Home Malware Programs Potentially Unwanted Programs (PUPs) AnySend

AnySend

Posted: May 23, 2014

Threat Metric

Ranking: 5,029
Threat Level: 1/10
Infected PCs: 132,593
First Seen: May 23, 2014
Last Seen: October 12, 2023
OS(es) Affected: Windows


The AnySend program by ClickMeIn Limited is offered as a file sharing application, but security researchers are classifying it as a Potentially Unwanted Program (PUP) with adware capabilities. The AnySend app can be downloaded directly from its website and could be installed via freeware packages as well. The AnySend software comes incorporated with the Install Core Click application distribution platform that can install additional software on your computer. The AnySend app adds a right-click option in the Windows shell. It may add a Browser Helper Object (BHO), an add-on or an extension to your web browser that could be used to display advertisement materials. The free features of AnySend rely on ads, and you would have to browse the web in the company of numerous pop-ups, ads, and in-text hyperlinks. You might want to scan your system for adware and PUPs with trusted anti-spyware utility.

Aliases

Artemis!3B24AC33A909 [McAfee]WS.Reputation.1 [Symantec]NSIS.Application.Vopackage.A [GData]TR/Fraud.Gen7 [AntiVir]Adware.Downware.1411 [DrWeb]Artemis!77726F336234 [McAfee]Artemis!254935C4969E [McAfee]Clickmein.046 [AVG]Artemis [McAfee-GW-Edition]AnyProtect [Sophos]Unwanted-Program ( 004ae67e1 ) [K7AntiVirus]Artemis!58879E11D7BD [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\anysend.exe File name: anysend.exe
Size: 1.57 MB (1571328 bytes)
MD5: 60e6148759c4dec05cc313dd63c730d0
Detection count: 173
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: July 8, 2016
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 1.1 MB (1106355 bytes)
MD5: b60199c4b03e7cd1b747018c6fd9662f
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 1.14 MB (1146869 bytes)
MD5: 9c79e53a7cfeeeccbc0c958841f38635
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: March 30, 2020
%LOCALAPPDATA%\AnySend.exe File name: AnySend.exe
Size: 336.15 KB (336152 bytes)
MD5: 2d495ad0f35292d7cd82e5d0033dc677
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: July 8, 2016
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 807.86 KB (807867 bytes)
MD5: ee83d51191e9ae1d623205e4f610f701
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 808.91 KB (808914 bytes)
MD5: 43972b9b1fe215b1acc7f5b438bfe83e
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 1.17 MB (1175416 bytes)
MD5: ece206de96c3f6afbe2a8806b5ac2ab3
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 274.16 KB (274161 bytes)
MD5: bdd7c3a4bbca055848f86c853c9eac74
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 1.07 MB (1076729 bytes)
MD5: e758b61e20ff2d788dc54a0b0178428a
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 1.06 MB (1069363 bytes)
MD5: 29e8549c43e367069b40a0483d91c9ab
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%TEMP%\{266CBD5E-708E-4C0F-9157-BDDEB8808A40}\ASPackage.exe File name: ASPackage.exe
Size: 264.37 KB (264373 bytes)
MD5: ba78c4ef2aa7b5b88124dc5feca7ab54
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\{266CBD5E-708E-4C0F-9157-BDDEB8808A40}
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 273.15 KB (273151 bytes)
MD5: ce53f6e477ccaf0792b2c48c43f69160
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 263.94 KB (263948 bytes)
MD5: 50a79cfb21ec230edd3378504c5d23da
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 299.12 KB (299120 bytes)
MD5: be448685ec9f5f46ae242a5a8175fa8e
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 580.31 KB (580318 bytes)
MD5: 06dcf8a7413f798d00b0d46bf8953d18
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%APPDATA%\ASPackage\ASPackage.exe File name: ASPackage.exe
Size: 266.46 KB (266469 bytes)
MD5: 689f77db50980942ac7caafe4cf5e50e
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: April 22, 2017
%LOCALAPPDATA%\AnySend.exe File name: AnySend.exe
Size: 367.68 KB (367688 bytes)
MD5: 62c194286205c2c2ea520ff4c1e5daee
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: July 8, 2016
C:\Program Files\anysend\AnySendUI.exe File name: C:\Program Files\anysend\AnySendUI.exe
MD5: 0f2992cbf2612076c7c402526b3492ff
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
AnySendSvc.exe File name: AnySendSvc.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{61628E2A-4FF9-4454-992D-D92A8CD27399}{7BFFA5F9-047F-4732-93B5-B9FE731DE96D}File name without pathhttp_www.anysend.com_0.localstoragehttp_www.anysend.com_0.localstorage-journalRegexp file mask%WINDIR%\System32\Tasks\AnySendUpdateHKEY..\..\..\..{RegistryKeys}SOFTWARE\AnySendSOFTWARE\Classes\*\shellex\ContextMenuHandlers\AnySendSOFTWARE\Classes\AnySend.ConnectSOFTWARE\Classes\AnySend.Connect.1Software\Microsoft\Internet Explorer\DOMStorage\anysend.comSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{61628E2A-4FF9-4454-992D-D92A8CD27399}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AnySend User InterfaceSOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{61628E2A-4FF9-4454-992D-D92A8CD27399}SOFTWARE\Wow6432Node\AnySendSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\AnySend User InterfaceSYSTEM\ControlSet001\services\AnySendServiceSYSTEM\ControlSet002\services\AnySendServiceSYSTEM\CurrentControlSet\services\AnySendServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}AnySendASPackage{7203C44E-08F7-471D-8C9B-349A0D17506F}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\AnySend%ALLUSERSPROFILE%\Application Data\AnySend%APPDATA%\ASPackage%APPDATA%\Microsoft\Windows\Start Menu\Programs\ASPackage%APPDATA%\Microsoft\Windows\Start Menu\Programs\AnySend%PROGRAMFILES%\AnySend%PROGRAMFILES(x86)%\AnySend%appdata%\AnySend
Loading...