Home Malware Programs Adware Adware.CandyBox

Adware.CandyBox

Posted: September 25, 2014

Threat Metric

Ranking: 8,754
Threat Level: 2/10
Infected PCs: 32,740
First Seen: September 25, 2014
Last Seen: October 12, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\AdwCleaner\quarantine\files\gvmevoopcjuymxwmeogfbmtiyxvvwcly\cab.exe File name: cab.exe
Size: 406.52 KB (406528 bytes)
MD5: 7d493febc01fb93e13e03750a862be32
Detection count: 12,181
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\AdwCleaner\quarantine\files\gvmevoopcjuymxwmeogfbmtiyxvvwcly\cab.exe
Group: Malware file
Last Updated: March 8, 2023
%SYSTEMDRIVE%\AdwCleaner\quarantine\files\gvmevoopcjuymxwmeogfbmtiyxvvwcly\aus.exe File name: aus.exe
Size: 286.2 KB (286208 bytes)
MD5: 7515019e92598852d62eeaf6c37786f6
Detection count: 12,006
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\AdwCleaner\quarantine\files\gvmevoopcjuymxwmeogfbmtiyxvvwcly\aus.exe
Group: Malware file
Last Updated: March 8, 2023
E:\Users\<username>\AppData\Local\Temp\n4695\CandyBox_2807-068a1596.exe File name: CandyBox_2807-068a1596.exe
Size: 473.95 KB (473957 bytes)
MD5: bc55ae9b027aee9e70fd8f684897243a
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: E:\Users\<username>\AppData\Local\Temp\n4695\CandyBox_2807-068a1596.exe
Group: Malware file
Last Updated: June 14, 2021

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Wow6432Node\CandyBoxHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Candy-Box_is1CandyBox_is1

Additional Information

The following directories were created:
%PROGRAMFILES%\Candy-Box%PROGRAMFILES%\CandyBox%PROGRAMFILES(x86)%\Candy-Box
Loading...