PUP.Wire VPN
The detection of PUP.Wire VPN on your system indicates the presence of a potentially unwanted program (PUP) that may compromise your privacy and security. PUPs are software applications that, while not necessarily malicious, can still cause significant disruptions to your computer's normal functioning and may expose you to various risks. Understanding what PUP.Wire VPN is, how it operates, and the symptoms it causes is crucial for effective removal and prevention of future infections.
Table of Contents
What Is PUP.Wire VPN?
PUP.Wire VPN is classified as a potentially unwanted program, which means it is a software application that you may not have intentionally installed or may not want on your computer. PUPs often get installed alongside other software you download from the internet, without your full knowledge or consent. They can range from adware that displays unwanted advertisements to programs that claim to offer useful services but actually provide little to no benefit while consuming system resources or collecting your personal data.
How PUP.Wire VPN Operates
PUPs like PUP.Wire VPN typically operate by integrating themselves into your system in a way that makes them difficult to detect and remove. They may alter your browser settings, install additional software without your permission, or even collect and transmit your personal data to third parties. The primary goal of many PUPs is to generate revenue for their developers through various means, such as displaying advertisements, selling your data, or offering fake updates or scareware that prompts you to pay for unnecessary services.
Symptoms of Infection
Symptoms of a PUP.Wire VPN infection can vary but commonly include an increase in unwanted advertisements, unexpected changes to your browser's homepage or search engine, slow system performance, and the presence of unfamiliar programs or toolbars in your browser or on your desktop. You might also notice that your web browser is being redirected to unwanted websites or that you are receiving pop-up ads even when your browser is closed. These symptoms indicate that your system has been compromised and requires immediate attention to remove the PUP and prevent further damage.
How to Remove PUP.Wire VPN
- Boot your computer in Safe Mode with Networking to prevent PUP.Wire VPN from loading and to give you a clean environment to work in.
- Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove all components of PUP.Wire VPN.
- Uninstall any suspicious programs that you do not recognize or that were installed around the time you first noticed symptoms of the infection.
- Reset your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, etc.) to their default settings to remove any changes made by PUP.Wire VPN.
- Reboot your computer and perform another scan with your anti-malware tool to ensure that all traces of PUP.Wire VPN have been removed.
Conclusion
Removing PUP.Wire VPN from your system is crucial to restoring your privacy and security. By following the steps outlined above and maintaining good computing practices, such as regularly updating your software, avoiding suspicious downloads, and using reputable security software, you can protect your system from PUPs and other types of malware. Remember, prevention is key, so always be cautious when downloading software from the internet and carefully read through any agreements or prompts during the installation process to avoid unintentionally installing unwanted programs.
Analysis Report
General information
| Family Name: | PUP.Wire VPN |
|---|---|
| Signature status: | Hash Mismatch |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
fa9ae2976de7c01e74a0c35982d4688d
SHA1:
4338b2849fff7b24a247115f24771401b4e63863
SHA256:
F2522C24CB8305432E2D160525F9516FAEDB1B381675F4D05AD1CB524C5EE80F
File Size:
8.62 MB, 8624600 bytes
|
|
MD5:
bbae36f39600ae44409e7b26c8117f0b
SHA1:
0980d794d50054d448ac6bf17cd91cb40b2e8cb7
SHA256:
8EBC5121ACF8A6F3371ECAB94961A67F8F6557B5EF8AB585D0729D396D9F4337
File Size:
3.64 MB, 3637208 bytes
|
|
MD5:
c0fa8b762f7044cdadc7adf4dedca1b2
SHA1:
af37f1b372a19c986864b4efd66e05c874297c29
SHA256:
52251865A0CFBA1152E9952BC4D3E089D12AEE1E74E4D60927E3E7D43EAD1478
File Size:
8.54 MB, 8539552 bytes
|
|
MD5:
0bc9f0d2828549a97363266f493dc471
SHA1:
a2c641e1c166b9e6ce2b6b6c7fdd259397a318e6
SHA256:
540FA0ACADA5A94C4520A35A768A22DA990F242D48D41A61DE5CD9AD0BEF7577
File Size:
3.64 MB, 3637208 bytes
|
|
MD5:
e2022cedcea9b5ea81764996732a9880
SHA1:
01ef636f9627a77ae11af9af88dd52106b163422
SHA256:
B7A7013B951C3CEA178ECE3363E3DD06626B9B98EE27EBFD7C161D0BBCFBD894
File Size:
350.17 KB, 350168 bytes
|
Show More
|
MD5:
ef7f2effb2d8975fd16b889f29910479
SHA1:
8c607cd8058b076bd3ad240a068f211d9b698c89
SHA256:
EFC560C65D1F00B602792D4ED59894F004A94BCBCB9AF26765AC1BA1AEB9A2F0
File Size:
8.62 MB, 8624600 bytes
|
|
MD5:
dc271bbe20f0dfb99e3c7b821aef690f
SHA1:
e166dd400514f03f17a9e46ea72edc8c70a29bd8
SHA256:
F9B58C0065DA39AF091943A62515A26A48C88BB9629C287F8E561ECD2320914E
File Size:
2.39 MB, 2391000 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File has exports table
- File has TLS information
- File is 32-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | upWire |
| File Description | Wirevpn |
| File Version |
|
| Internal Name | Wirevpn |
| Legal Copyright |
|
| Original Filename | Wirevpn.exe |
| Product Name |
|
| Product Version |
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| JOZEAL NETWORK TECHNOLOGY CO., LIMITED | GlobalSign | Root Not Trusted |
| WEILAI NETWORK TECHNOLOGY CO., LIMITED | GlobalSign | Root Not Trusted |
| WEILAI NETWORK TECHNOLOGY CO., LIMITED | GlobalSign | Hash Mismatch |
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 4,288 |
|---|---|
| Potentially Malicious Blocks: | 296 |
| Whitelisted Blocks: | 3,962 |
| Unknown Blocks: | 30 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- WireVPN.A
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Anti Debug |
|
| Network Winsock2 |
|
| Service Control |
|
| User Data Access |
|
| Encryption Used |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0980d794d50054d448ac6bf17cd91cb40b2e8cb7_0003637208.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a2c641e1c166b9e6ce2b6b6c7fdd259397a318e6_0003637208.,LiQMAxHB
|
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall delete rule name="upWire"
|
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall delete rule name="upWire"
|
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall add rule name="upWire" dir=out action=allow program="C:\Windows\SysWOW64\wire\upWire.exe"
|
Show More
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall add rule name="upWire" dir=out action=allow program="C:\Windows\SysWOW64\wire\upWire.exe"
|
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall add rule name="upWire" dir=in action=allow program="C:\Windows\SysWOW64\wire\upWire.exe"
|
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall add rule name="upWire" dir=in action=allow program="C:\Windows\SysWOW64\wire\upWire.exe"
|
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall delete rule name="wire"
|
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall delete rule name="wire"
|
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall add rule name="wire" dir=out action=allow program="C:\Windows\SysWOW64\wire\wire.exe"
|
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall add rule name="wire" dir=out action=allow program="C:\Windows\SysWOW64\wire\wire.exe"
|
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /c netsh advfirewall firewall add rule name="wire" dir=in action=allow program="C:\Windows\SysWOW64\wire\wire.exe"
|
C:\WINDOWS\system32\netsh.exe netsh advfirewall firewall add rule name="wire" dir=in action=allow program="C:\Windows\SysWOW64\wire\wire.exe"
|