PUP.LuDaShi

Threat Scorecard

Ranking: 732
Threat Level: 10 % (Normal)
Infected Computers: 139,935
First Seen: March 16, 2016
Last Seen: April 19, 2024
OS(es) Affected: Windows

File System Details

PUP.LuDaShi may create the following file(s):
# File Name MD5 Detections
1. LdsLite.exe fcc36e8a29aa752f01300f74c1be89c8 691
2. MobileDeviceSrv.exe ccd8369cc281c091ce86766004b3e669 377
3. MiniNews.exe 06ce90f74c9daa023a89030acb30466c 80
4. LdsLite.exe 45ebc4be21df257e03feee5a87917186 32
5. ComputerZ14.exe b1d87da50bad52902a6d90c593516ddc 21
6. ludashisetup.exe 5d6aba115a40909014777ff76a732e20 13
7. ludashisetup.exe 5f653efd6f1adc9cb20998ea8d084c16 12
8. ComputerZTray.exe 9ad3274f5af717f8358c1034437cbec3 8
9. ludashisetup.exe 4003f78adf7167719ed185b3356dcc7e 8
10. ludashisetup.exe f53110e8010be9f17c1c48e7d57c3ce0 7
11. ludashisetup.exe fe436f92885b4c8d122743151ddaa7d1 7
12. ludashisetup.exe 1b55a6dfefe520b7647d584a40153f7c 4
13. ComputerZTray.exe b550913c60ead9f153f24020896022c9 4
14. ludashisetup.exe a55d94709ef4aae820fbaef45c00188d 3
15. ComputerZTray.exe b4c2f72db41b3ce13e59bdfaa1e21b0a 3
16. ComputerZTray.exe 51e6d42e0febe12c20542412e786fdcf 2
17. ComputerZService.exe d4f2f0ebbb05071f2212cb0442813fd3 2
18. ComputerZTray.exe e530295768374dbe53ee2cca8aea47ad 2
19. ludashisetup.exe 90203d15be7566c38081d03ed6b93132 1
20. ludashisetup.exe 6f71da8eac83fe03182250c790f40d55 1
21. ludashisetup.exe f6aa833f511781465b7d08e84457b0b0 1
22. ludashisetup.exe a5a7d3570817a25880871d2f6e745cd1 1
23. ludashisetup.exe 3c5e43379674c99203feeeb2e96bf180 1
24. removelds_gcenter.bat 675c6ca06e9232982c828455cb91f05f 1
25. removelds.bat 366688c29407dd45b8b5738e9f769249 1
More files

Registry Details

PUP.LuDaShi may create the following registry entry or registry entries:
CLSID
{34B3C588-D06C-4F92-929C-2C3A0BC7F821}
Regexp file mask
%TEMP%\ludashisetup.exe
%Temp%\removelds.bat
%Temp%\removelds_gcenter.bat
%WINDIR%\System32\Tasks\ComputerZ-Tray
%WINDIR%\System32\Tasks\LDSGameCenter
SOFTWARE\Classes\ComputerZ8.DeskBandExt
SOFTWARE\Classes\ComputerZ8.DeskBandExt.1
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ludashi.com
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.ludashi.com
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ludashi.com
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.ludashi.com
SOFTWARE\LDSGameCenter
SOFTWARE\ldssrv
SOFTWARE\Ludashi
SOFTWARE\LudashiLspUrl
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT\mininews.exe
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\mininews.exe
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\mininews.exe
SOFTWARE\Microsoft\Tracing\ComputerZTray_RASAPI32
SOFTWARE\Microsoft\Tracing\ComputerZTray_RASMANCS
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ComputerZ-Tray
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ComputerZLite
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ComputerZ_CN.exe
Software\QiLu Inc.\mininews
SOFTWARE\WOW6432Node\LDSGameCenter
SOFTWARE\WOW6432Node\LdsLite
SOFTWARE\WOW6432Node\ldssrv
SOFTWARE\WOW6432Node\LuDaShi
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT\mininews.exe
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT\mininews.exe
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\mininews.exe
SOFTWARE\WOW6432Node\Microsoft\Tracing\ComputerZTray_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\ComputerZTray_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ComputerZ_CN.exe
SYSTEM\ControlSet001\Enum\Root\LEGACY_COMPUTERZ_X64
SYSTEM\ControlSet001\Enum\Root\LEGACY_COMPUTERZLOCK
SYSTEM\ControlSet001\Services\ComputerZ_x64
SYSTEM\ControlSet001\services\ComputerZLock
SYSTEM\ControlSet002\Enum\Root\LEGACY_COMPUTERZ_X64
SYSTEM\ControlSet002\Enum\Root\LEGACY_COMPUTERZLOCK
SYSTEM\ControlSet002\Services\ComputerZ_x64
SYSTEM\ControlSet002\services\ComputerZLock
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_COMPUTERZ_X64
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_COMPUTERZLOCK
SYSTEM\CurrentControlSet\Services\ComputerZ_x64
SYSTEM\CurrentControlSet\services\ComputerZLock

Directories

PUP.LuDaShi may create the following directory or directories:

%APPDATA%\360bizhi\Utils
%APPDATA%\360bizhi\softmgr
%APPDATA%\360bizhi\wallpaperhelper
%APPDATA%\ABCPhoto\mininews
%APPDATA%\youku
%APPDATA%\ytmediacenter
%AppData%\Ludashi
%PROGRAMFILES%\LDSGameCenter
%PROGRAMFILES%\LdsLite
%PROGRAMFILES%\LuDaShi
%PROGRAMFILES(x86)%\LDSGameCenter
%PROGRAMFILES(x86)%\LdsLite
%PROGRAMFILES(x86)%\LuDaShi
%WINDIR%\Syswow64\config\systemprofile\AppData\Roaming\LDSGameCenter
%WINDIR%\Syswow64\config\systemprofile\AppData\Roaming\Ludashi
%WINDIR%\system32\config\systemprofile\AppData\Roaming\LDSGameCenter
%WINDIR%\system32\config\systemprofile\AppData\Roaming\Ludashi
%appdata%\LDSGameAssistant
%appdata%\LDSGameCenter

Trending

Most Viewed

Loading...