PUA.Illyx

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

PUA.Illyx also known as Adware.BL, Trojan.Generic-HQNETrBIFpL (cloud), Adware ( 004ae5231 ).

Malware Analysis of PUA.Illyx – ~KSHXWPL.EXE

Created files:

%APPDATA%\MOZILLA\FIREFOX\PROFILES\J3CZWNGH.DEFAULT\DATAREPORTING\ARCHIVED\2016-12\1481190944457.4BDF130F-3401-4E8A-A8EC-E6D22EB6AD14.MAIN.JSONLZ4
%APPDATA%\MOZILLA\FIREFOX\PROFILES\J3CZWNGH.DEFAULT\SAVED-TELEMETRY-PINGS\4BDF130F-3401-4E8A-A8EC-E6D22EB6AD14
%APPDATA%\~KSHXWPL.EXE
%PROFILE%\DESKTOP\MYPC BACKUP.LNK
%SYSDIR%\TASKS\LAUNCHPRESIGNUP

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\OLBPre\DisplayName: “MyPC Backup ”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\OLBPre\UninstallString: “%Program Files%\OLBPre\uninst.exe”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Webplayer\UninstallString: “%Program Files%\Webplayer\uninstall.exe”

Detected by UnHackMe:

~KSHXWPL.EXE
DEFAULT LOCATION: %APPDATA%\~KSHXWPL.EXE

Dropper hash(md5): d5d07548da256da707b927681fb0eacd

Share This:

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

4
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera