Home Malware Programs Potentially Unwanted Programs (PUPs) PUP.ChinAd

PUP.ChinAd

Posted: October 22, 2013

Threat Metric

Ranking: 221
Threat Level: 8/10
Infected PCs: 637,770
First Seen: October 22, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

PUP.ChinAd is a potentially unwanted program that may display random ads or ads related to the web user's browsing habits on popular online shopping and social networking websites that PC users usually visit. These random advertisements of PUP.ChinAd may be displayed as boxes that contain a variety of available coupons or as underlined keywords, which when clicked may show a random advertisement that declares it is sent to the web user by PUP.ChinAd. PUP.ChinAd may embed a browser plug-in, add-on or extension for Internet Explorer, Mozilla Firefox, and Google Chrome that may usually be installed when the computer user downloads and installs other free applications. When the computer user installs these free applications, he may also install PUP.ChinAd on the PC. Once PUP.ChinAd is installed, it may display a 'See Similar' icon next to the image of the product on numerous online shopping websites. PUP.ChinAd may also show deals, coupons and offers on the affiliated product websites. Sometimes, by clicking on a given offer, the PC user may get rerouted to the doubtful advertising website, which was designed by web attackers to possibly boost traffic and earn money from click fraud.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



E:\5902551604822016\88518b16abdae9f65dcdda44588bc060826e90dd40ba58abeec55397bce85167 File name: 88518b16abdae9f65dcdda44588bc060826e90dd40ba58abeec55397bce85167
Size: 1.93 MB (1935360 bytes)
MD5: 5c1e55872eee347aab9986cebd50e352
Detection count: 204
Path: E:\5902551604822016\88518b16abdae9f65dcdda44588bc060826e90dd40ba58abeec55397bce85167
Group: Malware file
Last Updated: July 15, 2022
%SYSTEMDRIVE%\Users\<username>\desktop\raffle.exe File name: raffle.exe
Size: 1.78 MB (1787208 bytes)
MD5: 663fbf2a248971ea69c6234480a4bdcb
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\desktop
Group: Malware file
Last Updated: October 26, 2019
%ALLUSERSPROFILE%\DreamScreen\DreamScreen.scr File name: DreamScreen.scr
Size: 5.3 MB (5304832 bytes)
MD5: 719e1b98d3255693303adf38abbf0cd6
Detection count: 54
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%\DreamScreen
Group: Malware file
Last Updated: September 27, 2017
C:\Program Files (x86)\hmrl\RlDateSet.exe File name: RlDateSet.exe
Size: 962.32 KB (962328 bytes)
MD5: 3f73a23886f2109e11882f5a600d3c24
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\hmrl\RlDateSet.exe
Group: Malware file
Last Updated: October 22, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{7237A7B9-A57A-47F7-AA32-542848F408E1}{97510FAC-ED50-46BF-B2A1-25F434BF1030}Regexp file mask%WINDIR%\system32\drivers\lanmamaster.sysHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\DongFangImeDictFileSOFTWARE\Classes\DongFangImeSkinFileSOFTWARE\DongFangSOFTWARE\DongFangInputSOFTWARE\DongFangServiceSOFTWARE\Google\Chrome\NativeMessagingHosts\com.haitao.chrome.namsg.ht1haoSOFTWARE\TXlTb2Z0Software\WanNengWBSOFTWARE\WanNengWBInputSOFTWARE\WanNengWBServiceSoftware\WanNengZipHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}万能五笔内置版万能压缩东方输入法

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\DreamScreen%ALLUSERSPROFILE%\ailiaoweb%APPDATA%\DreamScreen%APPDATA%\Microsoft\Windows\Start Menu\Programs\HT1H%APPDATA%\TravelCheap%APPDATA%\calfwallpaper%APPDATA%\fwsrv%APPDATA%\haotukankan%APPDATA%\jyzip%APPDATA%\lehold%APPDATA%\ptsandf%COMMONPROGRAMFILES%\dongfanginput%COMMONPROGRAMFILES(X86)%\dongfanginput%HOMEDRIVE%\beloved521%LOCALAPPDATA%\haotukankan%LOCALAPPDATA%\htyh%PROGRAMFILES%\WanNengWBInput%PROGRAMFILES%\ZHPDFReader%PROGRAMFILES%\bianya%PROGRAMFILES%\bianya2%PROGRAMFILES%\dongfanginput%PROGRAMFILES%\fastwifi%PROGRAMFILES%\flushcopy%PROGRAMFILES%\gmbox%PROGRAMFILES%\kbox%PROGRAMFILES%\mainexe%PROGRAMFILES%\pandapdf%PROGRAMFILES%\puddingzip%PROGRAMFILES%\scwbwordsvc%PROGRAMFILES%\scwordsvc%PROGRAMFILES%\worthyshop%PROGRAMFILES(x86)%\WanNengWBInput%PROGRAMFILES(x86)%\ZHPDFReader%PROGRAMFILES(x86)%\ailiao%PROGRAMFILES(x86)%\bianya%PROGRAMFILES(x86)%\bianya2%PROGRAMFILES(x86)%\dongfanginput%PROGRAMFILES(x86)%\fastwifi%PROGRAMFILES(x86)%\flushcopy%PROGRAMFILES(x86)%\gmbox%PROGRAMFILES(x86)%\kbox%PROGRAMFILES(x86)%\mainexe%PROGRAMFILES(x86)%\pandapdf%PROGRAMFILES(x86)%\puddingzip%PROGRAMFILES(x86)%\scwbwordsvc%PROGRAMFILES(x86)%\scwordsvc%PROGRAMFILES(x86)%\worthyshop%PROGRAMFILES(x86)%\xsqxz%USERPROFILE%\Local Settings\Application Data\htyh%UserProfile%\Local Settings\Application Data\haotukankan%appdata%\EverydayWallpaper%appdata%\commander%appdata%\fpsmaste%appdata%\fypdfconvert%appdata%\inkmgsrv%appdata%\jisusearch%appdata%\jjsciktynotes%appdata%\kaobeitu%appdata%\lpsrvrt%appdata%\nvsofthelpex%appdata%\qiaozip%appdata%\qiaozipzhuomianup%appdata%\screenocr%appdata%\secondsearch%appdata%\seenstamine%appdata%\smartdesktop%appdata%\webappplugin%appdata%\xbpic%appdata%\xbpicviewer%appdata%\xfpdf%homedrive%\wannengwbinput%localappdata%\qiaozip%temp%\fmpskin%windir%\SysWOW64\IME\WanNengWB%windir%\System32\IME\WanNengWB
Loading...