Program.Unwanted.1393

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Malware Analysis of Program.Unwanted.1393 – SITERANK.DLL

Created files:

%Program Files%\RebateInformer\unins000.exe
%Program Files%\RebateInformer\unins000.msg
%Program Files%\SiteRanker\SiteRank.dll
%Program Files%\SiteRanker\SiteRankTray.exe
%Program Files%\SiteRanker\siterank_ff.cab

Autostart registry keys:

HKLM\Software\Classes\CLSID\{042DA63B-0933-403D-9395-B49307691690}\InprocServer32\: “%Program Files%\Inbox Toolbar\Inbox.dll”
HKLM\SOFTWARE\CLASSES\CLSID\{0CD282C1-FDBE-4AD5-95F2-85E4474432EC}\INPROCSERVER32\: “%SYSTEMDRIVE%\PROGRA~1\SITERA~1\SITERANK.DLL”
HKLM\SOFTWARE\CLASSES\CLSID\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}\INPROCSERVER32\: “%SYSTEMDRIVE%\PROGRA~1\SITERA~1\SITERANK.DLL”
HKLM\SOFTWARE\CLASSES\CLSID\{37540F19-DD4C-478B-B2DF-C19281BCAF27}\INPROCSERVER32\: “%SYSTEMDRIVE%\PROGRA~1\INBOXT~1\INBOX.DLL”
HKLM\Software\Classes\CLSID\{612AD33D-9824-4E87-8396-92374E91C4BB}\LocalServer32\: “%Program Files%\Inbox Toolbar\Inbox.exe”
HKLM\SOFTWARE\CLASSES\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}\INPROCSERVER32\: “%SYSTEMDRIVE%\PROGRA~1\APPGRA~1\APPGRA~1.DLL”
HKLM\Software\Classes\CLSID\{865D7100-82C7-42F4-9C06-860DEC0871B2}\InprocServer32\: “%Program Files%\24x7Help\24x7desk.dll”
HKLM\SOFTWARE\CLASSES\CLSID\{AF808758-C780-404C-A4EE-4526323FD9B6}\INPROCSERVER32\: “%SYSTEMDRIVE%\PROGRA~1\REBATE~1\REBATEI.DLL”
HKLM\SOFTWARE\CLASSES\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}\INPROCSERVER32\: “%SYSTEMDRIVE%\PROGRA~1\APPGRA~1\APPGRA~1.DLL”
HKLM\SOFTWARE\CLASSES\CLSID\{CCB69577-088B-4004-9ED8-FF5BCC83A039}\INPROCSERVER32\: “%SYSTEMDRIVE%\PROGRA~1\REBATE~1\REBATEI.DLL”
HKLM\Software\Classes\CLSID\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}\InprocServer32\: “%Program Files%\Inbox Toolbar\Inbox.dll”
HKLM\Software\Classes\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}\InprocServer32\: “%Program Files%\Inbox Toolbar\Inbox.dll”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\InboxToolbar: “”%Program Files%\Inbox Toolbar\Inbox.exe” /STARTUP”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\24x7HELP: “”%Program Files%\24x7Help\App24x7Help.exe” /STARTUP”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SiteRanker: “”%Program Files%\SiteRanker\SiteRankTray.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\PCPowerSpeed: “”%Program Files%\PCPowerSpeed\PCPowerTray.exe” /startup”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\AppGraffiti: “”%Program Files%\AppGraffiti\AppGraffiti.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}_is1\DisplayName: “SiteRanker”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}_is1\UninstallString: “”%Program Files%\SiteRanker\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}_is1\DisplayName: “RebateInformer”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}_is1\UninstallString: “”%Program Files%\RebateInformer\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{612AD33D-9824-4E87-8396-92374E91C4BB}_is1\DisplayName: “Inbox Toolbar”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{612AD33D-9824-4E87-8396-92374E91C4BB}_is1\UninstallString: “”%Program Files%\Inbox Toolbar\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1\DisplayName: “AppGraffiti”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1\UninstallString: “”%Program Files%\AppGraffiti\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1\DisplayName: “24×7 Help”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1\UninstallString: “”%Program Files%\24x7Help\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1\DisplayName: “PC Power Speed 2.1.0.108”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B0C56FD7-493D-44DD-B007-BBB5117D6E6F}_is1\UninstallString: “”%Program Files%\PCPowerSpeed\unins000.exe””
HKLM\System\CurrentControlSet\services\24x7HelpSvc\ImagePath: “%Program Files%\24x7Help\App24x7Svc.exe”
HKLM\System\CurrentControlSet\services\24x7HelpSvc\DisplayName: “24x7HelpService”

Detected by UnHackMe:

SITERANK.DLL
Default location: %PROGRAM FILES%\SITERANKER\SITERANK.DLL

Dropper hash(md5): f90ebbd0da8ce3dde2a70a5b78435e88

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

4
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera