PUP.Keyfinder

The detection of PUP.Keyfinder on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it to prevent any potential harm.

What Is PUP.Keyfinder?

PUP.Keyfinder is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, stability, and security. They often get installed alongside other software or through deceptive download links.

How PUP.Keyfinder Operates

PUP.Keyfinder, like other PUPs, may operate by collecting user data, displaying unwanted advertisements, or modifying system settings without permission. It may also slow down your system, cause crashes, or interfere with other applications. PUPs can be challenging to remove, as they often disguise themselves as legitimate programs or hide in the system's background processes.

In general, PUPs can be spread through various means, including software bundling, drive-by downloads, or phishing attacks. They may also be installed by exploiting vulnerabilities in the system or other applications. It is crucial to be cautious when downloading software or clicking on links from unknown sources to avoid infecting your system with PUPs.

Symptoms of Infection

If your system is infected with PUP.Keyfinder, you may experience a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and unexpected changes to your system settings. You may also notice that your browser homepage or search engine has been modified without your consent. In some cases, PUPs can also cause system crashes or freezes.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Modified system settings
  • Browser homepage or search engine changes
  • System crashes or freezes

How to Remove PUP.Keyfinder

  1. Boot your system in Safe Mode with Networking to prevent PUP.Keyfinder from loading and to allow for a more straightforward removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.Keyfinder and any other potential threats.
  3. Uninstall any suspicious programs or applications that may be related to PUP.Keyfinder.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any modifications made by PUP.Keyfinder.
  5. Reboot your system and perform another scan to ensure that PUP.Keyfinder has been completely removed.

Conclusion

Removing PUP.Keyfinder from your system is essential to prevent any potential harm and restore your computer's performance and security. By following the steps outlined above, you can effectively remove this potentially unwanted program and protect your system from similar threats in the future. It is also crucial to practice safe computing habits, such as being cautious when downloading software and avoiding suspicious links, to minimize the risk of infecting your system with PUPs or other types of malware.

Analysis Report

General information

Family Name: PUP.Keyfinder
Signature status: No Signature

Known Samples

MD5: 7744f9b71b6a14be4e6383aaec7d5f57
SHA1: 974dbf949c5947c680a826eded2e1b7c1f129243
SHA256: 5941309D9E06C06DF410DE58F35C342A5CC900FC8D0ECE1AA85D591DB05D182A
File Size: 418.83 KB, 418835 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • Installer Manifest
  • No Version Info
  • RAR (In Overlay)
  • RARinO
  • WinRAR SFX
  • WRARSFX
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\apps Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\__tmp_rar_sfx_access_check_2925562 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\faq.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\faq.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\history.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\history.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\icon.ico Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\icon.ico Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\keyfinder.cfg Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\keyfinder.cfg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\keyfinder.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\keyfinder.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\license.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\license.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\readme.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\apps\magicaljellybeankeyfinder\readme.txt Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k�8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~� % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee+Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey

Windows API Usage

Category API
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx
User Data Access
  • GetComputerName
  • GetUserObjectInformation

Shell Command Execution

(NULL) C:\Users\Dmtmfyeu\AppData\Local\Temp\Apps\MagicalJellyBeanKeyfinder\keyfinder.exe

Related Posts

Trending

Most Viewed

Loading...