PUP.Ypack.G

The detection of PUP.Ypack.G on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is PUP.Ypack.G?

PUP.Ypack.G is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in the classical sense but can still cause problems for users. PUPs can be installed on a system without the user's knowledge or consent, often through bundled software installations or deceptive download practices. They can display unwanted advertisements, collect user data, or modify system settings, leading to a range of issues.

How PUP.Ypack.G Operates

Once installed, PUP.Ypack.G can operate in various ways, depending on its intended purpose. It may display pop-up advertisements, alter search engine results, or redirect users to unwanted websites. In some cases, PUPs can also collect user data, such as browsing history or personal information, which can be used for targeted advertising or other malicious purposes. Understanding how PUP.Ypack.G operates is crucial in developing an effective removal strategy.

Symptoms of Infection

Systems infected with PUP.Ypack.G may exhibit a range of symptoms, including unwanted advertisements, slow system performance, and unexpected changes to browser settings or homepage redirects. Users may also notice an increase in pop-up windows or find that their search results are being redirected to unfamiliar websites. In some cases, the presence of PUP.Ypack.G may not be immediately apparent, making it essential to regularly scan your system for potential threats.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Changes to browser settings or homepage redirects
  • Increased risk of additional malware infections

How to Remove PUP.Ypack.G

  1. Boot your system in Safe Mode with Networking to prevent PUP.Ypack.G from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of PUP.Ypack.G.
  3. Uninstall any suspicious programs that may have been installed without your knowledge or consent, as these could be related to the PUP infection.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any changes made by PUP.Ypack.G and to ensure that your browsing experience is secure and free from unwanted interruptions.
  5. Reboot your system and perform another scan to ensure that all components of PUP.Ypack.G have been successfully removed.

Conclusion

Removing PUP.Ypack.G from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good computer hygiene practices, such as regularly updating your operating system and software, using strong antivirus programs, and being cautious when downloading and installing new software, you can protect your system from PUPs and other types of malware. Remember, prevention is key, and staying informed about the latest threats and how to mitigate them is crucial in the ongoing battle against cyber threats.

Analysis Report

General information

Family Name: PUP.Ypack.G
Signature status: Root Not Trusted

Known Samples

MD5: a60fdf3e7f210df8bcf88ada72ea4d37
SHA1: 6ee3a987da24315e7c55c9ff553dfcccd4b30dde
SHA256: 7A0E69DFAFF537A07A35DC175BFB97E7C1CE6821FBF9F60425F17128E7DCE5EA
File Size: 1.67 MB, 1669272 bytes
MD5: e5bd37f0959c7dafcef38b3c6008426c
SHA1: 25967bf79c0d97b71e3574507585366cbe45e6d1
SHA256: 0DACE7DB029DAD76F265330BB7FB761495380A05A5251C48FF67B92967AE5824
File Size: 1.53 MB, 1527600 bytes
MD5: 6a52a1209ea9d89fd06ebb5d8e32a4f3
SHA1: 301ed962cdc0312fd27d862762de31adf415671b
SHA256: 3C2E345182EEDBA58A95DCA6C98F86FC87A760A9BD6C9E5F85659618966420A7
File Size: 1.53 MB, 1532080 bytes
MD5: 3f02d4ebe6f56417745fe92ab4573c3e
SHA1: f3ef218c6f167e35d7e10f5ab522935cc3dd65ec
SHA256: 7B31E908A3CE2FAC394BC1F42B92304A6622A06600A015014E20C69D780345BE
File Size: 1.53 MB, 1528496 bytes
MD5: a0f5c561bf1352a746f344b0afc0c928
SHA1: e3149d5a68fb50e6ee6ebf3e7d30286284243927
SHA256: 76776C2B3F883EA7DB831173D39278E3EF50882BBC2D54F75B3C724CC632B1FB
File Size: 4.02 MB, 4021912 bytes
Show More
MD5: d49437077108b9913656b1245a9ea0c1
SHA1: e5138c14ac71593b73c883cb26c8ec3eddcd6266
SHA256: 00F39BF6E50A1ECC3453BCE0C5A2ABA3C4FB6CD0E8F55BAAC6B07BA255E2D020
File Size: 4.06 MB, 4056240 bytes
MD5: e10a54618e55f01a41d7a92082cd23e9
SHA1: 56b0306b67f5265536dfdc7db0a582c24aa7fe47
SHA256: 64608681CEA537A4189B89FE6F0B9E5068D6D3F70C0DB3102829E0DE171E8253
File Size: 1.61 MB, 1609904 bytes
MD5: a798d32210517deba0f1fb20133e09bd
SHA1: 716844ed935658ad0d2d7bde2e6e8876b5d18525
SHA256: 1B7ADB7780330A885EFD753D24BA370B51CF0DB9E147850B6D4426C72EC45E58
File Size: 3.34 MB, 3340464 bytes
MD5: ec6af83913e16eeb8dd1dc696bcb15e7
SHA1: 06b76cb7955a946745315cea659a8171bd3b3792
SHA256: 206DFE5CA54429F3717983BE5FA9D5A20A6E5F3438D18FAC64687F282E44D1F9
File Size: 4.16 MB, 4160672 bytes
MD5: 4f467cf6958005f41600740c023287e7
SHA1: 436d8e9f0c74b383086dab8ac616b762f0478abb
SHA256: B244E62D93F443F97AA030C0206BD15E02C8175767C847ED40290FF49C2A7EAA
File Size: 3.99 MB, 3986096 bytes
MD5: e7bff0dd17bb226cf8c05845d33b794b
SHA1: 4aecf575b06537d8a72368a4e94500d6b933908c
SHA256: D49009E9BF319B46B30BCDD8F9AE7B118603A9526CEA10404EEDF9ED44C9C06C
File Size: 3.30 MB, 3297456 bytes
MD5: e3fffb071ce80b5568c3abe06444c72d
SHA1: bf3bb0965d78b64c9ed462f67e180707f7cb9ddd
SHA256: A12F34C3B345447B3809B7B8BE0A6DB9123B5EE408FB4BC7038C6CDE904DE67A
File Size: 2.39 MB, 2389680 bytes
MD5: 6d9b57f862ea6091f88d958cffe2a36d
SHA1: a751a5201691cdf7fca227215ba64af435f4b2a9
SHA256: C20B4F030394D55D8E866262E43A390AD46BB5340318D9D1DD08A598C6D5FDB3
File Size: 1.51 MB, 1512112 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name YANDEX LLC
Company Short Name YANDEX LLC
File Description
  • @PRODUCT_FILE_DESCRIPTION@
  • Yandex
File Version
  • 25.2.4.954
  • 25.2.3.808
  • 24.12.3.780
  • 24.10.4.927
  • 24.10.4.850
  • 24.10.1.599
  • 24.7.2.1100
  • 24.6.4.582
  • 24.6.1.768
  • 24.4.4.1169
Show More
  • 23.11.0.2472
  • 23.5.3.918
Internal Name
  • @INTERNAL_NAME@
  • notification_helper_exe
  • setup
Last Change
  • 9b32803ea2d305cd87dd8af7b47fa56e870c767e
  • 078d1ebfcba7a22d6ec2f7e39669e84988cd37e2
  • 500ec94cb1e04153e64f10d9eebb4e28fe70fd79
  • 701f3abe30bd0dd4f8e0c921c03d41893ea3f6dd
  • 918f6c64d7e1fda0d7c2a3184e7d32df3735d90d
  • 7639b62e06fe54628306eb626e3898aa877d3479
  • 663571e13fadae5ce98627cd88eef0240de7052d
  • 06675302fd9ccd703b40fe9fd3a7732e9a898559
  • a041fd2d75d29596caf491d9372182e5e185d7c6
  • be527d27a3113e4e91b22bd093ad83f65539be98
Show More
  • cdc2d6fcf846c30ea88ce7f10ef9bae5ecacf9ef
  • ff102d7073a0b4af5e2b046265a6da8ef562a423
Legal Copyright
  • Copyright (c) 2012-2023 YANDEX LLC. All Rights Reserved.
  • Copyright (c) 2012-2024 YANDEX LLC. All Rights Reserved.
  • Copyright (c) 2012-2025 YANDEX LLC. All Rights Reserved.
Official Build 1
Original Filename notification_helper.exe
Product Chromium Version
  • 130.0.6723.170
  • 128.0.6613.186
  • 126.0.6478.234
  • 124.0.6367.243
  • 118.0.5993.144
  • 112.0.5615.204
Product Name Yandex
Product Short Name Yandex
Product Version
  • 25.2.4.954
  • 25.2.3.808
  • 24.12.3.780
  • 24.10.4.927
  • 24.10.4.850
  • 24.10.1.599
  • 24.7.2.1100
  • 24.6.4.582
  • 24.6.1.768
  • 24.4.4.1169
Show More
  • 23.11.0.2472
  • 23.5.3.918
Product Yandex Version
  • 25.2.4.954
  • 25.2.3.808
  • 24.12.3.780
  • 24.10.4.927
  • 24.10.4.850
  • 24.10.1.599
  • 24.7.2.1100
  • 24.6.4.582
  • 24.6.1.768
  • 24.4.4.1169
Show More
  • 23.11.0.2472
  • 23.5.3.918

Digital Signatures

Signer Root Status
YANDEX LLC GlobalSign Code Signing Root R45 Root Not Trusted
YANDEX LLC GlobalSign GCC R45 EV CodeSigning CA 2020 Self Signed

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Version
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 4,276
Potentially Malicious Blocks: 24
Whitelisted Blocks: 3,673
Unknown Blocks: 579

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 ? ? ? 0 0 0 0 ? 0 ? 1 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? ? 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 ? ? ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 1 ? 0 0 0 ? 0 ? ? 0 0 0 ? ? 0 0 0 ? x x ? ? ? 0 1 0 0 0 0 0 ? 0 ? ? 0 0 0 ? ? 0 ? 0 0 ? 0 0 0 0 ? ? ? ? 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 ? 0 0 ? 0 ? 0 ? ? 0 ? ? ? 0 0 0 0 ? 0 ? 0 0 0 ? ? ? 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 ? 0 0 ? 0 ? ? 0 0 ? 0 0 ? 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 x x 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 1 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? ? ? ? ? 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 1 0 1 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 0 ? ? 0 0 ? ? 0 ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 ? 0 ? ? 0 0 ? ? 0 ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 0 0 0 ? ? 0 ? 0 0 ? 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? 0 0 0 ? 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 ? ? ? 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? ? ? 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? ? ? 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? ? ? 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 0 0 0 0 ? ? 0 ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? x ? 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 x 0 0 ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 1 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\program files (x86) Read Attributes,Synchronize,Write Data
c:\programdata\yandex\yandexbrowser\service_update.log Read Attributes,Synchronize,Append data
c:\users\user\appdata\local\temp\yandex_browser_installer.log Read Attributes,Synchronize,Append data
c:\users\user\downloads\yandex_browser_installer.log Read Attributes,Synchronize,Append data
c:\windows\systemtemp Read Attributes,Synchronize,Write Data

Registry Modifications

Key::Value Data API Name
HKCU\software\yandex\yandexbrowser::ap RegNtPreCreateKey

Related Posts

Trending

Most Viewed

Loading...