PUP.KeyViewer

The detection of PUP.KeyViewer on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. PUPs are software applications that, while not necessarily malicious, can still cause significant disruptions and pose risks to your personal data and system integrity. Understanding what PUP.KeyViewer is, how it operates, and the symptoms it causes is crucial for effective removal and prevention of future infections.

What Is PUP.KeyViewer?

PUP.KeyViewer is categorized as a potentially unwanted program, which means it is not classified as malware in the traditional sense but can still exhibit undesirable behavior. PUPs often find their way onto systems through bundled software downloads, where they are included alongside legitimate applications without the user's full knowledge or consent. Once installed, PUP.KeyViewer may perform a variety of actions that are not in the best interest of the user, such as displaying unwanted advertisements, collecting user data, or modifying system settings.

How PUP.KeyViewer Operates

The operation of PUP.KeyViewer typically involves integrating itself into the system in a way that makes it difficult to detect and remove. It may install additional components or modify system files to ensure its persistence. PUPs like PUP.KeyViewer often have the capability to communicate with remote servers, from which they can receive updates, send collected data, or download additional unwanted software. This communication can lead to further system compromises and increased risk of malware infections.

Symptoms of Infection

Systems infected with PUP.KeyViewer may exhibit a range of symptoms, including but not limited to, an increase in unwanted pop-ups or advertisements, unexpected changes in browser settings or homepage, slowdowns in system performance, and the presence of unfamiliar programs or toolbars. Users may also notice that their browsing data is being collected or that they are being redirected to unwanted websites. These symptoms can significantly disrupt the user experience and pose security risks.

How to Remove PUP.KeyViewer

  1. Boot your computer in Safe Mode with Networking to prevent PUP.KeyViewer from loading and to give you internet access for downloading removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, which is capable of detecting and removing PUPs and other types of malware. Perform a full scan of your system to identify all components of PUP.KeyViewer.
  3. Uninstall any suspicious programs that were installed around the time you noticed the infection. Be cautious and only uninstall programs that you are certain are not needed.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any changes made by PUP.KeyViewer, such as altered homepages or search engines.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all components of PUP.KeyViewer have been removed. This step is crucial for verifying the effectiveness of the removal process.

Conclusion

Removing PUP.KeyViewer from your system requires a thorough approach to ensure all its components are eliminated. By following the steps outlined above and maintaining good computing practices, such as regularly updating your operating system and applications, using strong antivirus software, and being cautious with downloads and email attachments, you can protect your system from PUPs and other types of malware. Remember, prevention is key, and staying informed about the latest threats and best practices for computer security is essential for safeguarding your digital life.

Analysis Report

General information

Family Name: PUP.KeyViewer
Signature status: No Signature

Known Samples

MD5: dde142fbeb37c54679a0ea122a2011e4
SHA1: b7f8dfe6caa5d7f2e364cc66ad109a8c514e9c59
File Size: 51.16 KB, 51164 bytes
MD5: 5dacea3525718bbc1159b40b06831a13
SHA1: 0f01da459f776de9b9ac8e3acf6af335946d72a3
SHA256: 8B3AAFD9196A074EEE355D394BFFC84033762D5402F7048E49FA6B17CFC61F60
File Size: 26.11 KB, 26112 bytes
MD5: bdb00015b4bc13da57874cd499afff51
SHA1: 3054892b7d5d652a24b3818cfe90e07f96022368
SHA256: 914121E504FE31A8C19D925B570BA832AB3C429B120ECDFB9F0245E58AAE1A21
File Size: 51.16 KB, 51164 bytes
MD5: 48ec9aecff5ab939ea57ae69f264ad2f
SHA1: 4962bd97bb420df17a99c2ed62087739472873df
SHA256: C0FC2F52126BE2CC24E1C8556C835A8D538E5B1BC8D3806395801AED3A7BA7AE
File Size: 50.85 KB, 50848 bytes
MD5: 7f597fd0a7bf2e961be2705986698a32
SHA1: 7af9b7786337d34598fdb7912362e5c3d40cd5d8
SHA256: 280E8D82B7E4A7ED044968604756DDB939B81832A6FA176277844437133F90C8
File Size: 50.85 KB, 50848 bytes
Show More
MD5: 344709a2f2fd788236f1f5ffa997cd46
SHA1: 8cbbbf4973f7b7e22620148d898c060280512080
SHA256: 59E23515978DD7DF6FFA6175F2D37251E44EA671FE7FC431540F30DD9450DDCF
File Size: 48.85 KB, 48848 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • Installer Manifest
  • nosig nsis
  • No Version Info
  • Nullsoft Installer
  • x86

Block Information

Total Blocks: 75
Potentially Malicious Blocks: 0
Whitelisted Blocks: 75
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.MH
  • Agent.MI
  • Agent.MU
  • Autorun.LA
  • Chapak.HBBB
Show More
  • FakeAV.AU
  • Makoob.A
  • Parite.F
  • Trojan.Downloader.Gen.BQ

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsb256e.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsb256e.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsb256e.tmp\system.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsgf481.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsgf481.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsgf481.tmp\system.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsl255d.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsp2d4d.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsp2d4d.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp2d4d.tmp\system.dll Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\nsp5769.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsp5769.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsp5769.tmp\system.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsqf470.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsze9d4.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsze9d4.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsze9d4.tmp\system.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows nt\currentversion\softwareprotectionplatform\activation::manual  RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Dynbcegf\AppData\Local\Temp\nsp5769.tmp\ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 S�? xy#kP~�ރ#�����^#۴�c}��Vs}�kP~0�)����1��d���d#B FF e<��1���h�n�}#e��#e�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �N�r�i��*����8\x��B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx��� ���\�!IN�sb �!>!wz#@�#��#�O$kF$��$¨%:�%f�%� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 闩ȁ獖} RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k- �vT�����(�(X�*J1�1HO@V�A��G�IH[uH�p^��_�zh�rk�qq�Xvy�{b��P��jI�������6����.���j���*� [�m�ƾB�]��IVӂa����$�Ac�8წ���&M�^��=�S.SLB1_T�Vw�`�V��3��%�������A RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��  xy* �/��Y�d�� ��ރ�p��^�o�[Vs}kP~��11��7 ���ﺃee����1��h�n�ie��r[�v RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 l�8�tX�jg�8 �6 �v �Z xy ��T���������5����Bx!wz#�#��$kF%:�%`�&� (�(X�)E)�`*J*9+�[,��-!R/9�/��1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20U_*V �X� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鳼ȁ ਪˣ鈯ˣ遙̃豤̃অˣ炑̃龡^濖̃賬̃攘ť獖}偫~엦1਷ˣ邯̃뫯ʃeꙥžဈ엦18¶fꙥži5ꙥžr/֢vꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m_jg �� �v ��T������%��Bx�<#��(�(X�(�)�`*J*9*�"-!R1�1HO5,]@V�A��G�IH[uH�pN$N�^��_�zb"hc�wh�rj�bk`k�ql(�lR q�Xr�BsU�vy�w�ny�9{b�~D�P��������7�M�b:���������6�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴅ȁ獖}偫~엦1eꙥž¶i ꙥžr ֢vꙥž RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �mUtX �� �v �ZT�����Bx�<#��&� (�(X�*J*9*�"1`1�1HO=�@V�A��G�IH[uH�pN$N�Z^�^��_�zb"hc�wj�bk`k�qk�8l(�lR q�Xr�BtǤw�n{b��P�����!�����7� ���3�M�b:�����������O���.�� RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\Users\Dynbcegf\AppData\Local\Temp\gkey.exe
C:\Users\Fbdifovb\AppData\Local\Temp\gkey.exe
C:\Users\Ndmqahzf\AppData\Local\Temp\gkey.exe
C:\Users\Nzasdrra\AppData\Local\Temp\gkey.exe
C:\Users\Nxhvyrvb\AppData\Local\Temp\gkey.exe

Related Posts

Trending

Most Viewed

Loading...