � �ރ �p ��^ �o � ee= Vs} kP~ ��1 . �� 7 � �� ﺃ e e�� � ��1 �� f e�� g � | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | k 8��81��B�8 �6 �v y��Z xy �� �a ۀ�� T��� B� ����� 1���� �5����eeBx �<�� �� �R �7 �!wz "M)"Wc#�#��$kF$�� %"�%:� %�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=� ,��/9� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | k 8��81��B�8 �6 �v y��Z xy �� �a ۀ�� T��� B� ����� 1���� �5����eeBx �<�� �� �R �7 �!wz "M)"Wc#�#��$kF$�� %"�%:� %�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=� ,��/9� | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Network Winsock2 |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Syscall Use |
Show More
|
| Process Terminate |
|
| Keyboard Access |
|
| Service Control |
|
| Network Winhttp |
|
| Network Wininet |
|
| Network Winsock |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
"C:\WINDOWS\Sysnative\cmd.exe" /c WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionPath="c:\users\user\downloads\9ed14e98fe946b678c8754ecc3118eb1ec6c6adf_0003043840"
|
C:\WINDOWS\System32\Wbem\WMIC.exe WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionPath="c:\users\user\downloads\9ed14e98fe946b678c8754ecc3118eb1ec6c6adf_0003043840"
|
WriteConsole: Access is denied
|
(NULL) C:\Program Files (x86)\_KMSAuto Lite v1.8.8.0 Portable\SACC.BaT
|
C:\WINDOWS\system32\reg.exe reg Query "HKLM\Hardware\Description\System\CentralProcessor\0"
|
Show More
C:\WINDOWS\system32\find.exe find /i "x86"
|
C:\WINDOWS\system32\explorer.exe explorer "KMSAuto x64.exe"
|
"C:\WINDOWS\Sysnative\cmd.exe" /c copy C:\WINDOWS\system32\Tasks\KMSAuto "C:\Users\Kfstbngz\AppData\Local\Temp\KMSAuto.tmp" /Y
|
"C:\WINDOWS\Sysnative\cmd.exe" /c WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionPath="c:\users\user\downloads\d83edb614c6e237a1bd4991393d9a45b4e330c4f_0003048448"
|
C:\WINDOWS\System32\Wbem\WMIC.exe WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionPath="c:\users\user\downloads\d83edb614c6e237a1bd4991393d9a45b4e330c4f_0003048448"
|
runas c:\users\user\downloads\._cache_e44fc7c9ce7e220dafa65c9f25ecc4799b374f23_0003809280
|
runas C:\ProgramData\Synaptics\Synaptics.exe InjUpdate
|