PUP.QQB.A

The detection of PUP.QQB.A on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent future infections.

What Is PUP.QQB.A?

PUP.QQB.A is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in nature but can still cause problems for computer users. PUPs can be installed on a system without the user's knowledge or consent, often through bundled software downloads or deceptive advertising. They can collect user data, display unwanted ads, and slow down system performance.

How PUP.QQB.A Operates

PUP.QQB.A, like other PUPs, can operate in various ways to achieve its goals. It may collect user data, such as browsing history and search queries, to display targeted ads or sell the information to third parties. It can also slow down system performance by consuming system resources or installing additional software without the user's consent. In some cases, PUPs can also download and install other malware or viruses, increasing the risk of further infections.

Symptoms of Infection

The symptoms of a PUP.QQB.A infection can vary, but common signs include unwanted ads or pop-ups, slow system performance, and unfamiliar programs or toolbars installed on the system. Users may also notice changes to their browser settings, such as a new default search engine or homepage. In some cases, the system may become unstable or crash frequently, indicating a more severe infection.

  • Unwanted ads or pop-ups
  • Slow system performance
  • Unfamiliar programs or toolbars installed on the system
  • Changes to browser settings
  • System instability or frequent crashes

How to Remove PUP.QQB.A

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.QQB.A and any other malware that may be present.
  3. Uninstall any suspicious programs or software that may be related to the infection, using the "Add/Remove Programs" or "Programs and Features" control panel.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by the malware.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing PUP.QQB.A from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above, you can effectively remove the malware and prevent future infections. It is essential to remain vigilant and take proactive measures to protect your system, such as keeping your operating system and software up to date, using reputable anti-malware tools, and being cautious when downloading software or clicking on links from unknown sources.

Analysis Report

General information

Family Name: PUP.QQB.A
Signature status: No Signature

Known Samples

MD5: a9262436daf4bd07ea662d898e58e866
SHA1: 33afb97b8b619c8e45961810a1a47448c2b2b664
SHA256: AA923A938B7EF73DF1F59B4FDC8E7651B5259975BA361F9C33AF3E000614BDC8
File Size: 892.42 KB, 892416 bytes
MD5: 41750b11f662dad061641d887d4230aa
SHA1: d4033bd554e06de41fe807cf0a9b41b21e1c2efb
SHA256: CF6C0054D721AFE6BC32B205275BA50F92BD1C88A3ED8963D475D54B9B417DF9
File Size: 8.32 MB, 8323072 bytes
MD5: a286396957ecc05dc1720b42a37b40e7
SHA1: 5201536a9ab4c8a697d00d3be3b65cdbbd21b8fe
SHA256: BF5AAE955DD4D66794E94FD686F2DD6EE4DE2DB3F5CA56BC92515EEFFA9865E8
File Size: 9.11 MB, 9109504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments 2014-07-16 00:00:00
Company Name Tencent Inc.
File Description QQ浏览器安装程序
File Version
  • 22.0.6021.400
  • 1.1.29.01
Internal Name QQBrowser
Legal Copyright Copyright © 2026 Tencent. All Rights Reserved.
Product Name QQ浏览器
Product Version
  • 22.0.6021.400
  • 1.1.29.01

File Traits

  • AutoHK
  • big overlay
  • HighEntropy
  • VirtualQueryEx
  • WriteProcessMemory
  • x64
  • x86

Block Information

Total Blocks: 17,816
Potentially Malicious Blocks: 300
Whitelisted Blocks: 13,066
Unknown Blocks: 4,450

Visual Map

0 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 ? ? 0 ? 0 0 ? 0 0 0 ? 0 ? 0 0 ? ? ? 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? 0 0 0 0 ? ? ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 0 0 ? 0 ? ? 0 0 0 ? 0 0 ? 0 ? 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? 0 ? 0 ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? ? 0 ? 0 ? 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? 0 ? 0 0 ? ? 0 ? 0 0 ? ? ? ? ? 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? 0 0 0 ? 1 ? ? ? ? 0 0 ? 0 ? 0 ? 0 0 ? ? ? 0 0 ? 0 0 ? 0 ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? 0 ? 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 ? 0 0 ? ? 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 ? 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 ? ? ? ? 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? ? ? 0 0 ? ? 0 0 0 ? ? 0 0 0 0 0 ? 0 0 ? 0 0 ? ? ? ? 0 ? 0 0 0 ? 0 ? 0 ? 0 0 0 0 ? 0 0 ? ? ? ? ? 0 ? 0 0 ? 0 0 ? 0 0 0 ? 0 0 ? ? ? 0 ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 ? ? 0 ? 0 0 ? 0 0 ? 0 ? ? ? 0 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 ? 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 ? ? 0 ? 0 0 0 ? ? 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 ? 0 ? 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 ? 0 0 ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? 0 0 ? ? 0 0 ? ? 0 ? 0 0 0 ? 0 0 0 ? 0 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 ? 0 ? ? 0 0 ? ? 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 ? ? ? ? 0 0 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? 0 ? 0 0 0 0 ? 0 0 ? ? 0 ? ? ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? x 0 0 ? 0 ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 ? ? 0 0 1 ? ? ? 0 ? 0 0 ? 0 0 0 ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? 0 0 ? ? ? ? 0 ? 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 ? ? ? 0 ? 0 ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 ? 0 ? 0 0 ? 0 ? 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? 0 0 ? ? 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 0 ? 0 ? 0 ? 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 ? ? 0 0 0 0 ? ? 0 ? ? ? ? ? ? 0 ? 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • BadJoke.LJ
  • Stealer.B
  • Stealer.BC
  • Stealer.BH
  • Stealer.BK
Show More
  • Stealer.BPD

Files Modified

File Attributes
c:\users\user\appdata\roaming\tencent\qqbrowser\setuplog\2026-09-15 00_55_15.log Generic Write,Read Attributes
c:\users\user\appdata\roaming\tencent\qqbrowser\setuplog\2026-09-15 22_09_25.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\appcompatflags\compatibility assistant::executablestoexclude c:\users\user\downloads\d4033bd554e06de41fe807cf0a9b41b21e1c2efb_0008323072 RegNtPreCreateKey
HKCU\software\microsoft\windows nt\currentversion\appcompatflags\compatibility assistant\persisted::c:\users\user\downloads\d4033bd554e06de41fe807cf0a9b41b21e1c2efb_0008323072  RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\appcompatflags\compatibility assistant::executablestoexclude c:\users\user\downloads\5201536a9ab4c8a697d00d3be3b65cdbbd21b8fe_0009109504 RegNtPreCreateKey
HKCU\software\microsoft\windows nt\currentversion\appcompatflags\compatibility assistant\persisted::c:\users\user\downloads\5201536a9ab4c8a697d00d3be3b65cdbbd21b8fe_0009109504  RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • ReadProcessMemory
Anti Debug
  • OutputDebugString