PUP.Keyfinder
The detection of PUP.Keyfinder on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it to prevent any potential harm.
Table of Contents
What Is PUP.Keyfinder?
PUP.Keyfinder is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They often get installed alongside other software or through deceptive download links.
How PUP.Keyfinder Operates
PUP.Keyfinder, like other PUPs, may operate by collecting user data, displaying unwanted advertisements, or modifying system settings without permission. It may also slow down your system, cause crashes, or interfere with other applications. PUPs can be challenging to remove, as they often disguise themselves as legitimate programs or hide in the system's background processes.
In general, PUPs can be spread through various means, including software bundling, drive-by downloads, or phishing attacks. They may also be installed by exploiting vulnerabilities in the system or other applications. It is crucial to be cautious when downloading software or clicking on links from unknown sources to avoid infecting your system with PUPs.
Symptoms of Infection
If your system is infected with PUP.Keyfinder, you may experience a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and unexpected changes to your system settings. You may also notice that your browser homepage or search engine has been modified without your consent. In some cases, PUPs can also cause system crashes or freezes.
- Unwanted advertisements or pop-ups
- Slow system performance
- Modified system settings
- Browser homepage or search engine changes
- System crashes or freezes
How to Remove PUP.Keyfinder
- Boot your system in Safe Mode with Networking to prevent PUP.Keyfinder from loading and to allow for a more straightforward removal process.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.Keyfinder and any other potential threats.
- Uninstall any suspicious programs or applications that may be related to PUP.Keyfinder.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any modifications made by PUP.Keyfinder.
- Reboot your system and perform another scan to ensure that PUP.Keyfinder has been completely removed.
Conclusion
Removing PUP.Keyfinder from your system is essential to prevent any potential harm and restore your computer's performance and security. By following the steps outlined above, you can effectively remove this potentially unwanted program and protect your system from similar threats in the future. It is also crucial to practice safe computing habits, such as being cautious when downloading software and avoiding suspicious links, to minimize the risk of infecting your system with PUPs or other types of malware.
Analysis Report
General information
| Family Name: | PUP.Keyfinder |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
7744f9b71b6a14be4e6383aaec7d5f57
SHA1:
974dbf949c5947c680a826eded2e1b7c1f129243
SHA256:
5941309D9E06C06DF410DE58F35C342A5CC900FC8D0ECE1AA85D591DB05D182A
File Size:
418.83 KB, 418835 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have relocations information
- File doesn't have security information
- File has exports table
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- Installer Manifest
- No Version Info
- RAR (In Overlay)
- RARinO
- WinRAR SFX
- WRARSFX
- x86
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\temp\apps | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\__tmp_rar_sfx_access_check_2925562 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\faq.txt | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\faq.txt | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\history.txt | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\history.txt | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\icon.ico | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\keyfinder.cfg | Generic Read,Write Data,Write Attributes,Write extended,Append data |
Show More
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\keyfinder.cfg | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\keyfinder.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\keyfinder.exe | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\license.txt | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\license.txt | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\readme.txt | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\readme.txt | Synchronize,Write Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | -k � 8��8tX��B�8 �� �6 �v5� �Z xy �� T�B� ������ � ���� �5����ee��Bx �< �!wz "Wc#�#��$kF$�� %"�%:� %�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9� /��0P%1`1�1HO 1�D5�05�G | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | ~� % xy * � /�� Y� d� kP~ � � �ރ �p ��^ �o � ��z ee+ Vs} kP~ ��1 � �� 7 � �� ﺃ e e�� ��1 �� f e�� h �n | RegNtPreCreateKey |
Show More
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | .k 8��8tX��B�8 �� �6 �v5� �Z xy �� T�B� ������ � ���� �5����ee��Bx �< �!wz "Wc#�#��$kF$�� %"�%:� %�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9� /��0P%1`1�1HO 1�D5�05�G | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Keyboard Access |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| User Data Access |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
(NULL) C:\Users\Dmtmfyeu\AppData\Local\Temp\Apps\MagicalJellyBeanKeyfinder\keyfinder.exe
|