Home Possibly Unwanted Program PUP.Ghostify

PUP.Ghostify

Posted: February 8, 2017

Threat Metric

Ranking: 12,478
Threat Level: 1/10
Infected PCs: 4,028
First Seen: February 8, 2017
Last Seen: September 5, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\czPEyLGbQ2qd Updater\czPEyLGbQ2qd Updater.exe File name: czPEyLGbQ2qd Updater.exe
Size: 313.34 KB (313344 bytes)
MD5: 180272457b847db4c184196fa96f4b65
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\czPEyLGbQ2qd Updater
Group: Malware file
Last Updated: February 14, 2017
%PROGRAMFILES(x86)%\zPhckCNZm3Jw Updater\zPhckCNZm3Jw Updater.exe File name: zPhckCNZm3Jw Updater.exe
Size: 313.34 KB (313344 bytes)
MD5: acb7dbccfd61c9c31cc349fa9c4b6707
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\zPhckCNZm3Jw Updater
Group: Malware file
Last Updated: February 14, 2017
%PROGRAMFILES%\GTFPOQUOTT Updater\GTFPOQUOTT Updater.exe File name: GTFPOQUOTT Updater.exe
Size: 313.34 KB (313344 bytes)
MD5: 0e9fb430d6b9eb1d033d1fdfca860b22
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\GTFPOQUOTT Updater
Group: Malware file
Last Updated: February 14, 2017
C:\Windows\Temp\EEBF.tmp File name: EEBF.tmp
Size: 1.23 MB (1230978 bytes)
MD5: 0d21122df118e0651647d63e49e20551
Detection count: 5
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Windows\Temp\EEBF.tmp
Group: Malware file
Last Updated: January 19, 2021

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\System32\Tasks\GTFPOQUOTT%WINDIR%\System32\Tasks\GTFPUUKOLIIHKEY..\..\..\..{RegistryKeys}SOFTWARE\GTFPOQUOTT UpdaterSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GTFPUUKOLIISOFTWARE\Wow6432Node\GTFPOQUOTT UpdaterSYSTEM\ControlSet001\services\GTFPOQUOTT UpdaterSYSTEM\ControlSet002\services\GTFPOQUOTT UpdaterSYSTEM\CurrentControlSet\services\GTFPOQUOTT UpdaterHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}GTFPOQUOTT Updater_is1

Additional Information

The following directories were created:
%PROGRAMFILES%\GTFPUUKOLII%PROGRAMFILES(x86)%\GTFPUUKOLII%ProgramFiles%\GTFPOQUOTT%ProgramFiles%\GTFPOQUOTT Updater%ProgramFiles(x86)%\GTFPOQUOTT%ProgramFiles(x86)%\GTFPOQUOTT Updater
Loading...