Home Malware Programs Adware Adware.KeyDownload

Adware.KeyDownload

Posted: February 14, 2014

Threat Metric

Ranking: 11,601
Threat Level: 2/10
Infected PCs: 51,016
First Seen: February 14, 2014
Last Seen: October 8, 2023
OS(es) Affected: Windows


Adware.KeyDownload is adware that may insert an unwanted add-on, plug-in or browser extension on popular Web browsers such as Internet Explorer, Mozilla Firefox and Google Chrome. Once installed on the computer system, Adware.KeyDownload may display disturbing pop-up advertisements, messages and banners carrying various online discount deals, saving coupons, sales and other offers. Adware.KeyDownload may seem to be a useful tool to online shoppers. However, in fact, Adware.KeyDownload may be considered to be a potentially unwanted application if it integrates into the PC without the computer user's approval. Adware.KeyDownload may also spread and enter the PC as an extra program through bundled freeware that computer users can download from unreliable download websites. Adware.KeyDownload may track the PC user's surfing habits and gather browsing details that may later be used with the aim to deliver targeted advertisements. Adware.KeyDownload may be created with the goal to generate advertising income from clicks on ads and raised Internet traffic.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Local\Temp\KDUpdSrv.exe File name: KDUpdSrv.exe
Size: 229.69 KB (229696 bytes)
MD5: 28464ed23eca4fedb103778f5b9d1e0d
Detection count: 4,502
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\KDUpdSrv.exe
Group: Malware file
Last Updated: July 11, 2023
%PROGRAMFILES%\Keyplayer Classic\Extension32.dll File name: Extension32.dll
Size: 168.44 KB (168448 bytes)
MD5: 45a3b5bbd4c35d7e36cfc795e8054395
Detection count: 1,565
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Keyplayer Classic
Group: Malware file
Last Updated: July 3, 2014
%TEMP%\kdupdsrv.exe File name: kdupdsrv.exe
Size: 217.92 KB (217920 bytes)
MD5: b5cf24fd6db378d9d922025b9f3cd246
Detection count: 766
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: January 8, 2019
%TEMP%\kdupdsrv.exe File name: kdupdsrv.exe
Size: 216.38 KB (216384 bytes)
MD5: 4440855c958337d91afda2e7b949c8f7
Detection count: 342
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: July 26, 2020
%TEMP%\kdupdsrv.exe File name: kdupdsrv.exe
Size: 228.16 KB (228160 bytes)
MD5: 88093e7d732bcb6af309b831115632de
Detection count: 185
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: May 21, 2016
%PROGRAMFILES%\Keyplayer Classic\NMHClient.exe File name: NMHClient.exe
Size: 428.54 KB (428544 bytes)
MD5: 18d4ab4a67d5c8c96c37a5800e29c518
Detection count: 152
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Keyplayer Classic
Group: Malware file
Last Updated: July 3, 2014
KeyPlayerV0.exe File name: KeyPlayerV0.exe
Size: 228.86 KB (228864 bytes)
MD5: a57433829b2fed953119b4bb85dbe884
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: July 29, 2014
%PROGRAMFILES%\Keyplayer Classic\NMHClient.exe File name: NMHClient.exe
Size: 379.39 KB (379392 bytes)
MD5: 05d73f4ac451b1f50cdd4e9200dad17f
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Keyplayer Classic
Group: Malware file
Last Updated: July 3, 2014
%PROGRAMFILES(x86)%\KeyDownload\KeyDownload-codedownloader.exe File name: KeyDownload-codedownloader.exe
Size: 526.52 KB (526528 bytes)
MD5: ee7d558b85f5f98d71c0d1a5101709ea
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\KeyDownload
Group: Malware file
Last Updated: June 17, 2014
%PROGRAMFILES(x86)%\KeyDownload\KeyDownload-enabler.exe File name: KeyDownload-enabler.exe
Size: 345.79 KB (345792 bytes)
MD5: 0e41d784ae6a8324da1414782f4aef78
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\KeyDownload
Group: Malware file
Last Updated: June 17, 2014
%PROGRAMFILES(x86)%\KeyDownload\KeyDownload-firefoxinstaller.exe File name: KeyDownload-firefoxinstaller.exe
Size: 888.51 KB (888512 bytes)
MD5: b5d889e840f1ec9daaeb0927962f7c4a
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\KeyDownload
Group: Malware file
Last Updated: June 17, 2014
%PROGRAMFILES(x86)%\KeyDownload\KeyDownload-updater.exe File name: KeyDownload-updater.exe
Size: 356.03 KB (356032 bytes)
MD5: 63555254fc4067dceea40d2ee59f1a5d
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\KeyDownload
Group: Malware file
Last Updated: June 17, 2014
%PROGRAMFILES(x86)%\KeyDownload\KEYPLAYER\keyplayer.exe File name: keyplayer.exe
Size: 62.46 KB (62464 bytes)
MD5: fe3e8788e0c017d623be86a48a60e932
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\KeyDownload\KEYPLAYER
Group: Malware file
Last Updated: June 17, 2014
%PROGRAMFILES(x86)%\KeyDownload\KeyDownload-codedownloader.exe File name: KeyDownload-codedownloader.exe
Size: 555.71 KB (555712 bytes)
MD5: 08802c3fccc6883df22a56f13ad1054b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\KeyDownload
Group: Malware file
Last Updated: February 14, 2014
%PROGRAMFILES(x86)%\KeyDownload\KeyDownload-enabler.exe File name: KeyDownload-enabler.exe
Size: 407.23 KB (407232 bytes)
MD5: 3e7c148a94d8fc93e334d63eebdd6773
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\KeyDownload
Group: Malware file
Last Updated: February 14, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{6FFA0D01-9182-48AA-98C9-AE5E64757FCC}{7DDBC31B-22BD-4BBD-9F65-E8623814F3BB}{C1EA4179-A319-4c6a-A3E5-67FF3592A12E}File name without pathKEYPLAYER media player.lnkKeyPlayer.lnkHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\KeyDownload1SOFTWARE\Classes\AppID\KeyDownload.DLLSOFTWARE\Classes\AppID\{C2178B36-2955-479B-818C-A2AE8E500454}SOFTWARE\Classes\Applications\keyplayer.exeSOFTWARE\Classes\AudioCD\shell\PlayWithKEYPLAYERSOFTWARE\Classes\Directory\shell\AddToPlaylistKEYPLAYERSOFTWARE\Classes\Directory\shell\PlayWithKEYPLAYERSOFTWARE\Classes\DVD\shell\PlayWithKEYPLAYERSOFTWARE\Classes\KeyDownload.KeyDownloadSOFTWARE\Classes\KeyDownload.KeyDownload.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\KeyDownload1SOFTWARE\Classes\Wow6432Node\AppID\KeyDownload.DLLSOFTWARE\Classes\Wow6432Node\AppID\{C2178B36-2955-479B-818C-A2AE8E500454}SOFTWARE\Clients\Media\KEYPLAYERSOFTWARE\KeyDownloadSOFTWARE\Keyplayer ClassicSoftware\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311051129}Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411781116}Software\Microsoft\Internet Explorer\Approved Extensions\{BEE7841B-3C8B-46EA-AFE9-8461458BB2C1}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\KeyDownload-bg.exeSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\KeyDownload1-bg.exeSoftware\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1EA4179-A319-4c6a-A3E5-67FF3592A12E}SOFTWARE\Mozilla\Firefox\Extensions\{BEE7841B-3C8B-46ea-AFE9-8461458BB2C1}SOFTWARE\Wow6432Node\Classes\AppID\KeyDownload.DLLSOFTWARE\Wow6432Node\Classes\AppID\{C2178B36-2955-479B-818C-A2AE8E500454}SOFTWARE\Wow6432Node\KeyDownloadSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\KeyDownload-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\KeyDownload1-bg.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{C1EA4179-A319-4c6a-A3E5-67FF3592A12E}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\{BEE7841B-3C8B-46ea-AFE9-8461458BB2C1}SOFTWARE\Wow6432Node\MozillaPlugins\@keydownload.com/keyplayer,version=2.2.0-gitHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}KeyDownload{BEE7841B-3C8B-46ea-AFE9-8461458BB2C1}_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\KeyDownload%APPDATA%\KeyDownload%APPDATA%\KeyDownload1%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\eodkncoddaagiibpdlfepebiggiijkbe%PROGRAMFILES%\KeyDownload%PROGRAMFILES%\KeyDownload-Addon%PROGRAMFILES%\KeyDownload1%PROGRAMFILES%\Keyplayer Classic%PROGRAMFILES(x86)%\KeyDownload%PROGRAMFILES(x86)%\KeyDownload-Addon%PROGRAMFILES(x86)%\KeyDownload1%PROGRAMFILES(x86)%\KeyPlayer%PROGRAMFILES(x86)%\KeyPlayer-soft%PROGRAMFILES(x86)%\Keyplayer Classic%USERPROFILE%\AppData\LocalLow\KeyDownload1
The following URL's were detected:
KeyDownload
Loading...