Win32.Trojan.WisdomEyes.151026.9950.9980

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

Win32.Trojan.WisdomEyes.151026.9950.9980 also known as HEUR/QVM10.1.0000.Malware.Gen, ADWARE/Adware.dnqs.

Malware Analysis of Win32.Trojan.WisdomEyes.151026.9950.9980 – PACICULTMAPPERTSK.EXE

Created files:

%Program Files%\Ozepycoinucult\msvcr100.dll
%Program Files%\Pacicult\PacicultMappersrv.html5
%Program Files%\Pacicult\PacicultMappertsk.exe
%Program Files%\PC Speed Up\agsXMPP.dll
%Program Files%\PC Speed Up\App.config

Autostart registry keys:

HKLM\Software\Classes\Applications\opera.exe\shell\open\command\: “”%Program Files%\Opera\Launcher.exe” “%1″”
HKLM\Software\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C}\InprocServer32\: “%Program Files%\PC Speed Up\PCSUHelper.dll”
HKLM\SOFTWARE\CLASSES\CLSID\{DFEAF541-F3E1-4C24-ACAC-99C30715084A}\INPROCSERVER32\: “%PROGRAM FILES%\MICROSOFT SILVERLIGHT\5.1.30514.0\NPCTRL.DLL”
HKLM\Software\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268}\InprocServer32\: “%Program Files%\PC Speed Up\PCSUHelper.dll”
HKLM\Software\Classes\OperaStable\shell\open\command\: “”%Program Files%\Opera\Launcher.exe” -noautoupdate — “%1″”
HKLM\Software\Clients\StartMenuInternet\OperaStable\shell\open\command\: “”%Program Files%\Opera\Launcher.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D7314F9862C648A4DB8BE2A5B47BE100\Patches\ED07A2BB4DF1F3A429E67D4FCF32AEED\DisplayName: “Microsoft Silverlight 5.1.30514.0”
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D7314F9862C648A4DB8BE2A5B47BE100\InstallProperties\UninstallString: “MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}”
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D7314F9862C648A4DB8BE2A5B47BE100\InstallProperties\DisplayName: “Microsoft Silverlight”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Opera 38.0.2220.31\DisplayName: “Opera Stable 38.0.2220.31”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Opera 38.0.2220.31\UninstallString: “”%Program Files%\Opera\Launcher.exe” /uninstall”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1\DisplayName: “PC Speed Up”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1\UninstallString: “”%Program Files%\PC Speed Up\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1A8A6B58-65C3-4539-A062-AAD1AC118D65}\UninstallString: “rundll32.exe “%Program Files%\Ledigeanonpy\Ldglauncher.dll”,u “/k={1A8A6B58-65C3-4539-A062-AAD1AC118D65}””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1A8A6B58-65C3-4539-A062-AAD1AC118D65}\DisplayName: “yessearches – Uninstall”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\UninstallString: “MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\DisplayName: “Microsoft Silverlight”
HKLM\System\CurrentControlSet\services\PacicultMappersrv\ImagePath: “”%Program Files%\Pacicult\PacicultMappersrv.html5″ {79740E79-A383-47A7-B513-3DF6563D007F} {8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}”
HKLM\System\CurrentControlSet\services\PacicultMappersrv\DisplayName: “Pacicult Mapper”
HKLM\System\CurrentControlSet\services\PCSUService\ImagePath: “%Program Files%\PC Speed Up\PCSUService.exe”
HKLM\System\CurrentControlSet\services\PCSUService\DisplayName: “PC Speed Up Service”
HKLM\System\CurrentControlSet\services\SCService\ImagePath: “”%Program Files%\PC Speed Up\SpeedCheckerService.exe””
HKLM\System\CurrentControlSet\services\SCService\DisplayName: “SpeedChecker Service”
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\PCSpeedUp: “%Program Files%\PC Speed Up\PCSUNotifier.exe”
HKLM\Software\Classes\ftp\shell\open\command\: “”%Program Files%\Opera\launcher.exe” -noautoupdate — “%1″”
HKLM\Software\Classes\http\shell\open\command\: “”%Program Files%\Opera\launcher.exe” -noautoupdate — “%1″”
HKLM\Software\Classes\https\shell\open\command\: “”%Program Files%\Opera\launcher.exe” -noautoupdate — “%1″”

Detected by UnHackMe:

PACICULTMAPPERTSK.EXE
Default location: %PROGRAM FILES%\PACICULT\PACICULTMAPPERTSK.EXE

Dropper hash(md5): 8159c37422acea8b24d071f5cb1cdfd3

Share This:

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

4
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera