PUP.Keygen.FFB

The detection of PUP.Keygen.FFB on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.Keygen.FFB?

PUP.Keygen.FFB is a type of potentially unwanted program that is designed to perform specific tasks without the user's knowledge or consent. While it may not be as malicious as other types of malware, it can still cause problems with your system and compromise your personal data. PUPs like PUP.Keygen.FFB are often bundled with other software or downloaded from untrusted sources, making them a common threat to computer users.

How PUP.Keygen.FFB Operates

PUP.Keygen.FFB operates by installing itself on your system and then performing various tasks, such as displaying unwanted advertisements, collecting user data, or modifying system settings. It may also download and install additional malware or PUPs, which can further compromise your system's security. In some cases, PUP.Keygen.FFB may be used to generate revenue for its creators by displaying ads or promoting other software.

It is crucial to note that PUP.Keygen.FFB can be difficult to detect and remove, as it may be disguised as a legitimate program or hide itself in the system's files and registry. Therefore, it is essential to use reputable security software and follow proper removal procedures to ensure that the threat is completely eliminated.

Symptoms of Infection

If your system is infected with PUP.Keygen.FFB, you may experience various symptoms, including unwanted advertisements, slow system performance, and unexpected changes to your browser settings or homepage. You may also notice that your system is crashing or freezing frequently, or that your personal data is being collected and transmitted without your consent.

  • Unwanted ads or pop-ups
  • Slow system performance
  • Changes to browser settings or homepage
  • System crashes or freezes
  • Unexplained data collection or transmission

How to Remove PUP.Keygen.FFB

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for easier removal.
  2. Use a reputable security tool, such as SpyHunter, to perform a full scan of your system and detect any malware or PUPs.
  3. Uninstall any suspicious programs or software that may be related to the PUP.
  4. Reset your browser settings, including Chrome, Firefox, and Edge, to their default values to remove any unwanted changes.
  5. Reboot your system and perform a follow-up scan to ensure that the threat has been completely removed.

Conclusion

In conclusion, the detection of PUP.Keygen.FFB on your system is a serious issue that requires immediate attention. By understanding the nature of this threat and following the proper removal procedures, you can protect your system and personal data from further damage. It is essential to remain vigilant and to use reputable security software to prevent similar threats in the future. Remember to always be cautious when downloading software or clicking on links from untrusted sources, and to regularly scan your system for malware and PUPs to ensure your computer remains secure and performs optimally.

Analysis Report

General information

Family Name: PUP.Keygen.FFB
Signature status: No Signature

Known Samples

MD5: baedba0d53a8353ce582b90f01beb6e0
SHA1: 2204c1129578b9ffa39bedac12432170fbbf22e8
SHA256: 54D4B53128545135795C6BDB5E546B0E3D17EA0D79A1E9F65E98135A880D5068
File Size: 1.31 MB, 1309696 bytes
MD5: a14257f2958a25460765c130f237474b
SHA1: 52cb919d12aa08a7d0441a549f6e5c005d4dbd08
SHA256: CF4BE4B4AC21B1E5A66B22F01699FC280E9EF2A7C3BA3AB3456C9D2B10630E58
File Size: 608.65 KB, 608646 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft
  • Synaptics
File Description Synaptics Pointing Device Driver
File Version
  • 1.00
  • 1.0.0.4
Internal Name Win
Original Filename Win.exe
Product Name
  • Synaptics Pointing Device Driver
  • Win
Product Version
  • 1.00
  • 1.0.0.0

File Traits

  • dll
  • x86

Block Information

Similar Families

  • Kraddare.OC
  • Kryptik.LFT
  • RemoteAdmin.M
  • Trojan.Downloader.Gen.JA
  • Wabot.D
Show More
  • Webalta.A

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\programdata\synaptics Synchronize,Write Attributes
c:\programdata\synaptics\rcxc113.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\synaptics.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\synaptics\synaptics.exe Synchronize,Write Attributes
c:\programdata\synaptics\synaptics.exe Synchronize,Write Data
c:\users\user\appdata\local\temp\j7znqte.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\winsl Synchronize,Write Attributes
c:\users\user\appdata\roaming\winsl\l4\7\2026 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_2204c1129578b9ffa39bedac12432170fbbf22e8_0001309696 Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\downloads\._cache_2204c1129578b9ffa39bedac12432170fbbf22e8_0001309696 Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀT���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/�� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::synaptics pointing device driver C:\ProgramData\Synaptics\Synaptics.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � xy* �/��Y�d�kP~� ��ރ�p��^�o�ee4Vs}kP~��1.��7 ���ﺃee��� ��1 ��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀ��T���B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9� RegNtPreCreateKey

Windows API Usage

Category API
Service Control
  • OpenSCManager
Process Shell Execute
  • ShellExecuteEx
Process Manipulation Evasion
  • NtUnmapViewOfSection
Network Winsock2
  • WSAStartup
  • WSAttemptAutodialName
User Data Access
  • GetUserObjectInformation
Network Winhttp
  • WinHttpOpen
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile
Network Winsock
  • bind
  • closesocket
  • gethostbyname
  • getsockname
  • socket
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

runas c:\users\user\downloads\._cache_2204c1129578b9ffa39bedac12432170fbbf22e8_0001309696
runas C:\ProgramData\Synaptics\Synaptics.exe InjUpdate

Related Posts

Trending

Most Viewed

Loading...