Chedot Browser

By GoldSparrow in Potentially Unwanted Programs

Threat Scorecard

Popularity Rank: 342
Threat Level: 10 % (Normal)
Infected Computers: 142,707
First Seen: September 3, 2015
Last Seen: May 29, 2026
OS(es) Affected: Windows

The Chedot Browser is promoted on Chedot.com as an innovative Web browser based on the open-source project Chromium that would allow users to download any media on the Internet blazingly fast. In addition, users of the Chedot Browser will be directed to the Chedot.com search portal where they can find direct links to services like YouTube, Facebook and currency exchange rates. Users that may want to download the Chedot Browser should know that it is perceived as a Potentially Unwanted Program (PUP). Security investigators note that web surfers using Chedot only have access to commercials by sponsors of Chedot.com and will not see the native ads on trusted e-commerce sites like Amazon, Walmart, eBay and Best Buy. Moreover, users of the Chedot Browser will not have the option to change their default search engine to leading engines like Google and Bing. The Chedot Browser works similarly to the Mustang Browser and the Protectium and might present users with many pop-up windows to promote sponsored services and products. The Chedot Browser may arrive on your system bundled with a free program installer and edit your Windows Registry values to become your default Internet client. The Chedot Browser may be built upon Chromium, but it may not allow you to browse as fast as your Internet connection allows because it is constantly exchanging information with the servers of advertisers. The Chedot Browser may send information like your Internet browsing and download history logs to advertisers in order to show related commercials on the pages you visit. You may want to remove all files related to the Chedot Browser by using a reputable anti-malware solution.

SpyHunter Detects & Remove Chedot Browser

Registry Details

Chedot Browser may create the following registry entry or registry entries:
File name without path
Chedot.lnk
Software\Chedot
SOFTWARE\Classes\.htm\OpenWithProgIds\ChedotHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.html\OpenWithProgIds\ChedotHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.shtml\OpenWithProgids\ChedotHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.webp\OpenWithProgids\ChedotHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xht\OpenWithProgIds\ChedotHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xhtml\OpenWithProgIds\ChedotHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\chedot.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chedot.exe
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids\ChedotHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithProgids\ChedotHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Chedot
SOFTWARE\RegisteredApplications\Chedot.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Wow6432Node\Chedot
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\chedot.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Chedot
SOFTWARE\Wow6432Node\RegisteredApplications\Chedot.NSJA6BHDA3NCFCFMXW3QSCUYUQ

Directories

Chedot Browser may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\Chedot
%LOCALAPPDATA%\Chedot
%PROGRAMFILES%\Chedot
%PROGRAMFILES(x86)%\Chedot
%UserProfile%\Local Settings\Application Data\Chedot

Analysis Report

General information

Family Name: PUP.Chedot
Signature status: Self Signed

Known Samples

MD5: 4a5023faf541dcd11e990d8dbf0bbdb2
SHA1: cf0ce48d086e38eb90ed2fa891401acc715ec252
SHA256: 31515A740EA7786343A2090570B4E8869351ADBAFE9FF44A18FE2B5B45BEA77B
File Size: 3.39 MB, 3389824 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Chedot
File Description Chedot Setup
File Version 5.1.1.0
Internal Name sf_rt
Original Filename suf_launch.exe
Product Name Chedot
Product Version 5.1.1.0

Digital Signatures

Signer Root Status
Guerrilla Programming OÜ Symantec Class 3 SHA256 Code Signing CA Self Signed

Block Information

Total Blocks: 152
Potentially Malicious Blocks: 0
Whitelisted Blocks: 152
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 2 0 1 1 0 1 0 0 1 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 2 2 2 3 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_ir_sf_temp_0\chedot.ico Generic Read,Write Attributes
c:\users\user\appdata\local\temp\_ir_sf_temp_0\chedot.ico Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_ir_sf_temp_0\ftp.lmd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_ir_sf_temp_0\irimg1.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_ir_sf_temp_0\irimg1.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_ir_sf_temp_0\irimg2.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_ir_sf_temp_0\irsetup.dat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_ir_sf_temp_0\irsetup.dat Synchronize,Write Attributes
c:\users\user\appdata\local\temp\_ir_sf_temp_0\irsetup.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\_ir_sf_temp_0\license.txt Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_ir_sf_temp_0\lua5.1.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\chedot setup log.txt Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::left RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::top RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • ShellExecuteEx
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

open C:\Users\Uuetfptg\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe __IRAOFF:2156210 "__IRAFN:c:\users\user\downloads\cf0ce48d086e38eb90ed2fa891401acc715ec252_0003389824" "__IRCT:3" "__IRTSS:3383754" "__IRSID:S-1-5-21-3119368278-1123331430-659265220-1001"

1 Comment

Mario Hakulinen Reply

When Chedot is running it use, in practice, the full memory available creating the situation than the computer speed fall down. You can check the Chedot memory usage using the Task Manager. Probably the reason is that CheDot use memory consuming background processes. The positive side of CheDot is that it has built-in VPN.
Mario Hakulinen

Trending

Most Viewed

Loading...