Home Malware Programs Potentially Unwanted Programs (PUPs) PUP.Crimsolite

PUP.Crimsolite

Posted: February 6, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 1,042
First Seen: February 6, 2014
Last Seen: June 6, 2023
OS(es) Affected: Windows


PUP.Crimsolite is a potentially unwanted program (PUP), which may be downloaded from the Internet when a computer user downloads various free programs from questionable download websites. PUP.Crimsolite may lead to numerous PC problems when it is downloaded and installed on the computer system. The computer user may approve to download PUP.Crimsolite when he is downloading other free software, or he may download PUP.Crimsolite because of a rush by not paying enough attention to the installation process. When the PC user downloads any free app from the Internet and does not read the download agreement, he may not be aware of what extra potentially unwanted tools may come packaged with the free program he is downloading. When downloaded and installed, PUP.Crimsolite may run numerous background processes that may slow the computer system down. PUP.Crimsolite may cover the screen of the PC with numerous random pop-up advertisements.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



cf9d4bb7dd0253c915bd90e973f56c98df0972c632c99061bcb5cea7b0570bd9.exe File name: cf9d4bb7dd0253c915bd90e973f56c98df0972c632c99061bcb5cea7b0570bd9.exe
Size: 2.16 MB (2164392 bytes)
MD5: 099e77a705369d8f77f8403a8068f3a6
Detection count: 79
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 10, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{1b059c94-7dfc-419a-8aa6-8e643bac7974}{57598D3D-4682-464B-8A24-84462A40A4FA}{AFCA2592-4D6B-4DC0-B9E1-F1BC3978DEDF}HKEY..\..\..\..{RegistryKeys}SOFTWARE\crimsoliteSOFTWARE\Microsoft\Tracing\crimsolite_RASAPI32SOFTWARE\Microsoft\Tracing\crimsolite_RASMANCSSOFTWARE\Microsoft\Tracing\updatecrimsolite_RASAPI32SOFTWARE\Microsoft\Tracing\updatecrimsolite_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B059C94-7DFC-419A-8AA6-8E643BAC7974}SOFTWARE\Wow6432Node\crimsoliteSOFTWARE\Wow6432Node\Microsoft\Tracing\crimsolite_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\crimsolite_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updatecrimsolite_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatecrimsolite_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1b059c94-7dfc-419a-8aa6-8e643bac7974}SYSTEM\ControlSet001\services\eventlog\Application\Update crimsoliteSYSTEM\ControlSet001\services\Update crimsoliteSYSTEM\CurrentControlSet\services\eventlog\Application\Update crimsoliteSYSTEM\CurrentControlSet\services\Update crimsoliteHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}crimsolite

Additional Information

The following directories were created:
%PROGRAMFILES%\crimsolite%PROGRAMFILES(X86)%\crimsolite
Loading...