Home Possibly Unwanted Program PUP.2345.com

PUP.2345.com

Posted: July 13, 2015

Threat Metric

Ranking: 751
Threat Level: 1/10
Infected PCs: 279,986
First Seen: July 13, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttp_skin.ie.2345.com_0.localstorageHKEY..\..\..\..{RegistryKeys}Software\2345.comSoftware\2345ExplorerSOFTWARE\2345PicSOFTWARE\Classes\.htm\OpenWithProgIds\2345ExplorerHTMLSOFTWARE\Classes\.html\OpenWithProgIds\2345ExplorerHTMLSOFTWARE\Classes\.shtml\OpenWithProgids\2345ExplorerHTMLSOFTWARE\Classes\.webp\OpenWithProgids\2345ExplorerHTMLSOFTWARE\Classes\.xht\OpenWithProgIds\2345ExplorerHTMLSOFTWARE\Classes\.xhtml\OpenWithProgIds\2345ExplorerHTMLSOFTWARE\Classes\2345ExplorerHTMLSOFTWARE\Classes\Applications\2345Explorer.exeSoftware\Classes\http\shell\2345ExplorerSoftware\Classes\https\shell\2345ExplorerSOFTWARE\Clients\StartMenuInternet\2345ExplorerSOFTWARE\Clients\StartMenuInternet\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDITIONAL_IE8_MEMORY_CLEANUP\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_REQUIRE_VALID_MAILTO_APP_PPROTOCOL_REGISTRATION_KB941193\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION\2345Explorer.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WEBOC_OMNAVIGATOR_IMPLEMENTATION\2345Explorer.exeSOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\2345Explorer.exeSOFTWARE\Microsoft\Tracing\2345Explorer_RASAPI32SOFTWARE\Microsoft\Tracing\2345Explorer_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\2345Explorer.exeSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\2345PicViewer.exeSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids\2345Pic.bmpSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\OpenWithProgids\2345Pic.dibSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\OpenWithProgids\2345Pic.emfSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithProgids\2345Pic.gifSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids\2345Pic.icoSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\OpenWithProgids\2345Pic.jfifSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\OpenWithProgids\2345Pic.jpeSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids\2345Pic.jpegSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithProgids\2345Pic.jpgSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids\2345Pic.pngSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\OpenWithProgids\2345Pic.tifSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\OpenWithProgids\2345Pic.tiffSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\OpenWithProgids\2345Pic.wdpSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\OpenWithProgids\2345Pic.wmfSOFTWARE\RegisteredApplications\2345ExplorerSOFTWARE\Wow6432Node\2345ExplorerSOFTWARE\Wow6432Node\2345PicSOFTWARE\Wow6432Node\Clients\StartMenuInternet\2345ExplorerSOFTWARE\Wow6432Node\Microsoft\MediaPlayer\ShimInclusionList\2345Explorer.exeSOFTWARE\Wow6432Node\Microsoft\Tracing\2345Explorer_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\2345Explorer_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\2345Explorer.exeSOFTWARE\Wow6432Node\RegisteredApplications\2345ExplorerSYSTEM\ControlSet001\services\Protect_2345ExplorerSYSTEM\CurrentControlSet\services\Protect_2345ExplorerHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}2345Explorer2345Pic

Additional Information

The following directories were created:
%APPDATA%\2345Explorer%APPDATA%\2345Pic%APPDATA%\Shield_2345Explorer%LOCALAPPDATA%\2345Explorer%PROGRAMFILES%\2345Soft\2345Explorer%PROGRAMFILES%\2345Soft\2345Pic%PROGRAMFILES(x86)%\2345Soft\2345Explorer%PROGRAMFILES(x86)%\2345Soft\2345Pic%TEMP%\2345Explorer%appdata%\softmgr_2345
Loading...