APPL/Agent.7567

Dmitry Sokolov recommends UnHackMe!

UnHackMe is a powerful tool against malware.

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved! 5 Stars (5 / 5)

APPL/Agent.7567 also known as Hacktool ( 655367771 ), Adware.Win32.ELEX.HD.

Malware Analysis of APPL/Agent.7567 – SHORTBOOST.EXE

Created files:

%Program Files%\SearchesToYesbnd\ccuter.exe
%Program Files%\SearchesToYesbnd\ffuter.exe
%Program Files%\SearchesToYesbnd\shortboost.exe
%Program Files%\SearchesToYesbnd\unIns.exe
%Program Files%\SearchesToYesbnd\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}

Autostart registry keys:

HKLM\Software\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C}\InprocServer32\: “%Program Files%\PC Speed Up\PCSUHelper.dll”
HKLM\Software\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268}\InprocServer32\: “%Program Files%\PC Speed Up\PCSUHelper.dll”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1\DisplayName: “PC Speed Up”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1\UninstallString: “”%Program Files%\PC Speed Up\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Reduce Car Costs_is1\DisplayName: “Reduce Car Costs 1.2.3”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Reduce Car Costs_is1\UninstallString: “”%Program Files%\AB-Tools.com\Reduce Car Costs\unins000.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall cos\UninstallString: “”%Program Files%\SearchesToYesbnd\unIns.exe” /cf={A16B1AF7-982D-40C3-B5C1-633E1A6A6678}”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall cos\DisplayName: “yessearches Uninstall”
HKLM\System\CurrentControlSet\Services\ggbugreport\ImagePath: “”%Program Files%\SearchesToYesbnd\bugreport.exe” {154DFF63-3402-4815-941A-AAD63AE8B428}”
HKLM\System\CurrentControlSet\Services\ggbugreport\DisplayName: “ggbugreport”
HKLM\System\CurrentControlSet\Services\PCSUService\ImagePath: “%Program Files%\PC Speed Up\PCSUService.exe”
HKLM\System\CurrentControlSet\Services\PCSUService\DisplayName: “PC Speed Up Service”
HKLM\System\CurrentControlSet\Services\SCService\ImagePath: “”%Program Files%\PC Speed Up\SpeedCheckerService.exe””
HKLM\System\CurrentControlSet\Services\SCService\DisplayName: “SpeedChecker Service”
HKLM\System\CurrentControlSet\Services\Winsere\ImagePath: “”%Program Files%\Winsere\Winsere\Winsere.exe” {79740E79-A383-47A7-B513-3DF6563D007F} {A16B1AF7-982D-40C3-B5C1-633E1A6A6678}”
HKLM\System\CurrentControlSet\Services\Winsere\DisplayName: “Winsere”
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\PCSpeedUp: “%Program Files%\PC Speed Up\PCSUNotifier.exe”

Detected by UnHackMe:

SHORTBOOST.EXE
Default location: %PROGRAM FILES%\SEARCHESTOYESBND\SHORTBOOST.EXE

Dropper hash(md5): 123dbd97732a2d6089a6a50d9737a507

Written by 

Malware Hunter.

UnHackMe removes malware invisible for your antivirus!

Free Download

1
UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1/10. UnHackMe uses minimum of computer resources.

WordPress SEO fine-tune by Meta SEO Pack from Poradnik Webmastera