PUP.HideCon

The detection of PUP.HideCon on your system indicates the presence of a potentially unwanted program (PUP) that may be hiding or concealing its activities from the user. PUPs are software applications that, while not necessarily malicious, can still cause problems for users by displaying unwanted advertisements, collecting personal data without consent, or altering system settings without permission. It is essential to address the PUP.HideCon detection to maintain the security and integrity of your computer system.

What Is PUP.HideCon?

PUP.HideCon, as a potentially unwanted program, is designed to operate in a way that is not immediately apparent to the user. Its primary goal may be to generate revenue for its developers through various means, such as displaying advertisements, redirecting search queries, or collecting and selling user data. PUPs like PUP.HideCon can be installed on a system through bundled software downloads, where the user unknowingly agrees to the installation of additional programs alongside the intended software.

How PUP.HideCon Operates

PUP.HideCon operates by integrating itself into the system and potentially altering browser settings, registry entries, and other configuration files to ensure its persistence. It may also communicate with remote servers to report user activity, download additional components, or receive updates. The program's ability to hide its activities can make it challenging for users to detect and remove it without proper tools and guidance.

Symptoms of Infection

Systems infected with PUP.HideCon may exhibit several symptoms, including an increase in unwanted advertisements and pop-ups, unexpected changes in browser homepage or search engine settings, and a general slowdown in system performance. Users may also notice unfamiliar programs or toolbars installed on their browsers or desktops. These symptoms can vary in severity and may not always be immediately noticeable, making regular system monitoring and maintenance crucial.

How to Remove PUP.HideCon

  1. Boot your computer in Safe Mode with Networking to prevent PUP.HideCon from loading and to allow for a more straightforward removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components related to PUP.HideCon.
  3. Uninstall any suspicious programs that were installed around the time the PUP was detected. Be cautious and only remove programs that you are certain are not needed or are known to be malicious.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any changes made by PUP.HideCon, such as altered homepage settings or unwanted toolbar installations.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of PUP.HideCon have been removed and that your system is clean.

Conclusion

Removing PUP.HideCon from your system is crucial to prevent potential privacy and security risks. By following the steps outlined above and maintaining good computing practices, such as regularly updating your software, avoiding suspicious downloads, and using reputable security tools, you can protect your system from PUPs and other types of malware. Remember, vigilance and proactive maintenance are key to ensuring the ongoing security and performance of your computer.

Analysis Report

General information

Family Name: PUP.HideCon
Signature status: No Signature

Known Samples

MD5: 6db4884dbccadaca8955ab11fb81e64c
SHA1: aaa9368493266cf8b2c6424004c9a87dc56b1829
SHA256: 8646B9C89782A6024779C44589CCFC9516292A81F36B34BC4E87670E66A9DD7B
File Size: 111.62 KB, 111616 bytes
MD5: a0e92d984f19eff55cb995748cb3d83d
SHA1: aff56025cf5903464ed9afdfb47b52b047d7965d
SHA256: CA052F0D907D315548675F48FAAE5BD696EEE4EA47F229B76B334F2AB17583BC
File Size: 90.11 KB, 90112 bytes
MD5: a2fe16e8078859a4baf010b2090c0748
SHA1: 8aeec8634461408a63b66c52c7bf12acd0d8a598
SHA256: 0A51DA2B7573D450B7A8320FDAA068F8B71BD96C0F4D990747EF93CD14B41D2B
File Size: 90.11 KB, 90112 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • fptable
  • Stealer
  • x64
  • x86

Block Information

Total Blocks: 457
Potentially Malicious Blocks: 0
Whitelisted Blocks: 457
Unknown Blocks: 0

Visual Map

2 0 0 1 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 2 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 2 2 0 2 2 2 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 3 1 1 0 1 2 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.IUY
  • Agent.XCD
  • Injector.OIA
  • Kryptik.BBO
  • ShellcodeRunner.DK
Show More
  • ShellcodeRunner.I
  • XWorm.X

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiComputeXformCoefficients
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiExcludeClipRect
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtSelectClipRgn
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetFontData
  • win32u.dll!NtGdiGetGlyphIndicesW
  • win32u.dll!NtGdiGetOutlineTextMetricsInternalW
  • win32u.dll!NtGdiGetRandomRgn
  • win32u.dll!NtGdiGetRealizationInfo
  • win32u.dll!NtGdiGetTextCharsetInfo
  • win32u.dll!NtGdiGetTextExtentExW

81 additional items are not displayed above.

Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\aff56025cf5903464ed9afdfb47b52b047d7965d_0000090112.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8aeec8634461408a63b66c52c7bf12acd0d8a598_0000090112.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...