Home Possibly Unwanted Program PUP.Skymonk

PUP.Skymonk

Posted: January 20, 2014

Threat Metric

Ranking: 3,425
Threat Level: 1/10
Infected PCs: 45,566
First Seen: January 20, 2014
Last Seen: March 9, 2025
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\Skymonk2Plugin\KangoBHO.dll File name: KangoBHO.dll
Size: 251.39 KB (251392 bytes)
MD5: 5c7703f9d55754ae94a3a6762ba2063c
Detection count: 5,876
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Skymonk2Plugin\KangoBHO.dll
Group: Malware file
Last Updated: January 26, 2024
D:\System Volume Information\_restore{2CB420A6-A62D-48F5-B8CD-041895010AA6}\RP372\A0228118.exe File name: A0228118.exe
Size: 372.22 KB (372224 bytes)
MD5: 9c7504c35fe0d74191450dda37c1d294
Detection count: 1,946
File type: Executable File
Mime Type: unknown/exe
Path: D:\System Volume Information\_restore{2CB420A6-A62D-48F5-B8CD-041895010AA6}\RP372\A0228118.exe
Group: Malware file
Last Updated: March 9, 2022
C:\Program Files (x86)\Skymonk2Plugin\KangoBHO64.dll File name: KangoBHO64.dll
Size: 301.05 KB (301056 bytes)
MD5: 7fbef60a8dc5137b6971050b67fcd2be
Detection count: 1,557
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Skymonk2Plugin\KangoBHO64.dll
Group: Malware file
Last Updated: January 26, 2024
D:\System Volume Information\_restore{2CB420A6-A62D-48F5-B8CD-041895010AA6}\RP276\A0192150.exe File name: A0192150.exe
Size: 364.54 KB (364544 bytes)
MD5: 28ea6cf6cb79d3125d29e2182b9c6645
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: D:\System Volume Information\_restore{2CB420A6-A62D-48F5-B8CD-041895010AA6}\RP276\A0192150.exe
Group: Malware file
Last Updated: January 2, 2022
%LOCALAPPDATA%\Skymonk2\skymonk2.exe File name: skymonk2.exe
Size: 561.8 KB (561808 bytes)
MD5: c2b1dd471aec25157aca81d69a25a8d2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Skymonk2
Group: Malware file
Last Updated: January 20, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{2434971D-DF3B-43DA-B810-7A44F62317A5}{49203157-9761-467F-B689-D0CCB7E83923}{49D931C3-97C7-46BF-850F-83CC98E81623}{88AD246E-288C-4950-BEBF-140DFDD28240}{88B8244F-28A7-49E3-ABB2-180D65D2E640}{A923CA26-988F-4FE5-B1F5-B3DD3F3D6F4A}{A9E7CA1D-9850-4FCF-8498-4CDDE83DEA4A}{E71A8D5A-B484-4D39-9364-40134F50FFE9}File name without pathContinue installation - SkyMonk Installation.lnkSkymonk 2.lnkHKEY..\..\..\..{RegistryKeys}Software\Classes\skymonkSoftware\Microsoft\Internet Explorer\Approved Extensions\{49D931C3-97C7-46BF-850F-83CC98E81623}Software\Microsoft\Internet Explorer\Approved Extensions\{A923CA26-988F-4FE5-B1F5-B3DD3F3D6F4A}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2434971D-DF3B-43DA-B810-7A44F62317A5}Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\KangoEngine.exeSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A923CA26-988F-4FE5-B1F5-B3DD3F3D6F4A}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{49D931C3-97C7-46BF-850F-83CC98E81623}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A923CA26-988F-4FE5-B1F5-B3DD3F3D6F4A}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{49D931C3-97C7-46BF-850F-83CC98E81623}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A923CA26-988F-4FE5-B1F5-B3DD3F3D6F4A}Software\Microsoft\Windows\CurrentVersion\Run\Skymonk2Software\Microsoft\Windows\CurrentVersion\Uninstall\Skymonk2SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Skymonk2PluginSoftware\Services\Sm2SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2434971D-DF3B-43DA-B810-7A44F62317A5}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\KangoEngine.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A923CA26-988F-4FE5-B1F5-B3DD3F3D6F4A}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Skymonk2Plugin

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Skymonk 2%APPDATA%\{A923CA26-988F-4FE5-B1F5-B3DD3F3D6F4A}%LOCALAPPDATA%\Skymonk2%PROGRAMFILES%\Skymonk2Plugin%PROGRAMFILES(x86)%\Skymonk2Plugin%USERPROFILE%\AppData\LocalLow\{A923CA26-988F-4FE5-B1F5-B3DD3F3D6F4A}%USERPROFILE%\Local Settings\Application Data\Skymonk2
The following URL's were detected:
Skymonk
Loading...