Home Malware Programs Adware Boxore Client

Boxore Client

Posted: November 6, 2012

Threat Metric

Ranking: 3,518
Threat Level: 2/10
Infected PCs: 54,421
First Seen: November 6, 2012
Last Seen: October 14, 2023
OS(es) Affected: Windows

The Boxore Client software that is published by Boxore OU is promoted at Boxore.com as a shopping advisor that can make product recommendations based on your online preferences, and help you make smart purchases. One of the main selling points of the Boxore Client app is that your anonymity is guaranteed as well as your safety, but that is not entirely accurate. Security analysts took a look at the source code of the Boxore Client app and reported that it falls into the category of adware such as OpenCandy and Multiplug. The Boxore Client adware is not a safe application because it may redirect users to corrupted Web pages that may host the Neutrino Exploit Kit and users may find their Windows unresponsive at times. The ads by Boxore Client may be injected into your Internet client via a browser plug-in, extension, add-on and Browser Helper Object. There are many variants of the Boxore Client adware that are packed as XPI, CRX, DLL and BHO files, and may be signed with outdated and insecure digital signatures. Computer users that are infected with the Boxore Client adware may be vulnerable to Man-in-the-Middle attacks and should remove the Boxore Client adware sooner rather than later. Web surfers that are having problems with the products of Boxore OU report that they may be provided with customer surveys and can not close the pop-ups by Boxore Client unless they answer all questions on the survey. As stated above, the Boxore Client adware may not protect your privacy and may perform a system-wide scan to build a unique advertising profile about you. The Boxore Client adware may index your video and image collection, as well as browsing history and software configuration. The Boxore Client adware may send the scan log to untrusted advertisers for market development purposes, and you might not like that. The Boxore Client adware should not be tolerated, and you should take action by installing a reputable anti-malware tool that can purge the Boxore Client adware from your PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\Boxore\Boxore Client\boxore.exe File name: boxore.exe
Size: 1.55 MB (1551872 bytes)
MD5: da40115130f766c1e19b5b87d13031e5
Detection count: 4,136
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Boxore\Boxore Client\boxore.exe
Group: Malware file
Last Updated: April 16, 2022
%PROGRAMFILES(x86)%\Boxore\Boxore Client\boxore.exe File name: boxore.exe
Size: 1.52 MB (1527808 bytes)
MD5: a14d72b43d5138e18629253f77abf5cb
Detection count: 1,157
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Boxore\Boxore Client\boxore.exe
Group: Malware file
Last Updated: June 3, 2022
C:\Config.Msi\a5a4f57.rbf File name: a5a4f57.rbf
Size: 1.52 MB (1527296 bytes)
MD5: 6a55808ee98ff5390f3e155a63a3fcfc
Detection count: 1,021
Mime Type: unknown/rbf
Path: C:\Config.Msi\a5a4f57.rbf
Group: Malware file
Last Updated: July 1, 2023
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\Boxore\Boxore Client\IE\AdRotateEngine.exe.vir File name: AdRotateEngine.exe.vir
Size: 4.34 MB (4348416 bytes)
MD5: 7152e524cad3c103170f1be405a82348
Detection count: 408
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\Boxore\Boxore Client\IE\AdRotateEngine.exe.vir
Group: Malware file
Last Updated: May 19, 2023
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Boxore\Boxore Client\boxore.exe.vir File name: boxore.exe.vir
Size: 1.53 MB (1538560 bytes)
MD5: 5cb2e8a9b6935f228623c69f1b17669d
Detection count: 365
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\Boxore\Boxore Client\boxore.exe.vir
Group: Malware file
Last Updated: January 26, 2023
C:\Program Files\Boxore\Boxore Client\IE\AdRotate32.dll File name: AdRotate32.dll
Size: 605.69 KB (605696 bytes)
MD5: 83a0cd2184e7a0fe1601ff12de76cb8b
Detection count: 251
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files\Boxore\Boxore Client\IE\AdRotate32.dll
Group: Malware file
Last Updated: April 6, 2022
%PROGRAMFILES%\Boxore\Boxore Client\boxore.exe File name: boxore.exe
Size: 1.55 MB (1550336 bytes)
MD5: 03ca22c2c216d067ef022dc2f0f2a942
Detection count: 131
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Boxore\Boxore Client
Group: Malware file
Last Updated: May 25, 2017
C:\Program Files (x86)\MediaStreamingAgent\MediaStreamingAgent\LSP\MediaStreamingService.exe File name: MediaStreamingService.exe
Size: 1.7 MB (1706696 bytes)
MD5: 22f646f8e484092b8a1dced89419da11
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\MediaStreamingAgent\MediaStreamingAgent\LSP\MediaStreamingService.exe
Group: Malware file
Last Updated: April 9, 2023
%PROGRAMFILES%\Boxore\Boxore Client\boxore.exe File name: boxore.exe
Size: 1.52 MB (1527808 bytes)
MD5: 82159da0de06a96963a5e3a22553d0a7
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Boxore\Boxore Client
Group: Malware file
Last Updated: May 25, 2017
%PROGRAMFILES%\Boxore\BoxoreClient\boxore.exe File name: boxore.exe
Size: 1.72 MB (1724728 bytes)
MD5: d9578ee38d39788a90a0ceadb99b21c0
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Boxore\BoxoreClient
Group: Malware file
Last Updated: February 22, 2013
C:\AdwCleaner\quarantine\files\olfpqkwjcjvjhwswsfrlzuagxgcaiyco\MediaStreamingAgent\MediaStreamingAgent.exe File name: MediaStreamingAgent.exe
Size: 1.18 MB (1187328 bytes)
MD5: 310cafa58e1080e803c3782d5d8d184f
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: C:\AdwCleaner\quarantine\files\olfpqkwjcjvjhwswsfrlzuagxgcaiyco\MediaStreamingAgent\MediaStreamingAgent.exe
Group: Malware file
Last Updated: April 23, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{00224814-F11C-4357-A1E6-5345F66798C8}{076776F6-8E36-4D3D-A75A-7C4B0A5FAC61}{1518FA02-18F0-4D80-A2CF-D221AD887B38}{1BD46251-EC44-496E-8A3D-2A4D285E68A4}{286EE0A4-E572-4CC1-AB12-0C3359C0201D}{32679C14-9FEF-4DC9-88D6-14D5A5587B67}{3394B039-70BF-4F83-AF34-6D886AB97085}{33BEDC51-AA3C-4B11-AAC8-257667B247A8}{354D0176-9715-40AA-9665-0E2747379310}{3B2B7614-6FBC-468D-B534-2C0F06A12FDE}{44D495FC-7300-40F1-B494-9BB64D799174}{4DD76FEC-1519-45BC-B4F7-22DD3AF9B56E}{50021174-55B0-40C0-BCD0-75A8C0E7072D}{56AEAB10-6187-43BD-AF5E-9F245651EA2B}{60C5C7A9-1DFD-49DB-A22C-482D6B5CC6BC}{6A9551A5-F227-4325-9D8F-F53C7B43CA6C}{74A6CDF3-241B-47BF-8650-D493C13C588C}{757377F6-39AB-4878-BB21-9918A035B510}{785737C7-59F0-4E5E-B950-1B29726DF1E3}{7871A888-97D7-42F8-9E16-5F6E9878A99A}{7D9C562A-2C8D-473D-9EB7-849DBC820271}{85A37EAE-E569-4FA5-A1E0-E503035AFD77}{945A681B-5BDD-497C-9149-E651FC3A45A9}{9AD3F4DB-0AEB-4E50-85DD-63442AA2DDCB}{9B4CCACF-7D79-4E4C-9F67-DCC8400385B8}{9DF4FCCD-B6C8-4E84-A60E-DE8BFC8388A8}{A55EBD18-B813-4464-A2C3-BDC736F2DEFB}{A619E354-3358-4B89-BD8F-CC17065C4977}{A98D3705-537E-4CB8-B44F-31715692E997}{ACB7A18B-BDF0-486C-95ED-D9A4BE8B8F54}{B5449E8D-FA6B-41F3-A7B5-C148504AFAEC}{B7458E35-9A9E-43D9-BD94-01FEBC5064E4}{C0FE3821-40E9-4626-B43A-D969A831EB14}{C3CAF5AA-DEF8-4E03-BE5D-AD15FA0433B7}{C3E0B25C-E790-4856-B200-9E6691B310A4}{C5B840DD-2B3C-45CB-B28F-E10A5EACEF2E}{CC99D6D8-8CC8-44B9-88FC-712F7422CD60}{D2DC209D-1D85-4D23-B665-5DC748C090EC}{D4B9CCC7-65B2-4A30-9658-40D535E5848E}{D6CDDF8E-D133-46A1-948C-6050E1956171}{DDB2E4CB-73F5-4350-B6DC-A1615BCB0734}{DEF096FE-9095-48F4-BB57-7014F75B04DD}{E003F5D3-5BA8-4B9A-B707-359FEDD4EAEC}{E42FEB55-F337-4778-BD69-D02F8930BACB}{EA077208-C4B6-47F3-B9F9-AC0282772C78}{ECE249B9-2C98-4611-B385-45459C5AACCD}{F9141F2C-E01F-4C4F-83CB-5E6A85B2CBB8}{FCF89692-B2DB-4527-B6C8-C554200C7521}File name without pathhttp_www.boxore.com_0.localstoragehttp_www.boxore.com_0.localstorage-journalwww.boxore[1].xmlRegexp file mask%WINDIR%\System32\BoxoreService.dll%WINDIR%\SysWOW64\BoxoreService.dllHKEY..\..\..\..{RegistryKeys}Software\BoxoreSOFTWARE\BoxoreServiceSOFTWARE\Classes\AppID\BoxoreService.exeSOFTWARE\Classes\Installer\Features\9BB106980C8CD3949921DAF7159A813ASOFTWARE\Classes\Installer\Features\9FEB8FB96CD4CF54A95AB4311193C2DASOFTWARE\Classes\Installer\Features\A07B748F92CF28B478E2852FECD9EE90SOFTWARE\Classes\Installer\Features\ADF563E0F909939438A862D14D868D26SOFTWARE\Classes\Installer\Features\E8E877ED6825FF148AE54DA13648DD38SOFTWARE\Classes\Installer\Products\A07B748F92CF28B478E2852FECD9EE90SOFTWARE\Classes\Installer\Products\ADF563E0F909939438A862D14D868D26SOFTWARE\Classes\Installer\Products\E8E877ED6825FF148AE54DA13648DD38SOFTWARE\MediaStreamingAgentSoftware\Microsoft\Internet Explorer\Approved Extensions\{EFA7A511-B491-4312-BB35-4586B99E45ED}Software\Microsoft\Internet Explorer\DOMStorage\boxore.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.boxore.comSOFTWARE\Microsoft\Windows\CurrentVersion\Run\MediaStreamingAgentSOFTWARE\Software\Update\ClientState\{5B54E9B6-D6C4-11E0-8E9D-92FB4824019B}SOFTWARE\Software\Update\ClientStateMedium\{5B54E9B6-D6C4-11E0-8E9D-92FB4824019B}SOFTWARE\Wow6432Node\BoxoreSOFTWARE\Wow6432Node\BoxoreServiceSOFTWARE\Wow6432Node\Google\Chrome\Extensions\jeaihkehdlhkocphopopahkfjcfcphefSOFTWARE\Wow6432Node\MediaStreamingAgentSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\BoxoreSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Boxore ClientSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\MediaStreamingAgentSOFTWARE\Wow6432Node\Software\Update\Clients\{5B54E9B6-D6C4-11E0-8E9D-92FB4824019B}SOFTWARE\Wow6432Node\Software\Update\ClientState\{5B54E9B6-D6C4-11E0-8E9D-92FB4824019B}SOFTWARE\Wow6432Node\Software\Update\ClientStateMedium\{5B54E9B6-D6C4-11E0-8E9D-92FB4824019B}SYSTEM\ControlSet001\Control\SafeBoot\Network\BoxoreServiceSYSTEM\ControlSet001\services\BoxoreServiceSYSTEM\ControlSet002\Control\SafeBoot\Network\BoxoreServiceSYSTEM\CurrentControlSet\Control\SafeBoot\Network\BoxoreServiceSYSTEM\CurrentControlSet\services\BoxoreServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{0E365FDA-909F-4939-838A-261DD468D862}{47BA91BB-CD0D-4208-BF6E-B8EF32BD5D54}{49F1E961-77E0-441D-917E-9F938801BCDA}{9953E458-EBBE-4B2C-BC73-5DEE10AC617F}{BC95F9C5-A038-45EE-A739-96B8A6D79F7D}{D8D8A342-0E9F-47EA-A35E-CF431B50B286}{DE778E8E-5286-41FF-A85E-D41A6384DD83}{E199C882-78F1-45F1-9D8A-3DD3AF97A7C0}{F847B70A-FC29-4B82-872E-58F2CE9DEE09}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\Boxore%ALLUSERSPROFILE%\Boxore%LOCALAPPDATA%\Boxore%PROGRAMFILES%\Boxore%PROGRAMFILES%\Boxore\BoxoreClient%PROGRAMFILES%\MediaStreamingAgent%PROGRAMFILES(X86)%\Boxore%PROGRAMFILES(x86)%\Boxore\BoxoreClient%PROGRAMFILES(x86)%\MediaStreamingAgent%UserProfile%\Local Settings\Application Data\Boxore%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\Boxore%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\BoxoreService%WINDIR%\System32\config\systemprofile\AppData\Local\Boxore%WINDIR%\System32\config\systemprofile\AppData\Local\BoxoreService
Loading...