PUP.Adware.ClientConnect.ean

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

PUP.Adware.ClientConnect.ean also known as Adware.ClientConnect/Variant, HEUR/QVM06.2.Malware.Gen, Win32.Application.Conduit.E.

Malware Analysis of PUP.Adware.ClientConnect.ean – B5DAADC79F0E3C91AFFC75D30B53E3FE07084418061EB308B5D62570434EA699.EXE

Created files:

%Appdata%\VOPackage\Uninstall.exe
%Appdata%\VOPackage\VOPackage.exe
%Desktop%\b5daadc79f0e3c91affc75d30b53e3fe07084418061eb308b5d62570434ea699.exe
%Desktop%\PC Speed Up.lnk
%Desktop%\Super Optimizer.lnk

Autostart registry keys:

HKLM\Software\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C}\InprocServer32\: “%Program Files%\PC Speed Up\PCSUHelper.dll”
HKLM\Software\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268}\InprocServer32\: “%Program Files%\PC Speed Up\PCSUHelper.dll”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IECT2562738\DisplayName: “RadioIslame Toolbar for IE”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IECT2562738\UninstallString: “”%Common Appdata%\Tbccint\IE\CT2562738\UninstallerUI.exe” -ctid=CT2562738 -toolbarName=RadioIslame -toolbarEnv=conduit -type=IE -origin=AddRemove -userMode=8 -dum=2″
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1\DisplayName: “PC Speed Up”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1\UninstallString: “”%Program Files%\PC Speed Up\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Super Optimizer_is1\DisplayName: “Super Optimizer v3.2”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Super Optimizer_is1\UninstallString: “”%Program Files%\Super Optimizer\unins000.exe” /VERYSILENT”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage\DisplayName: “Remote Desktop Access (VuuPC)”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage\UninstallString: “”%Appdata%\VOPackage\Uninstall.exe””
HKLM\System\CurrentControlSet\Services\PCSUService\ImagePath: “%Program Files%\PC Speed Up\PCSUService.exe”
HKLM\System\CurrentControlSet\Services\PCSUService\DisplayName: “PC Speed Up Service”
HKLM\System\CurrentControlSet\Services\SCService\ImagePath: “”%Program Files%\PC Speed Up\SpeedCheckerService.exe””
HKLM\System\CurrentControlSet\Services\SCService\DisplayName: “SpeedChecker Service”
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\DisplayName: “RadioIslame Customized Web Search”
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Super Optimizer: “%Program Files%\Super Optimizer\SupOptLauncher.exe”
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\PCSpeedUp: “%Program Files%\PC Speed Up\PCSUNotifier.exe”
HKCU\Software\RadioIslame\toolbar\DisplayName: “RadioIslame”

Detected by UnHackMe:

B5DAADC79F0E3C91AFFC75D30B53E3FE07084418061EB308B5D62570434EA699.EXE
Default location: %DESKTOP%\B5DAADC79F0E3C91AFFC75D30B53E3FE07084418061EB308B5D62570434EA699.EXE

Dropper hash(md5): 0aa53a53377b2d813f6ae4cf7c3485ea

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

4
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera