PUP.SpywareCease

The detection of PUP.SpywareCease on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your privacy and security. This type of threat is designed to collect and transmit sensitive information about your browsing habits, personal data, and system configuration to third-party servers. It is essential to take immediate action to remove PUP.SpywareCease and prevent further damage to your system and data.

What Is PUP.SpywareCease?

PUP.SpywareCease is a type of malware that falls under the category of potentially unwanted programs (PUPs). These programs are often bundled with free software downloads or installed through deceptive means, such as fake updates or misleading advertisements. Once installed, PUP.SpywareCease can collect and transmit sensitive information, display unwanted advertisements, and compromise your system's performance and security.

How PUP.SpywareCease Operates

PUP.SpywareCease operates by infiltrating your system and gathering information about your browsing habits, search queries, and personal data. This information can be used to create targeted advertisements, sell to third-party companies, or even stolen for identity theft. The malware may also install additional components, such as toolbars, browser extensions, or system services, to further compromise your system. In some cases, PUP.SpywareCease may also attempt to connect to remote servers to receive updates, transmit data, or download additional malware.

Symptoms of Infection

The symptoms of PUP.SpywareCease infection may vary, but common indicators include unwanted advertisements, pop-ups, and browser redirects. You may also notice a decrease in system performance, slow browser loading times, and unfamiliar programs or toolbars installed on your system. In some cases, you may receive fake alerts, warnings, or messages claiming that your system is infected or that you need to update your software. It is essential to be cautious when encountering these symptoms, as they may be attempts by the malware to trick you into installing additional threats or providing sensitive information.

How to Remove PUP.SpywareCease

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and interfering with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove PUP.SpywareCease and any related components.
  3. Uninstall any suspicious programs or applications that may be related to the malware, using the Windows Control Panel or Settings app.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions, toolbars, or settings.
  5. Reboot your system and perform an additional scan to ensure that all components of PUP.SpywareCease have been removed.

Conclusion

Removing PUP.SpywareCease from your system requires careful attention to detail and a comprehensive approach. By following the steps outlined above, you can effectively remove the malware and prevent further damage to your system and data. It is essential to remain vigilant and take proactive measures to protect your system from future threats, such as keeping your software up-to-date, using strong antivirus protection, and being cautious when downloading and installing software from the internet.

Analysis Report

General information

Family Name: PUP.SpywareCease
Signature status: Self Signed

Known Samples

MD5: 293db11205b40e159950f1860cab6ff3
SHA1: e90d90c534bb7de91fd7ed9dd67d08d8c60b7f92
File Size: 8.42 MB, 8419368 bytes
MD5: e684596dd0aeda719217e9aa1298dcf5
SHA1: c809ae6700ab882505cb70f0f29bad54d91b91ed
SHA256: 3B4E99BAE7A002E7235A465ACCBFDED160093516CE6A94BFA07B33613E48B698
File Size: 4.45 MB, 4448832 bytes
MD5: 59f30eb3746748edafc98bf6a407a5da
SHA1: f203b093145568f1389add3d0466234b15c5f85d
SHA256: 73BA2B7BEFABA592B4F87C7DF73060F23D12AEF6DB7871CB52A53B3960759606
File Size: 3.32 MB, 3317608 bytes
MD5: 98b224cca6b4e5c938ad074a79a03f43
SHA1: 05fead593aea3c7f961ca0a747cb2f5b215004e7
SHA256: 0693A9CBE022A2F0EBF8F653EBC356E135CA6B08FB6CE20F11FED5A0469C466D
File Size: 3.49 MB, 3485888 bytes
MD5: 36198447464c704e07c36a11e81106ad
SHA1: cb13de707910d6f7d644b20e1299caf3f1f852bc
SHA256: F656668BA1782390E862347E8EDA9CEB75670930F52C21EC7627018A60A474C1
File Size: 2.45 MB, 2449272 bytes
Show More
MD5: ac6d5d50cb85fbdbacc2d9483e9df116
SHA1: 444f38cd92a799a4fbec354791b30a79b0d327d8
SHA256: 84052C6933CA5147F7AFFD8E04DB2C144508A5F56F37015984A60752C70C9622
File Size: 3.46 MB, 3459736 bytes
MD5: a89074ca1f13b9747d956233e03bf4fc
SHA1: 41af44cdcf90572b8d1ac176bed36204d8a38b33
SHA256: 1F4FC49D554AAFCE169238F0B163B4C0CDE5C3D347052217960A939B037C823F
File Size: 3.64 MB, 3636024 bytes
MD5: eb60475d66b052538fe1600c1ffc2a90
SHA1: 2216f46010fa2560f51389f663c1161426635dc5
SHA256: AF7D45674E1E32A9E62407FF50ECAA2ECC210C5C3BA1F7916969810E2D25587A
File Size: 6.07 MB, 6072584 bytes
MD5: 48af80ee4036505c1b10312587f8bd29
SHA1: 1711b4e3bfb125b3cf2e8eec4bcc055983f1e291
SHA256: 4487D543F89EC9E69F8698DAACE0545E4F18B9D7592E682CB73921A18081BD4E
File Size: 721.18 KB, 721178 bytes
MD5: caff35e175e7aff84db8dbd9f3a96f8b
SHA1: 8ed1045f5c32584d6e2f47df7fd244e2cadca228
SHA256: 35854D6E616247AC4B81B8FE478744FBDEDD8EFEE0128ADE01E1EFEA608A2385
File Size: 1.14 MB, 1138392 bytes
MD5: 4ccbf383702505df52442388de44335c
SHA1: 96c503993542e054382d05be1300ac24bbac4ac2
SHA256: 3A0CDD6DFF37025B6243F119E840A9B5B68BC0BD79A30E1B2E1504BCC897B010
File Size: 5.83 MB, 5833504 bytes
MD5: 92ffd0293f7058074d470259169a30bd
SHA1: 73c28a1891431302b31380034edf09cc565a9c0f
SHA256: FFE1CE97752025AC175E01BA7B8DCB8079F3E532810A331B07BE715855B5951F
File Size: 4.97 MB, 4966696 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Comments
  • This installation was built with Inno Setup.
Company Name
  • CheeseSoft Inc.
  • driverchecker.com, Inc.
  • DriverChecker.com, Inc.
  • RegistryEasy, Inc.
  • www.bestuninstalltool.com
  • www.PerfectUninstaller.com
  • www.PerfectUninstaller.net
File Description
  • Best Uninstall Tool Setup
  • Driver Checker Setup
  • Perfect Uninstaller Setup
  • Registry Easy Setup
  • Setup/Uninstall
File Version
  • 51.49.0.0
  • 6.3.3.9
  • 6.3.3.6
  • 5.6
  • 4.9
  • 3.7
  • 2.7.4
  • 2.7.3
Legal Copyright
  • Copyright (C) 2006-2009 PerfectUninstaller.net, Inc.
  • Copyright (C) 2006-2009 RegistryEasy.com, Inc.
  • Copyright (C) 2006-2010 CheeseSoft Inc. All reghts reserved
  • Copyright (C) 2006-2011 Best Uninstall Tool, Inc.
  • Copyright (C) 2006-2011 Perfect Uninstaller, Inc.
  • Copyright (C) 2006-2012 Perfect Uninstaller, Inc.
  • Copyright (C) 2007 Perfect Uninstaller, Inc.
  • Copyright (C) 2007-2008 ACAUtilities.com, Inc.
  • Copyright (C) 2007-2008 DriverChecker.com, Inc.
Product Name
  • Best Uninstall Tool
  • Driver Checker
  • Perfect Uninstaller
  • Registry Easy
Product Version
  • 6.3.3.9
  • 6.3.3.6
  • 5.6
  • 4.9
  • 2.7.4
  • 2.7.3

Digital Signatures

Signer Root Status
Qiwang Computer Class 3 Public Primary Certification Authority Root Not Trusted
Qiwang Computer VeriSign Class 3 Code Signing 2004 CA Self Signed
Guangxi Nanning Qiwang Co. Ltd. VeriSign Class 3 Code Signing 2010 CA Self Signed

File Traits

  • Inno
  • Installer Manifest
  • Installer Version
  • x86

Block Information

Similar Families

  • Dropper.Delf.CF
  • Injector.AJA
  • Injector.KPD
  • Morto.B
  • Softcnapp.N
Show More
  • Trojan.Kryptik.Gen.EZ

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-03ohn.tmp\_isetup\_regdll.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-03ohn.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-03ohn.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-5hp98.tmp\73c28a1891431302b31380034edf09cc565a9c0f_0004966696.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-5kv69.tmp\e90d90c534bb7de91fd7ed9dd67d08d8c60b7f92_0008419368.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-at3ka.tmp\96c503993542e054382d05be1300ac24bbac4ac2_0005833504.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-henca.tmp\_isetup\_regdll.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\is-henca.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-henca.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-nnr3v.tmp\8ed1045f5c32584d6e2f47df7fd244e2cadca228_0001138392.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-tsg5j.tmp\_isetup\_regdll.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-tsg5j.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-tsg5j.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation

Shell Command Execution

"C:\Users\Veibjejo\AppData\Local\Temp\is-5KV69.tmp\e90d90c534bb7de91fd7ed9dd67d08d8c60b7f92_0008419368.tmp" /SL5="$50062,8142380,57856,c:\users\user\downloads\e90d90c534bb7de91fd7ed9dd67d08d8c60b7f92_0008419368"
"C:\Users\Xtebxiqw\AppData\Local\Temp\is-NNR3V.tmp\8ed1045f5c32584d6e2f47df7fd244e2cadca228_0001138392.tmp" /SL5="$1103AC,832782,73728,c:\users\user\downloads\8ed1045f5c32584d6e2f47df7fd244e2cadca228_0001138392"
"C:\Users\Fvfvjxte\AppData\Local\Temp\is-AT3KA.tmp\96c503993542e054382d05be1300ac24bbac4ac2_0005833504.tmp" /SL5="$230162,5538848,78848,c:\users\user\downloads\96c503993542e054382d05be1300ac24bbac4ac2_0005833504"
"C:\Users\Vhbrtxkk\AppData\Local\Temp\is-5HP98.tmp\73c28a1891431302b31380034edf09cc565a9c0f_0004966696.tmp" /SL5="$20506,4674376,78848,c:\users\user\downloads\73c28a1891431302b31380034edf09cc565a9c0f_0004966696"