PUP.ChinAd

Threat Scorecard

Ranking: 259
Threat Level: 80 % (High)
Infected Computers: 274,605
First Seen: October 22, 2013
Last Seen: December 27, 2023
OS(es) Affected: Windows

PUP.ChinAd is a potentially unwanted application that may show random or its own advertisements on well-known social networking and online shopping websites frequently visited by Internet users. The advertisements of PUP.ChinAd may be shown as boxes that include numerous coupons, or as underlined keywords, which when clicked may illustrate a pop-up ad that claims it is brought to the computer user by PUP.ChinAd. PUP.ChinAd may insert an unwanted add-on, plug-in or extension for Mozilla Firefox, Google Chrome, and Internet Explorer while the PC user is downloading and installing other free software products. When the PC user installs these free software products, he may also install PUP.ChinAd on the computer system. When installed, SPUP.ChinAd may illustrate an icon 'See Similar' next to the product image on various online shopping websites. PUP.ChinAd may also deliver coupons, deals, and/or other services on the relevant product websites. Sometimes, by clicking on a delivered offer, the computer user may get diverted to the suspicious commercial website, which was created by cybercrooks to possibly raise traffic and benefit from the pay-per-click technique.

SpyHunter Detects & Remove PUP.ChinAd

File System Details

PUP.ChinAd may create the following file(s):
# File Name MD5 Detections
1. 555.exe 4b8c85f0e781fd990afdd561169f0f1a 118
2. 88518b16abdae9f65dcdda44588bc060826e90dd40ba58abeec55397bce85167 5c1e55872eee347aab9986cebd50e352 87
3. raffle.exe 663fbf2a248971ea69c6234480a4bdcb 28
4. DreamScreen.scr 719e1b98d3255693303adf38abbf0cd6 23
5. DreamScreen.scr 87da78621f404395871ba598a102b08a 12
6. DreamScreen.scr fce55a1d30e5b82085a026516fcccc22 6
7. RlDateSet.exe 3f73a23886f2109e11882f5a600d3c24 5
8. DreamScreen.scr 178c7170164017deaeca13277b025b00 3
9. DreamScreen.scr aa2187a4265d3b9b4edb41769cf9cc08 1

Registry Details

PUP.ChinAd may create the following registry entry or registry entries:
CLSID
{7237A7B9-A57A-47F7-AA32-542848F408E1}
{97510FAC-ED50-46BF-B2A1-25F434BF1030}
Regexp file mask
%WINDIR%\system32\drivers\lanmamaster.sys
SOFTWARE\Classes\DongFangImeDictFile
SOFTWARE\Classes\DongFangImeSkinFile
SOFTWARE\DongFang
SOFTWARE\DongFangInput
SOFTWARE\DongFangService
SOFTWARE\Google\Chrome\NativeMessagingHosts\com.haitao.chrome.namsg.ht1hao
SOFTWARE\TXlTb2Z0
Software\WanNengWB
SOFTWARE\WanNengWBInput
SOFTWARE\WanNengWBService
Software\WanNengZip

Directories

PUP.ChinAd may create the following directory or directories:

%ALLUSERSPROFILE%\DreamScreen
%ALLUSERSPROFILE%\ailiaoweb
%APPDATA%\DreamScreen
%APPDATA%\Microsoft\Windows\Start Menu\Programs\HT1H
%APPDATA%\TravelCheap
%APPDATA%\calfwallpaper
%APPDATA%\fwsrv
%APPDATA%\haotukankan
%APPDATA%\jyzip
%APPDATA%\lehold
%APPDATA%\ptsandf
%COMMONPROGRAMFILES%\dongfanginput
%COMMONPROGRAMFILES(X86)%\dongfanginput
%HOMEDRIVE%\beloved521
%LOCALAPPDATA%\haotukankan
%LOCALAPPDATA%\htyh
%PROGRAMFILES%\WanNengWBInput
%PROGRAMFILES%\ZHPDFReader
%PROGRAMFILES%\bianya
%PROGRAMFILES%\bianya2
%PROGRAMFILES%\dongfanginput
%PROGRAMFILES%\fastwifi
%PROGRAMFILES%\flushcopy
%PROGRAMFILES%\gmbox
%PROGRAMFILES%\kbox
%PROGRAMFILES%\mainexe
%PROGRAMFILES%\pandapdf
%PROGRAMFILES%\puddingzip
%PROGRAMFILES%\scwbwordsvc
%PROGRAMFILES%\scwordsvc
%PROGRAMFILES%\worthyshop
%PROGRAMFILES(x86)%\WanNengWBInput
%PROGRAMFILES(x86)%\ZHPDFReader
%PROGRAMFILES(x86)%\ailiao
%PROGRAMFILES(x86)%\bianya
%PROGRAMFILES(x86)%\bianya2
%PROGRAMFILES(x86)%\dongfanginput
%PROGRAMFILES(x86)%\fastwifi
%PROGRAMFILES(x86)%\flushcopy
%PROGRAMFILES(x86)%\gmbox
%PROGRAMFILES(x86)%\kbox
%PROGRAMFILES(x86)%\mainexe
%PROGRAMFILES(x86)%\pandapdf
%PROGRAMFILES(x86)%\puddingzip
%PROGRAMFILES(x86)%\scwbwordsvc
%PROGRAMFILES(x86)%\scwordsvc
%PROGRAMFILES(x86)%\worthyshop
%PROGRAMFILES(x86)%\xsqxz
%USERPROFILE%\Local Settings\Application Data\htyh
%UserProfile%\Local Settings\Application Data\haotukankan
%appdata%\EverydayWallpaper
%appdata%\commander
%appdata%\fpsmaste
%appdata%\fypdfconvert
%appdata%\inkmgsrv
%appdata%\jisusearch
%appdata%\jjsciktynotes
%appdata%\kaobeitu
%appdata%\lpsrvrt
%appdata%\nvsofthelpex
%appdata%\qiaozip
%appdata%\qiaozipzhuomianup
%appdata%\screenocr
%appdata%\secondsearch
%appdata%\seenstamine
%appdata%\smartdesktop
%appdata%\webappplugin
%appdata%\xbpic
%appdata%\xbpicviewer
%appdata%\xfpdf
%homedrive%\wannengwbinput
%localappdata%\qiaozip
%temp%\fmpskin
%windir%\SysWOW64\IME\WanNengWB
%windir%\System32\IME\WanNengWB

Trending

Most Viewed

Loading...