Home Malware Programs Adware Jollywallet

Jollywallet

Posted: March 7, 2013

Threat Metric

Ranking: 7,721
Threat Level: 2/10
Infected PCs: 21,121
First Seen: March 7, 2013
Last Seen: October 11, 2023
OS(es) Affected: Windows

Jollywallet is adware known for displaying repeated annoying advertisements attempting to promote savings on online shopping items. Jollywallet may come in a toolbar form where it also offers sharing and shipping features. Many times Jollywallet will load random pop-up messages that could redirect users to unwanted sites promoting products. Jollywallet may be installed with bundled software where it continues to run through the toolbar displayed on web browser applications. Removing or uninstalling may prove to be difficult due to Jollywallet not being listed with a correct name in the list of installed apps within the add/remove programs or files and programs feature in the Windows control panel. Automatic removal of Jollywallet is often performed with the use of an antispyware application.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



jollywallet_99_2.exe File name: jollywallet_99_2.exe
Size: 2.72 MB (2720120 bytes)
MD5: 0f17f7e4a7fd45360b92e3cfb312dea4
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110111251155}{22222222-2222-2222-2222-220122252255}{44444444-4444-4444-4444-440144254455}{55555555-5555-5555-5555-550155255555}{66666666-6666-6666-6666-660166256655}File name without pathhttp_www.jollywallet.com_0.localstoragehttp_www.jollywallet.com_0.localstorage-journalRegexp file mask%TEMP%\jollywallet[RANDOM CHARACTERS]%WINDIR%\System32\Tasks\jollywallet-chromiuminstaller%WINDIR%\System32\Tasks\jollywallet-codedownloader%WINDIR%\System32\Tasks\jollywallet-updater%WINDIR%\System32\Tasks\jollywallet-updater_user%WINDIR%\Tasks\jollywallet-chromiuminstaller.job%WINDIR%\Tasks\jollywallet-codedownloader.job%WINDIR%\Tasks\jollywallet-updater.job%WINDIR%\Tasks\jollywallet-updater_user.jobHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Crossrider\Button\12555Software\AppDataLow\Software\Crossrider\onBeforeNavigate\12555Software\AppDataLow\Software\Crossrider\onRequest\12555Software\AppDataLow\Software\JollyWalletSOFTWARE\Classes\CrossriderApp0012555.BHOSOFTWARE\Classes\CrossriderApp0012555.BHO.1SOFTWARE\Classes\CrossriderApp0012555.SandboxSOFTWARE\Classes\CrossriderApp0012555.Sandbox\CLSIDSOFTWARE\Classes\CrossriderApp0012555.Sandbox\CurVerSoftware\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\jollywalletSoftware\Cr_Installer\12555Software\InstalledBrowserExtensions\JollyWalletSOFTWARE\jollywalletSoftware\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110111251155}Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{11111111-1111-1111-1111-110111251155}Software\Microsoft\Internet Explorer\DOMStorage\jollywallet.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.jollywallet.comSoftware\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7b26e61c-045a-4607-82af-995a89b789f4}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ce6c9745-5ad7-4f85-a9c0-2f67c8801385}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d41f9bdf-97dd-4f7b-9841-4a8d2fe93269}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dfd7d9b1-1cc1-4d8a-bf44-b9879446a65d}Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\jollywallet.comSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\jollywallet-bg.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater12555.exeSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110111251155}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110111251155}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110111251155}SOFTWARE\Wow6432Node\jollywalletSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111251155}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110111251155}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\jollywallet-bg.exeSOFTWARE\Wow6432Node\Microsoft\Tracing\JollyWallet-InternalInstaller_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\JollyWallet-InternalInstaller_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\JollyWallet_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\JollyWallet_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111251155}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110111251155}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}JollyWallet

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\nebgmadhfahbjejndohjkhofghapnhhl%LOCALAPPDATA%\JollyWallet%LOCALAPPDATA%\Updater12555%PROGRAMFILES%\JollyWallet%PROGRAMFILES(x86)%\JollyWallet%UserProfile%\AppData\LocalLow\jollywallet

One Comment

  • Weslynn says:

    Is there any way you can tell me all this in layman language??? Am not very savvy with all the technology, but this is worse than greek to me....

Loading...