PUP.LuDaShi

Threat Scorecard

Ranking: 830
Threat Level: 10 % (Normal)
Infected Computers: 141,864
First Seen: March 16, 2016
Last Seen: March 1, 2025
OS(es) Affected: Windows

File System Details

PUP.LuDaShi may create the following file(s):
# File Name MD5 Detections
1. MobileDeviceSrv.exe ccd8369cc281c091ce86766004b3e669 378
2. LockHomePage.exe 02446ad15a7a7fcfd3a6e313c4833b13 162
3. MiniNews.exe 06ce90f74c9daa023a89030acb30466c 80
4. LdsLite.exe 45ebc4be21df257e03feee5a87917186 32
5. ComputerZ14.exe b1d87da50bad52902a6d90c593516ddc 21
6. removelds_gcenter.bat 675c6ca06e9232982c828455cb91f05f 1
7. removelds.bat 366688c29407dd45b8b5738e9f769249 1
More files

Registry Details

PUP.LuDaShi may create the following registry entry or registry entries:
CLSID
{34B3C588-D06C-4F92-929C-2C3A0BC7F821}
Regexp file mask
%TEMP%\ludashisetup.exe
%Temp%\removelds.bat
%Temp%\removelds_gcenter.bat
%WINDIR%\System32\Tasks\ComputerZ-Tray
%WINDIR%\System32\Tasks\LDSGameCenter
SOFTWARE\Classes\ComputerZ8.DeskBandExt
SOFTWARE\Classes\ComputerZ8.DeskBandExt.1
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ludashi.com
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.ludashi.com
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ludashi.com
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.ludashi.com
SOFTWARE\LDSGameCenter
SOFTWARE\ldssrv
SOFTWARE\Ludashi
SOFTWARE\LudashiLspUrl
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT\mininews.exe
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\mininews.exe
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\mininews.exe
SOFTWARE\Microsoft\Tracing\ComputerZTray_RASAPI32
SOFTWARE\Microsoft\Tracing\ComputerZTray_RASMANCS
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ComputerZ-Tray
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ComputerZLite
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ComputerZ_CN.exe
Software\QiLu Inc.\mininews
SOFTWARE\WOW6432Node\LDSGameCenter
SOFTWARE\WOW6432Node\LdsLite
SOFTWARE\WOW6432Node\ldssrv
SOFTWARE\WOW6432Node\LuDaShi
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT\mininews.exe
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\mininews.exe
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\mininews.exe
SOFTWARE\WOW6432Node\Microsoft\Tracing\ComputerZTray_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\ComputerZTray_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ComputerZ_CN.exe
SYSTEM\ControlSet001\Enum\Root\LEGACY_COMPUTERZ_X64
SYSTEM\ControlSet001\Enum\Root\LEGACY_COMPUTERZLOCK
SYSTEM\ControlSet001\Services\ComputerZ_x64
SYSTEM\ControlSet001\services\ComputerZLock
SYSTEM\ControlSet002\Enum\Root\LEGACY_COMPUTERZ_X64
SYSTEM\ControlSet002\Enum\Root\LEGACY_COMPUTERZLOCK
SYSTEM\ControlSet002\Services\ComputerZ_x64
SYSTEM\ControlSet002\services\ComputerZLock
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_COMPUTERZ_X64
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_COMPUTERZLOCK
SYSTEM\CurrentControlSet\Services\ComputerZ_x64
SYSTEM\CurrentControlSet\services\ComputerZLock

Directories

PUP.LuDaShi may create the following directory or directories:

%APPDATA%\360bizhi\Utils
%APPDATA%\360bizhi\softmgr
%APPDATA%\360bizhi\wallpaperhelper
%APPDATA%\ABCPhoto\mininews
%APPDATA%\youku
%APPDATA%\ytmediacenter
%AppData%\Ludashi
%PROGRAMFILES%\LDSGameCenter
%PROGRAMFILES%\LdsLite
%PROGRAMFILES%\LuDaShi
%PROGRAMFILES(x86)%\LDSGameCenter
%PROGRAMFILES(x86)%\LdsLite
%PROGRAMFILES(x86)%\LuDaShi
%WINDIR%\Syswow64\config\systemprofile\AppData\Roaming\LDSGameCenter
%WINDIR%\Syswow64\config\systemprofile\AppData\Roaming\Ludashi
%WINDIR%\system32\config\systemprofile\AppData\Roaming\LDSGameCenter
%WINDIR%\system32\config\systemprofile\AppData\Roaming\Ludashi
%appdata%\LDSGameAssistant
%appdata%\LDSGameCenter

Trending

Most Viewed

Loading...