Home Malware Programs Potentially Unwanted Programs (PUPs) AnySend

AnySend

Posted: May 23, 2014

Threat Metric

Ranking: 4,726
Threat Level: 1/10
Infected PCs: 133,153
First Seen: May 23, 2014
Last Seen: March 9, 2025
OS(es) Affected: Windows


The AnySend program by ClickMeIn Limited is offered as a file sharing application, but security researchers are classifying it as a Potentially Unwanted Program (PUP) with adware capabilities. The AnySend app can be downloaded directly from its website and could be installed via freeware packages as well. The AnySend software comes incorporated with the Install Core Click application distribution platform that can install additional software on your computer. The AnySend app adds a right-click option in the Windows shell. It may add a Browser Helper Object (BHO), an add-on or an extension to your web browser that could be used to display advertisement materials. The free features of AnySend rely on ads, and you would have to browse the web in the company of numerous pop-ups, ads, and in-text hyperlinks. You might want to scan your system for adware and PUPs with trusted anti-spyware utility.

Aliases

Artemis!3B24AC33A909 [McAfee]WS.Reputation.1 [Symantec]NSIS.Application.Vopackage.A [GData]TR/Fraud.Gen7 [AntiVir]Adware.Downware.1411 [DrWeb]Artemis!77726F336234 [McAfee]Artemis!254935C4969E [McAfee]Clickmein.046 [AVG]Artemis [McAfee-GW-Edition]AnyProtect [Sophos]Unwanted-Program ( 004ae67e1 ) [K7AntiVirus]Artemis!58879E11D7BD [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\System Volume Information\_restore{1D2673A0-62B1-4202-A15D-5BEB7280A3FA}\RP165\A0132603.exe File name: A0132603.exe
Size: 3.67 MB (3670640 bytes)
MD5: 58879e11d7bd43f7dc5f149801ea1165
Detection count: 8,350
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{1D2673A0-62B1-4202-A15D-5BEB7280A3FA}\RP165\A0132603.exe
Group: Malware file
Last Updated: May 24, 2022
C:\System Volume Information\_restore{1D2673A0-62B1-4202-A15D-5BEB7280A3FA}\RP165\A0132604.exe File name: A0132604.exe
Size: 7.03 MB (7033968 bytes)
MD5: 254935c4969e78cfe09267ef4c8492d0
Detection count: 7,335
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{1D2673A0-62B1-4202-A15D-5BEB7280A3FA}\RP165\A0132604.exe
Group: Malware file
Last Updated: May 24, 2022
C:\System Volume Information\_restore{1D2673A0-62B1-4202-A15D-5BEB7280A3FA}\RP165\A0132605.exe File name: A0132605.exe
Size: 175.38 KB (175384 bytes)
MD5: 77726f336234f32c03b473934d3aa29c
Detection count: 5,612
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{1D2673A0-62B1-4202-A15D-5BEB7280A3FA}\RP165\A0132605.exe
Group: Malware file
Last Updated: May 24, 2022
%PROGRAMFILES%\AnySend\AnySendShellExtension.dll File name: AnySendShellExtension.dll
Size: 401.92 KB (401920 bytes)
MD5: 0955998c632d81a02f799555d1d3db59
Detection count: 5,462
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\AnySend\AnySendShellExtension.dll
Group: Malware file
Last Updated: June 4, 2022
C:\Users\<username>\AppData\Local\Temp\Temp\NkpmG6iFRYyBo16zdQJPPe8uNkpmG6iFRYyBo16zdQJPPe8u\NkpmG6iFRYyBo16zdQJPPe8uNkpmG6iFRYyBo16zdQJPPe8u_as.exe File name: NkpmG6iFRYyBo16zdQJPPe8uNkpmG6iFRYyBo16zdQJPPe8u_as.exe
Size: 276.51 KB (276517 bytes)
MD5: 484ec7b9a08e9daa573466579ca90afd
Detection count: 1,965
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\Temp\NkpmG6iFRYyBo16zdQJPPe8uNkpmG6iFRYyBo16zdQJPPe8u\NkpmG6iFRYyBo16zdQJPPe8uNkpmG6iFRYyBo16zdQJPPe8u_as.exe
Group: Malware file
Last Updated: October 3, 2022
%PROGRAMFILES(x86)%\AnySend\AnySendUI.exe File name: AnySendUI.exe
Size: 7.08 MB (7089240 bytes)
MD5: 2d8802c281dec3918c22e79336ee771b
Detection count: 860
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\AnySend
Group: Malware file
Last Updated: May 23, 2014
%APPDATA%\ASPackage\ASSrv.exe File name: ASSrv.exe
Size: 67.58 KB (67584 bytes)
MD5: fe73274ca09199b275d14874636b077d
Detection count: 489
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ASPackage
Group: Malware file
Last Updated: June 16, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\setup.exe File name: setup.exe
Size: 269.18 KB (269188 bytes)
MD5: 0a188596a9813ca8a672ae82000daa3d
Detection count: 297
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\setup.exe
Group: Malware file
Last Updated: December 15, 2022
%PROGRAMFILES%\AnySend\AnySendUpdater.exe File name: AnySendUpdater.exe
Size: 175.38 KB (175384 bytes)
MD5: 1c36bdecf1b28c6ee7e938b22c9d125d
Detection count: 269
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\AnySend
Group: Malware file
Last Updated: May 23, 2014
%APPDATA%\anysend.exe File name: anysend.exe
Size: 1.57 MB (1571328 bytes)
MD5: 60e6148759c4dec05cc313dd63c730d0
Detection count: 173
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: July 8, 2016
C:\Users\<username>\AppData\Local\Temp\setupA9_.exe File name: setupA9_.exe
Size: 274.43 KB (274436 bytes)
MD5: f47789c152012beeb8879ebc23d8a52e
Detection count: 110
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\setupA9_.exe
Group: Malware file
Last Updated: April 15, 2023
F:\DATOS\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\ASPackage\ASPackage.exe.vir File name: ASPackage.exe.vir
Size: 267.93 KB (267938 bytes)
MD5: d978b170d6b9f0dad258b9009f1a86e9
Detection count: 42
Mime Type: unknown/vir
Path: F:\DATOS\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\ASPackage\ASPackage.exe.vir
Group: Malware file
Last Updated: July 2, 2021
C:\Program Files\anysend\AnySendUI.exe File name: C:\Program Files\anysend\AnySendUI.exe
MD5: 0f2992cbf2612076c7c402526b3492ff
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
AnySendSvc.exe File name: AnySendSvc.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{61628E2A-4FF9-4454-992D-D92A8CD27399}{7BFFA5F9-047F-4732-93B5-B9FE731DE96D}File name without pathhttp_www.anysend.com_0.localstoragehttp_www.anysend.com_0.localstorage-journalRegexp file mask%WINDIR%\System32\Tasks\AnySendUpdateHKEY..\..\..\..{RegistryKeys}SOFTWARE\AnySendSOFTWARE\Classes\*\shellex\ContextMenuHandlers\AnySendSOFTWARE\Classes\AnySend.ConnectSOFTWARE\Classes\AnySend.Connect.1Software\Microsoft\Internet Explorer\DOMStorage\anysend.comSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{61628E2A-4FF9-4454-992D-D92A8CD27399}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AnySend User InterfaceSOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{61628E2A-4FF9-4454-992D-D92A8CD27399}SOFTWARE\Wow6432Node\AnySendSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\AnySend User InterfaceSYSTEM\ControlSet001\services\AnySendServiceSYSTEM\ControlSet002\services\AnySendServiceSYSTEM\CurrentControlSet\services\AnySendServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}AnySendASPackage{7203C44E-08F7-471D-8C9B-349A0D17506F}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\AnySend%ALLUSERSPROFILE%\Application Data\AnySend%APPDATA%\ASPackage%APPDATA%\Microsoft\Windows\Start Menu\Programs\ASPackage%APPDATA%\Microsoft\Windows\Start Menu\Programs\AnySend%PROGRAMFILES%\AnySend%PROGRAMFILES(x86)%\AnySend%appdata%\AnySend
Loading...