RPDMGR.DLL – Adware KorAd

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

RPDMGR.DLL – Adware KorAd removal

FileMD5Virus Alias
RPDMGR.DLL 277072971f9343d31828782f44fa6597 Adware KorAd

RPDMGR.DLL size: 113088 bytes
RPDMGR.DLL hash: 277072971F9343D31828782F44FA6597

Created files:

%AppData%\RapidGet\RapidGet.exe
%AppData%\RapidGet\RapidGet.tlb
%AppData%\RapidGet\RPDMgr.dll
%AppData%\RapidGet\rpgchk.exe
%AppData%\RapidGet\RPGManager.exe
%AppData%\RapidGet\RPGSvcMan.exe
%AppData%\RapidGet\RPGUnist.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\RapidGet: %WinDir%\System32\config\Systemprofile\Application Data\RapidGet\RPGManager.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\rpga: %WinDir%\System32\config\Systemprofile\Application Data\RapidGet\rpgchk.exe
HKLM\System\CurrentControlSet\Services\RPGSvcman\Type: 10010000
HKLM\System\CurrentControlSet\Services\RPGSvcman\Start: 02000000
HKLM\System\CurrentControlSet\Services\RPGSvcman\DisplayName: RPGSvcman
HKLM\System\CurrentControlSet\Services\RPGSvcman\ImagePath: %WinDir%\System32\config\Systemprofile\Application Data\RapidGet\RPGSvcMan.exe

Detected by UnHackMe:

RPDMGR.DLL
Default location: %APPDATA%\RAPIDGET\RPDMGR.DLL

Dropper information:
MD5: f3ad1c7051372b722abc913a9a5b7959
File size: 882936 bytes

Leave a Reply