Threat Database Adware Adware.Adposhel.RA

Adware.Adposhel.RA

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 13,421
Threat Level: 20 % (Normal)
Infected Computers: 81
First Seen: March 7, 2024
Last Seen: June 12, 2026
OS(es) Affected: Windows

The detection of Adware.Adposhel.RA on your system indicates the presence of a potentially unwanted program that may be displaying unwanted advertisements, collecting user data, or performing other malicious activities. It is essential to take immediate action to remove this threat and prevent further damage to your system and personal data.

What Is Adware.Adposhel.RA?

Adware.Adposhel.RA is a type of adware program that is designed to display unwanted advertisements, often in the form of pop-ups, banners, or sponsored links. Adware programs like this one can be bundled with free software, downloaded from the internet, or installed through exploits in vulnerable software. Once installed, Adware.Adposhel.RA can collect user data, such as browsing history and search queries, and use it to display targeted advertisements.

How Adware.Adposhel.RA Operates

Adware.Adposhel.RA operates by infiltrating a system through various means, such as drive-by downloads, infected software downloads, or phishing emails. Once installed, it can modify system settings, registry entries, and browser configurations to display unwanted advertisements. It may also communicate with its command and control servers to receive updates, send user data, or download additional malware. Adware programs like Adware.Adposhel.RA can slow down system performance, consume system resources, and compromise user privacy.

Symptoms of Infection

Symptoms of Adware.Adposhel.RA infection may include unwanted pop-ups, banners, or sponsored links on web pages, unfamiliar programs or toolbars installed on the system, slow system performance, and suspicious network activity. Users may also notice that their browser homepage or search engine has been changed without their consent. In some cases, Adware.Adposhel.RA may also display fake alerts, warnings, or notifications to trick users into installing additional malware or purchasing fake software.

How to Remove Adware.Adposhel.RA

  1. Boot your system in Safe Mode with Networking to prevent Adware.Adposhel.RA from loading and to allow for a safe removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect all components of Adware.Adposhel.RA.
  3. Uninstall any suspicious programs or applications that may be related to Adware.Adposhel.RA.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all components of Adware.Adposhel.RA have been removed.

Conclusion

Removing Adware.Adposhel.RA from your system is crucial to preventing further damage and protecting your personal data. By following the steps outlined above, you can safely remove this threat and restore your system to its normal state. It is also essential to practice safe browsing habits, such as avoiding suspicious downloads, using strong antivirus software, and keeping your operating system and software up to date, to prevent similar infections in the future.

Analysis Report

General information

Family Name: Adware.Adposhel.RA
Signature status: No Signature

Known Samples

MD5: 664b8a3477125f4863ead4c53c9637d3
SHA1: 96ba1109cb26cafbb5de8c71f91660db39c18709
SHA256: 3BD168CF5A45771DAAC6794651B00331A54E1DE96E32DD70076B1D90BD716A40
File Size: 1.18 MB, 1181887 bytes
MD5: fc36ab5bae0ecb93922cc88a96e5677d
SHA1: e7b2ab1ef829474966fe638770c0758423f47669
SHA256: 56EA676ED859A4570CD304F0521248F1F5FC7B7F87355FF673042613E0B3BB02
File Size: 1.76 MB, 1757433 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Kalango's Soft
File Description Clickteam Fusion Application Runtime
File Version
  • 3, 0, 291, 5
  • 1.0
Internal Name lnchrt.exe
Legal Copyright Copyright © 2006-2015 Clickteam
Original Filename lnchrt.exe
Product Name Clickteam Fusion Application Runtime
Product Version 3, 0, 291, 5

File Traits

  • big overlay
  • HighEntropy
  • x86

Block Information

Total Blocks: 327
Potentially Malicious Blocks: 34
Whitelisted Blocks: 293
Unknown Blocks: 0

Visual Map

x x x x x x x x 0 x x x x x x 0 x 0 x x x x 0 x 0 x 0 x 0 x x 0 0 0 0 0 x 0 x x x 0 0 x x 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 2 3 0 0 1 0 0 0 1 0 0 1 0 0 0 1 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 0 0 1 0 1 0 0 0 0 0 1 0 1 1 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\ctrlx.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\joystick2.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\kcbutton.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\kcbutton.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\kcedit.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\kcedit.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\kcini.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\kcini.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\mmfs2.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\mrt4552.tmp\mmfs2.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\statictext.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\statictext.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\stdrt.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\stdrt.txt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrt4552.tmp\waveflt.sft Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\ctrlx.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\joystick2.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\kcarray.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\kcbutton.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\kccombo.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\kcfile.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\kcini.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\kcplugin.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\kcshape.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\mmfs2.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\stdrt.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mrtdd14.tmp\txtblt.mfx Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\system\currentcontrolset\control\mediaproperties\privateproperties\directinput\vid_0627&pid_0001\calibration\0::guid 蹐〟駿ᇰƀ䕄呓 RegNtPreCreateKey
HKCU\software\microsoft\directinput\stdrt.exe5b2b530600105a00::name STDRT.EXE RegNtPreCreateKey
HKCU\software\microsoft\directinput\stdrt.exe5b2b530600105a00::usesmapper RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::name STDRT.EXE RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::id STDRT.EXE5B2B530600105A00 RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::version RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::mostrecentstart 雁黖⹆ǜ RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::version Ԋ RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::name STDRT.EXE RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::id STDRT.EXE5B2B530600105A00 RegNtPreCreateKey
Show More
HKCU\software\microsoft\directinput\mostrecentapplication::mostrecentstart 낏黜⹆ǜ RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::left RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::top RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg �� �v xy ����T��������%����3bBx��$kF%�&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1�1HO5,]=�@V�A��B��G�IH[uH�pJ��N$N�U_*X�.X�\te_�za$b"hc�wc�zh�ri��j�bk` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg �� �v xy ����T��������%����3bBx��$kF%�&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1�1HO5,]=�@V�A��B��G�IH[uH�pJ��N$N�U_*X�.X�\te_�za$b"hc�wc�ze�vh�ri��j�b RegNtPreCreateKey
HKCU\system\currentcontrolset\control\mediaproperties\privateproperties\directinput\vid_0627&pid_0001\calibration\0::guid P�Me��DEST RegNtPreCreateKey
HKCU\software\microsoft\directinput\stdrt.exe5562d660000fea00::name STDRT.EXE RegNtPreCreateKey
HKCU\software\microsoft\directinput\stdrt.exe5562d660000fea00::usesmapper RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::id STDRT.EXE5562D660000FEA00 RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::mostrecentstart ⵣ뮾累ǜ RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::mostrecentstart ⃞믄累ǜ RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx
Keyboard Access
  • GetAsyncKeyState

Shell Command Execution

"C:\Users\Hxtavgdv\AppData\Local\Temp\mrt4552.tmp\stdrt.exe" /SF "c:\users\user\downloads\96ba1109cb26cafbb5de8c71f91660db39c18709_0001181887" /SO394240
"C:\Users\Rxpdwihe\AppData\Local\Temp\mrtDD14.tmp\stdrt.exe" /SF "c:\users\user\downloads\e7b2ab1ef829474966fe638770c0758423f47669_0001757433" /SO394240

Related Posts

Trending

Most Viewed

Loading...