PUP.Youxun

The detection of PUP.Youxun on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Youxun?

PUP.Youxun is a type of malware that is classified as a potentially unwanted program. This means that it is not necessarily a virus or a Trojan, but rather a program that may be installed on your system without your knowledge or consent. PUPs can be bundled with other software, downloaded from the internet, or installed through exploits in vulnerable applications. They often exhibit behavior that is annoying, intrusive, or potentially harmful, such as displaying unwanted ads, collecting personal data, or modifying system settings.

How PUP.Youxun Operates

Once installed, PUP.Youxun may operate in various ways, including displaying unwanted advertisements, collecting user data, or modifying system settings. It may also install additional components, such as toolbars, browser extensions, or other PUPs. In some cases, PUPs can be used to distribute more severe malware, such as viruses, Trojans, or ransomware. It's crucial to remove PUP.Youxun as soon as possible to prevent potential harm to your system and data.

Symptoms of Infection

Systems infected with PUP.Youxun may exhibit a range of symptoms, including unwanted pop-ups, slow system performance, and modified browser settings. You may also notice unfamiliar programs or toolbars installed on your system, or experience difficulties with browsing the internet. In some cases, PUPs can cause system crashes, freezes, or errors, making it essential to remove the infection to restore system stability.

  • Unwanted advertisements or pop-ups
  • Slow system performance or freezes
  • Modified browser settings or unfamiliar toolbars
  • Difficulty browsing the internet or accessing certain websites
  • System crashes or errors

How to Remove PUP.Youxun

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for internet access.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of PUP.Youxun.
  3. Uninstall any suspicious programs or applications that may be related to the PUP.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any modified settings or extensions.
  5. Reboot your system and perform a follow-up scan to ensure that all components of PUP.Youxun have been removed.

Conclusion

Removing PUP.Youxun from your system is crucial to preventing potential harm and restoring system stability. By following the steps outlined above, you can effectively remove the infection and prevent future occurrences. It's also essential to practice safe computing habits, such as avoiding suspicious downloads, using strong antivirus software, and keeping your operating system and applications up to date. By taking these precautions, you can help protect your system from PUPs and other types of malware, ensuring a safe and secure computing experience.

Analysis Report

General information

Family Name: PUP.Youxun
Signature status: Root Not Trusted

Known Samples

MD5: 6c991922aadc6ce9ec5f787b5c47cd87
SHA1: 76d5118a9ca410b880368ff5b05f955094155c4a
SHA256: 73228470CD7BA76E04FB19C5BFD6584772BDF0D5B77E772FC4F01929F88860A0
File Size: 1.47 MB, 1465728 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name 昆山悦趣信息科技有限公司
File Description 602全民红月
File Version 10.18.23.457
Internal Name 602全民红月
Legal Copyright Copyright (c) 2024 昆山悦趣信息科技有限公司
Original Filename 602全民红月
Product Name 602全民红月
Product Version 10.18.23.457

Digital Signatures

Signer Root Status
昆山悦趣信息科技有限公司 AAA Certificate Services Root Not Trusted

Block Information

Total Blocks: 4,839
Potentially Malicious Blocks: 71
Whitelisted Blocks: 3,167
Unknown Blocks: 1,601

Visual Map

? ? ? 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? x 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 x ? ? 0 0 ? ? 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? x 0 ? 0 ? 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 ? 0 0 ? ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 ? x 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 x 0 x 0 x 0 x 0 0 x 0 x 0 x 0 0 x 0 x x 0 ? x ? x 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 x x x x x x 0 ? ? 0 0 ? x x 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 ? 0 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 ? ? ? 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? ? ? 0 ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 1 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 0 0 0 ? ? ? 0 0 ? 0 0 0 0 0 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? 0 ? 0 0 ? ? 0 0 ? ? 0 ? ? ? 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? ? ? 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? 0 0 ? ? 0 ? ? ? ? ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 x 0 0 ? ? ? ? 0 0 0 0 ? ? ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? 0 ? 0 ? ? ? 0 ? 0 0 ? 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x ? ? ? 0 0 ? x 0 x ? x 0 0 ? ? 0 ? ? 0 ? 0 0 0 0 ? ? ? ? ? 0 ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? 0 0 0 ? 0 0 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 ? 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 ? ? 0 ? 0 0 0 0 0 ? ? 0 ? 0 ? 0 ? ? ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? 0 0 ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? ? ? 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 ? ? ? ? 0 ? 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 ? 0 ? ? ? ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 ? ? 0 ? 0 0 ? ? ? 0 0 ? 0 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 ? 0 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 ? ? ? ? 0 ? ? ? 0 0 0 0 ? 0 ? 0 0 ? 0 ? ? 0 ? 0 ? ? ? 0 ? ? 1 1 0 ? 0 ? ? 0 ? 0 0 ? ? 0 0 ? 0 ? ? ? 0 0 ? ? 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 ? 0 0 ? 0 0 ? ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? ? 0 ? ? ? ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\602games\qmhy_temps\2026-07-15log\20260715_162139run.log Generic Write,Read Attributes

Trending

Most Viewed

Loading...