Home Malware Programs Adware Adware.Maucampo

Adware.Maucampo

Posted: February 6, 2014

Threat Metric

Ranking: 13,366
Threat Level: 2/10
Infected PCs: 2,391
First Seen: February 6, 2014
Last Seen: September 24, 2023
OS(es) Affected: Windows


Maucampo Screenshot 1Adware.Maucampo is adware and a potentially unwanted Web browser extension produced by Yontoo Technology that may show numerous pop-up and banner ads and change the default Web browser search and home page settings. Adware.Maucampo may control a PC user's online activities and may insert and show random advertisements or the ones related to the computer user's Internet surfing habits. Once installed, Adware.Maucampo may add a Windows Service which is created to run repeatedly in the system background. If the service is stopped manually, this may stop the program to function appropriately. Adware.Maucampo may add a background controller service that is set to automatically run on the PC. To delay the start of this service is possible through the service manager. Adware.Maucampo may insert a Browser Helper Object (BHO) into Internet Explorer.

Maucampo Screenshot 2Maucampo Screenshot 3Maucampo Screenshot 4

Aliases

MalSign.Maucampo.E25 [AVG]Trojan.BPlug.11 [DrWeb]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\maucampo\updatemaucampo.exe File name: updatemaucampo.exe
Size: 97.04 KB (97048 bytes)
MD5: d6091e4dc292f20ec954114399ab7447
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\maucampo
Group: Malware file
Last Updated: February 6, 2014
%PROGRAMFILES%\maucampo\maucampo.FirstRun.exe File name: maucampo.FirstRun.exe
Size: 1.08 MB (1088792 bytes)
MD5: 7509481f423f4cf6d28e2a51cb7ec546
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\maucampo
Group: Malware file
Last Updated: February 6, 2014
%PROGRAMFILES%\maucampo\maucampouninstall.exe File name: maucampouninstall.exe
Size: 240.96 KB (240969 bytes)
MD5: 7e11818a0ca59e7e03e5f76a42733e9d
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\maucampo
Group: Malware file
Last Updated: February 6, 2014
%PROGRAMFILES%\maucampo\maucampoBHO.dll File name: maucampoBHO.dll
Size: 245.47 KB (245479 bytes)
MD5: b34af7a6e909898e56e43d223ee5fca5
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\maucampo
Group: Malware file
Last Updated: February 6, 2014
maucampoBHO.dll File name: maucampoBHO.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
maucampoUninstall.exe File name: maucampoUninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

CLSID{5275AC7F-2327-42CC-92C8-1D2AA6A563CF}{5d7d4fb9-aca5-4013-8879-c58dcd4df9f1}{E1E7DBB4-1DD9-4025-9C52-18F9A2AD944E}HKEY..\..\..\..{RegistryKeys}Software\maucampoSoftware\Microsoft\Internet Explorer\Approved Extensions\{5D7D4FB9-ACA5-4013-8879-C58DCD4DF9F1}SOFTWARE\Microsoft\Tracing\maucampo_RASAPI32SOFTWARE\Microsoft\Tracing\maucampo_RASMANCSSOFTWARE\Microsoft\Tracing\updatemaucampo_RASAPI32SOFTWARE\Microsoft\Tracing\updatemaucampo_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{5d7d4fb9-aca5-4013-8879-c58dcd4df9f1}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D7D4FB9-ACA5-4013-8879-C58DCD4DF9F1}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D7D4FB9-ACA5-4013-8879-C58DCD4DF9F1}SYSTEM\ControlSet001\services\eventlog\Application\Update maucampoSYSTEM\ControlSet001\services\Update maucampoSYSTEM\ControlSet002\services\eventlog\Application\Update maucampoSYSTEM\ControlSet002\services\Update maucampoSYSTEM\CurrentControlSet\services\eventlog\Application\Update maucampoSYSTEM\CurrentControlSet\services\Update maucampoHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}maucampo

Additional Information

The following directories were created:
%ProgramFiles%\maucampo%ProgramFiles(x86)%\maucampo
The following URL's were detected:
Maucampo.net/supporthttp://maucampo.net
Loading...