Threat Database Adware Adware.KeyDownload

Adware.KeyDownload

By CagedTech in Adware

Threat Scorecard

Ranking: 11,601
Threat Level: 20 % (Normal)
Infected Computers: 21,785
First Seen: February 14, 2014
Last Seen: October 18, 2023
OS(es) Affected: Windows

Adware.KeyDownload is adware that may display random pop-up ads carrying discount coupons, offers, sales and deals in well-known online shopping websites and social networking websites. Adware.KeyDownload may add an adware supported add-on, plug-in or browser extension for Mozilla Firefox, Internet Explorer and Google Chrome Web browsers that may show pop-up, pop-under, banner, search, and in-text link interstitial ads. Adware.KeyDownload may propagate and install itself onto the PC as an additional application throughout the installation of possibly unprotected free program downloads. Adware.KeyDownload may be embedded in the Web browser when the computer user installs free software that may have added into their installation Adware.KeyDownload. When the PC user installs free programs on the computer system, he may also install Adware.KeyDownload. Adware.KeyDownload may unwillingly redirect PC users to questionable websites that may be created for commercial intentions. Adware.KeyDownload may be designed with the aim to generate advertising income from ad clicks and inreased web traffic.

SpyHunter Detects & Remove Adware.KeyDownload

File System Details

Adware.KeyDownload may create the following file(s):
# File Name MD5 Detections
1. ExtensionUpdaterService.exe 8942e2b842395f06caf06ce88caa1b0b 3,987
2. Extension64.dll 7444e2be53d2fcba4f87bd8eda72625f 2,229
3. KDUpdSrv.exe 28464ed23eca4fedb103778f5b9d1e0d 1,924
4. kdupdsrv.exe 62afab4f927ff7826fd27d843b958401 1,631
5. keyplayer.exe 7db05775b4b689d05a132eb7c5f96e44 707
6. Extension32.dll 45a3b5bbd4c35d7e36cfc795e8054395 668
7. guardnot.exe f884b152552d3a62fed5e878aa9925ef 363
8. kdupdsrv.exe b5cf24fd6db378d9d922025b9f3cd246 327
9. syscheck.exe d5316f64948b0a12051f1a3cae008efa 210
10. kdupdsrv.exe 943341a4d968ebe720adf4ed1e6c27ca 189
11. KDUpdSrv.exe 5e663742f73d620d148673042ec8f23a 167
12. kdupdsrv.exe 4440855c958337d91afda2e7b949c8f7 146
13. kdupdsrv.exe 88093e7d732bcb6af309b831115632de 79
14. start_svc.exe 2ac63bff751f3320bce807353a5edc30 70
15. NMHClient.exe 18d4ab4a67d5c8c96c37a5800e29c518 65
16. NMHClient.exe 05d73f4ac451b1f50cdd4e9200dad17f 6
17. KeyDownload-codedownloader.exe ee7d558b85f5f98d71c0d1a5101709ea 4
18. KeyDownload-enabler.exe 0e41d784ae6a8324da1414782f4aef78 4
19. KeyDownload-firefoxinstaller.exe b5d889e840f1ec9daaeb0927962f7c4a 4
20. KeyDownload-updater.exe 63555254fc4067dceea40d2ee59f1a5d 4
21. keyplayer.exe fe3e8788e0c017d623be86a48a60e932 3
22. KeyDownload-codedownloader.exe 08802c3fccc6883df22a56f13ad1054b 2
23. KeyDownload-enabler.exe 3e7c148a94d8fc93e334d63eebdd6773 2
24. KeyDownload-firefoxinstaller.exe de9d7fbcc941898a2a95486af67c9f93 2
25. KeyDownloadhelper1.exe 349544e8730e45657df05cebdfaf8570 1
26. KeyDownload-bho64.dll 33b4bd3c6689d011ed4d13157b4ab8bf 1
27. KeyPlayerV0.exe a57433829b2fed953119b4bb85dbe884 0
More files

Registry Details

Adware.KeyDownload may create the following registry entry or registry entries:
CLSID
{6FFA0D01-9182-48AA-98C9-AE5E64757FCC}
{7DDBC31B-22BD-4BBD-9F65-E8623814F3BB}
{C1EA4179-A319-4c6a-A3E5-67FF3592A12E}
File name without path
KEYPLAYER media player.lnk
KeyPlayer.lnk
Software\AppDataLow\Software\KeyDownload1
SOFTWARE\Classes\AppID\KeyDownload.DLL
SOFTWARE\Classes\AppID\{C2178B36-2955-479B-818C-A2AE8E500454}
SOFTWARE\Classes\Applications\keyplayer.exe
SOFTWARE\Classes\AudioCD\shell\PlayWithKEYPLAYER
SOFTWARE\Classes\Directory\shell\AddToPlaylistKEYPLAYER
SOFTWARE\Classes\Directory\shell\PlayWithKEYPLAYER
SOFTWARE\Classes\DVD\shell\PlayWithKEYPLAYER
SOFTWARE\Classes\KeyDownload.KeyDownload
SOFTWARE\Classes\KeyDownload.KeyDownload.1
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\KeyDownload1
SOFTWARE\Classes\Wow6432Node\AppID\KeyDownload.DLL
SOFTWARE\Classes\Wow6432Node\AppID\{C2178B36-2955-479B-818C-A2AE8E500454}
SOFTWARE\Clients\Media\KEYPLAYER
SOFTWARE\KeyDownload
SOFTWARE\Keyplayer Classic
Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311051129}
Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411781116}
Software\Microsoft\Internet Explorer\Approved Extensions\{BEE7841B-3C8B-46EA-AFE9-8461458BB2C1}
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\KeyDownload-bg.exe
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\KeyDownload1-bg.exe
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1EA4179-A319-4c6a-A3E5-67FF3592A12E}
SOFTWARE\Mozilla\Firefox\Extensions\{BEE7841B-3C8B-46ea-AFE9-8461458BB2C1}
SOFTWARE\Wow6432Node\Classes\AppID\KeyDownload.DLL
SOFTWARE\Wow6432Node\Classes\AppID\{C2178B36-2955-479B-818C-A2AE8E500454}
SOFTWARE\Wow6432Node\KeyDownload
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\KeyDownload-bg.exe
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\KeyDownload1-bg.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{C1EA4179-A319-4c6a-A3E5-67FF3592A12E}
SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\{BEE7841B-3C8B-46ea-AFE9-8461458BB2C1}
SOFTWARE\Wow6432Node\MozillaPlugins\@keydownload.com/keyplayer,version=2.2.0-git

Directories

Adware.KeyDownload may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\KeyDownload
%APPDATA%\KeyDownload
%APPDATA%\KeyDownload1
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\eodkncoddaagiibpdlfepebiggiijkbe
%PROGRAMFILES%\KeyDownload
%PROGRAMFILES%\KeyDownload-Addon
%PROGRAMFILES%\KeyDownload1
%PROGRAMFILES%\Keyplayer Classic
%PROGRAMFILES(x86)%\KeyDownload
%PROGRAMFILES(x86)%\KeyDownload-Addon
%PROGRAMFILES(x86)%\KeyDownload1
%PROGRAMFILES(x86)%\KeyPlayer
%PROGRAMFILES(x86)%\KeyPlayer-soft
%PROGRAMFILES(x86)%\Keyplayer Classic
%USERPROFILE%\AppData\LocalLow\KeyDownload1

URLs

Adware.KeyDownload may call the following URLs:

KeyDownload

Trending

Most Viewed

Loading...