Downloader.Adload.Win32.22762

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Downloader.Adload.Win32.22762 also known as Trojan.Exception.gen.101.

Malware Analysis of Downloader.Adload.Win32.22762 – PICASACD.EXE

Created files:

%Program Files%\Google\Picasa3\cdautorun\Picasa Restore.app\Contents\Resources\zh_TW.lproj\PRMainMenu.nib\info.nib
%Program Files%\Google\Picasa3\cdautorun\Picasa Restore.app\Contents\Resources\zh_TW.lproj\PRMainMenu.nib\keyedobjects.nib
%Program Files%\Google\Picasa3\cdautorun\PicasaCD.exe
%Program Files%\Google\Picasa3\cdautorun\PicasaRestore.exe
%Program Files%\Google\Picasa3\GPAutoBackup_Setup.exe

Autostart registry keys:

HKLM\Software\Classes\Applications\PicasaPhotoViewer.exe\Shell\Open\Command\: “”%Program Files%\Google\Picasa3\PicasaPhotoViewer.exe” “%1″”
HKLM\Software\Classes\Applications\PicasaPhotoViewer.exe\Shell\Preview\Command\: “”%Program Files%\Google\Picasa3\PicasaPhotoViewer.exe” “%1″”
HKLM\Software\Classes\Applications\PicasaPhotoViewer.exe\Shell\Open\FriendlyAppName: “Picasa Photo Viewer”
HKLM\Software\Classes\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}\LocalServer32\: “”%Program Files%\Google\Common\Google Updater\GoogleUpdaterService.exe””
HKLM\Software\Classes\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}\LocalServer32\: “”%Program Files%\Google\Common\Google Updater\GoogleUpdaterService.exe””
HKLM\Software\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C}\InprocServer32\: “%Program Files%\PC Speed Up\PCSUHelper.dll”
HKLM\Software\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268}\InprocServer32\: “%Program Files%\PC Speed Up\PCSUHelper.dll”
HKLM\Software\Classes\Google.PhotoViewer.3.0\Shell\Open\Command\: “”%Program Files%\Google\Picasa3\PicasaPhotoViewer.exe” “%1″”
HKLM\Software\Classes\picasa\shell\open\command\: “”%Program Files%\Google\Picasa3\Picasa3.exe” “%1″”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1\DisplayName: “PC Speed Up”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1\UninstallString: “”%Program Files%\PC Speed Up\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Picasa 3\DisplayName: “Picasa 3”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Picasa 3\UninstallString: “”%Program Files%\Google\Picasa3\Uninstall.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F8FE0A54-D938-4647-A37A-7B98A0D1BBE0}\UninstallString: “rundll32.exe “%Program Files%\Esuyjojeght\esysystem.dll”,u “/k={F8FE0A54-D938-4647-A37A-7B98A0D1BBE0}””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F8FE0A54-D938-4647-A37A-7B98A0D1BBE0}\DisplayName: “yessearches – Uninstall”
HKLM\System\CurrentControlSet\services\coollevalalyconfigurationService\ImagePath: “”%Program Files%\Coollevalaly\coollevalalyconfigurationService.html5″ {79740E79-A383-47A7-B513-3DF6563D007F} {8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}”
HKLM\System\CurrentControlSet\services\coollevalalyconfigurationService\DisplayName: “Coollevalaly Configuration”
HKLM\System\CurrentControlSet\services\gusvc\ImagePath: “”%Program Files%\Google\Common\Google Updater\GoogleUpdaterService.exe””
HKLM\System\CurrentControlSet\services\gusvc\DisplayName: “Google Updater Service”
HKLM\System\CurrentControlSet\services\PCSUService\ImagePath: “%Program Files%\PC Speed Up\PCSUService.exe”
HKLM\System\CurrentControlSet\services\PCSUService\DisplayName: “PC Speed Up Service”
HKLM\System\CurrentControlSet\services\SCService\ImagePath: “”%Program Files%\PC Speed Up\SpeedCheckerService.exe””
HKLM\System\CurrentControlSet\services\SCService\DisplayName: “SpeedChecker Service”
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\PCSpeedUp: “%Program Files%\PC Speed Up\PCSUNotifier.exe”

Detected by UnHackMe:

PICASACD.EXE
Default location: %PROGRAM FILES%\GOOGLE\PICASA3\CDAUTORUN\PICASACD.EXE

Dropper hash(md5): 259694a9a1a3b6aaf8c007dc545b276f

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

1
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera