Home Malware Programs Adware PicColor

PicColor

Posted: September 17, 2014

Threat Metric

Ranking: 19,635
Threat Level: 2/10
Infected PCs: 142,449
First Seen: September 17, 2014
Last Seen: March 3, 2025
OS(es) Affected: Windows


PicColor, AKA PicColor Utility, is a browser add-on that claims to provide beneficial browser features while also loading advertisements. This loading of unwanted advertising is considered potentially undesirable, rather than a threatening behavior for software, although PicColor may cause your browser to experience performance or security issues. With the exception of unusual cases where PicColor is installed intentionally and considered desirable, most PCs users should consider using anti-adware tools to remove PicColor from their browsers.

The Add-On that doesn't Let You Pick Your Advertisements

You can install PicColor from its website, but reports of its nonconsensual delivery via alternative methods also have been confirmed by malware researchers. PicColor, like any other adware, sometimes may be installed by a Trojan downloader or other threats, but frequently is installed by third-party software bundles or intentionally mislabeled installers. While Say Media Group LTD, PicColor's developer, claims that PicColor is a beneficial product, roughly one-third of most notable PC security companies have categorized PicColor as an adware program.

Adware like PicColor is most well-known for modifying browsers to load advertisements that may include product comparisons, pop-up windows, 'enhanced' search results, transitional advertisements or banners. Undesirable symptoms malware researchers find typical with advertisements from PicColor and similar products, include increased browser loading times, misleading search results and issues with your general website interactivity. PicColor may modify more than one browser and is estimated to be fully compatible with most Windows Web-browsing products, such as Chrome, Internet Explorer and Firefox.

In their examinations of PicColor's advertisements, malware researchers also found other reasons to consider removing PicColor promptly. A minority of PicColor advertisements also included a series of software update tactics and other, toxic content that could mislead you into installing threats. Even though contact with PicColor advertising is not necessarily immediately threatening, you should strongly consider avoiding all unneeded interactions with sites or products promoted by PicColor adware, such as unusual brands of system optimization software.

Browsing the Colors of the Web without PicColor Advertisements

Uninstalling PicColor is recommendable for the security of your browser and PC, but standardized, manual removal may fail to eliminate all setting changes that are responsible for loading PicColor's advertisements. Removing adware like PicColor ordinarily should use tools specific for deleting adware. Any symptoms not covered in this article may be the result of other unwanted programs or threats installed from the same infection vector as PicColor, which may necessitate using additional security software. However, solitary PicColor installations should be simple to eliminate via system scans taken from within the Safe Mode environment, or after your PC boots from a separate hard drive.

Although a significant number of PC security companies have provided specific threat entries for PicColor, in some cases, your anti-malware products may incorrectly identify PicColor as a Trojan, such as Trojan.Win32.Generic!BT. Although PicColor does include attributes that could put your PC at risk for other attacks, PicColor doesn't harm your PC deliberately, thereby continuing to straddle the line between 'unwanted' and 'threatening' software. Updating your security tools should give them ideal opportunities to detect PicColor accurately.

Aliases

WS.Reputation.1 [Symantec]Unwanted-Program ( 004a8e8b1 ) [K7AntiVirus]Artemis!E108CBCC85FB [McAfee]Artemis!31DBF04A550C [McAfee]Generic.DFF [AVG]Riskware/PicColor [Fortinet]Artemis [McAfee-GW-Edition]ApplicUnwnt [Comodo]Artemis!B7723EB54E76 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\3a8c9699124a4506a71d46fb652dc7b1\3a8c9699124a4506a71d46fb652dc7b1.exe File name: 3a8c9699124a4506a71d46fb652dc7b1.exe
Size: 339.96 KB (339968 bytes)
MD5: c54e1261228606258da31d73d37493ec
Detection count: 1,635
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\3a8c9699124a4506a71d46fb652dc7b1
Group: Malware file
Last Updated: March 26, 2016
%ALLUSERSPROFILE%\4d0801eee76440b5aa8e9e9bd8f25f47\4d0801eee76440b5aa8e9e9bd8f25f47.exe File name: 4d0801eee76440b5aa8e9e9bd8f25f47.exe
Size: 339.96 KB (339968 bytes)
MD5: c9e4dbf40a59a54ce340ea3c4c308391
Detection count: 1,150
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\4d0801eee76440b5aa8e9e9bd8f25f47
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\1f005cc65f79462d9f0a7b88ca85c62c\1f005cc65f79462d9f0a7b88ca85c62c.exe File name: 1f005cc65f79462d9f0a7b88ca85c62c.exe
Size: 316.41 KB (316416 bytes)
MD5: 2cd41d695cc49b3a4303e3ae1384423b
Detection count: 429
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\1f005cc65f79462d9f0a7b88ca85c62c
Group: Malware file
Last Updated: December 10, 2018
%ALLUSERSPROFILE%\076de0f17486430a9cac30f03e0fc96d\076de0f17486430a9cac30f03e0fc96d.exe File name: 076de0f17486430a9cac30f03e0fc96d.exe
Size: 339.96 KB (339968 bytes)
MD5: 6042c8034de09319940451a605481413
Detection count: 426
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\076de0f17486430a9cac30f03e0fc96d
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\d6c5c2ecd29945f69948fd7d53149c77\d6c5c2ecd29945f69948fd7d53149c77.exe File name: d6c5c2ecd29945f69948fd7d53149c77.exe
Size: 345.6 KB (345600 bytes)
MD5: bde340603410039468c2dcef18f57ab3
Detection count: 356
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\d6c5c2ecd29945f69948fd7d53149c77
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\9d4504327ba74aacbbbb31ccceccf6c5\9d4504327ba74aacbbbb31ccceccf6c5.exe File name: 9d4504327ba74aacbbbb31ccceccf6c5.exe
Size: 345.6 KB (345600 bytes)
MD5: 4bf10e34466b30829c252f8bd84b8d70
Detection count: 342
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\9d4504327ba74aacbbbb31ccceccf6c5
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\5ae1342195304d05a1641dc56a00c14f\5ae1342195304d05a1641dc56a00c14f.exe File name: 5ae1342195304d05a1641dc56a00c14f.exe
Size: 339.96 KB (339968 bytes)
MD5: 756e005b39f90a981e5b174ed372da21
Detection count: 302
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\5ae1342195304d05a1641dc56a00c14f
Group: Malware file
Last Updated: September 23, 2017
C:\ProgramData\a94396dcb92441d6b8120704354d8a4c\a94396dcb92441d6b8120704354d8a4c.exe File name: a94396dcb92441d6b8120704354d8a4c.exe
Size: 316.92 KB (316928 bytes)
MD5: 0c53d99038438523b08d29fb0673ef39
Detection count: 281
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\a94396dcb92441d6b8120704354d8a4c\a94396dcb92441d6b8120704354d8a4c.exe
Group: Malware file
Last Updated: December 5, 2023
%ALLUSERSPROFILE%\dabe32db8b724140895b4725f59edce0\dabe32db8b724140895b4725f59edce0.exe File name: dabe32db8b724140895b4725f59edce0.exe
Size: 339.96 KB (339968 bytes)
MD5: 5e70c7b1d7cfa19e87318992c314bd8c
Detection count: 279
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\dabe32db8b724140895b4725f59edce0
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\926172019a8b4e14bddd1ca65ab10920\926172019a8b4e14bddd1ca65ab10920.exe File name: 926172019a8b4e14bddd1ca65ab10920.exe
Size: 316.41 KB (316416 bytes)
MD5: b99df52b5878271780d3d293009eabf1
Detection count: 274
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\926172019a8b4e14bddd1ca65ab10920
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\68380e060cd44989a7a99a71e93bbc99\68380e060cd44989a7a99a71e93bbc99.exe File name: 68380e060cd44989a7a99a71e93bbc99.exe
Size: 335.87 KB (335872 bytes)
MD5: a2f1ec7ed68d5e5403bb550384c005e9
Detection count: 272
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\68380e060cd44989a7a99a71e93bbc99
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\890cb5f003d1430780c8d0c74565cd1e\890cb5f003d1430780c8d0c74565cd1e.exe File name: 890cb5f003d1430780c8d0c74565cd1e.exe
Size: 339.96 KB (339968 bytes)
MD5: 8b4ed2a41ba02992c34b69cae885ab06
Detection count: 218
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\890cb5f003d1430780c8d0c74565cd1e
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\94d085a862584b48bcb72e5117d0a02d\94d085a862584b48bcb72e5117d0a02d.exe File name: 94d085a862584b48bcb72e5117d0a02d.exe
Size: 335.87 KB (335872 bytes)
MD5: e23942045ba9d041d625e538f658edc8
Detection count: 215
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\94d085a862584b48bcb72e5117d0a02d
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\9e3e9920a5c64672b6d01980d8ad9281\9e3e9920a5c64672b6d01980d8ad9281.exe File name: 9e3e9920a5c64672b6d01980d8ad9281.exe
Size: 319.48 KB (319488 bytes)
MD5: 44a1f9d917e65336d3d2897bc0c68376
Detection count: 215
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\9e3e9920a5c64672b6d01980d8ad9281
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\a21e3801ff3045caaba677812e6372c2\a21e3801ff3045caaba677812e6372c2.exe File name: a21e3801ff3045caaba677812e6372c2.exe
Size: 339.96 KB (339968 bytes)
MD5: be60856f5ec3ab8ca9c1750f24028b71
Detection count: 206
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\a21e3801ff3045caaba677812e6372c2
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\99bebbdfaf72437b9d2d20e4111f3f44\99bebbdfaf72437b9d2d20e4111f3f44.exe File name: 99bebbdfaf72437b9d2d20e4111f3f44.exe
Size: 335.87 KB (335872 bytes)
MD5: 003ab4dfdb65192633581c09980cad4f
Detection count: 204
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\99bebbdfaf72437b9d2d20e4111f3f44
Group: Malware file
Last Updated: April 11, 2019
%ALLUSERSPROFILE%\Application Data\56618d2a73ba476aa260529362ece56c\56618d2a73ba476aa260529362ece56c.exe File name: 56618d2a73ba476aa260529362ece56c.exe
Size: 319.48 KB (319488 bytes)
MD5: 16441038ad39334e6a915082ce2386b3
Detection count: 201
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data\56618d2a73ba476aa260529362ece56c
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\5c9ed6d8f33c476e98c64009c1e7ec4d\5c9ed6d8f33c476e98c64009c1e7ec4d.exe File name: 5c9ed6d8f33c476e98c64009c1e7ec4d.exe
Size: 345.08 KB (345088 bytes)
MD5: a2e10992129544e8e2ab1e05fbb07a8a
Detection count: 199
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\5c9ed6d8f33c476e98c64009c1e7ec4d
Group: Malware file
Last Updated: September 23, 2017
%ALLUSERSPROFILE%\datos de programa\b5faee7e99b145ec8c682adbf69c7aca\b5faee7e99b145ec8c682adbf69c7aca.exe File name: b5faee7e99b145ec8c682adbf69c7aca.exe
Size: 406.52 KB (406528 bytes)
MD5: 4ee3c4d63fc27a04ea402e3139b68c69
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\datos de programa\b5faee7e99b145ec8c682adbf69c7aca
Group: Malware file
Last Updated: March 26, 2016
%ALLUSERSPROFILE%\688bac24d8294ddc9b97a10de5058423\688bac24d8294ddc9b97a10de5058423.exe File name: 688bac24d8294ddc9b97a10de5058423.exe
Size: 381.44 KB (381440 bytes)
MD5: 7459d4fe3e1f46d4b7cc5d1bb8a0c403
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\688bac24d8294ddc9b97a10de5058423
Group: Malware file
Last Updated: March 26, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%TEMP%\PIcColor_setup.exe%WINDIR%\System32\ColorMedia.dll%WINDIR%\System32\Drivers\cmwf.sys%WINDIR%\System32\Drivers\cmwr.sysHKEY..\..\..\..{RegistryKeys}SYSTEM\ControlSet001\Services\cmwfSYSTEM\ControlSet001\Services\cmwrSYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\cmwf.sysSYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\cmwr.sysSYSTEM\CurrentControlSet\Control\SafeBoot\Network\cmwf.sysSYSTEM\CurrentControlSet\Control\SafeBoot\Network\cmwr.sysHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}PicColor Utility

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\PicColor Utility%ALLUSERSPROFILE%\PicColorData
Loading...