Impove
boot up time

Run a free scan to diagnose your PC
Start Test!

CHOCOSUPPORTER.EXE is Adware BHO

January 27, 2012 by NightWatcher
Filed under: Adware 
Install UnHackMe Install RegRun

We received the file CHOCOSUPPORTER.EXE and detected that CHOCOSUPPORTER.EXE is not good.
CHOCOSUPPORTER.EXE is Adware. You should remove the file CHOCOSUPPORTER.EXE.
Kill the process CHOCOSUPPORTER.EXE and remove CHOCOSUPPORTER.EXE from Windows.

Malware Analysis of CHOCOSUPPORTER.EXE
Full path on a computer: %Program Files%\Choco Supporter\ChocoSupporter.exe

Detected by UnHackMe:

Item Name: {98D68C3C-CF16-4CA8-BBDB-11E0EDB62E36}
Author: ????
Related File: %PROGRAM FILES%\CHOCO SUPPORTER\KEYWORDTAB.DLL
Type: Browser Helper Objects

After first reboot detected by UnHackMe:

Item Name: {2E70ECB3-FDB6-40E6-BF93-B72386F2F1FF}
Author: OPEN.s.
Related File: C:\PROGRA~1\CHOCOS~1\CHOCOS~1.DLL
Type: Browser Helper Objects

Item Name: Choco Supporter
Author: OPEN.s.
Related File: %PROGRAM FILES%\CHOCO SUPPORTER\CHOCOSUPPORTER.EXE
Type: Registry Run

Removal Results: Success
Number of reboot: 1

CHOCOSUPPORTER.EXE is known as:

Adware.BHO, Adware.Searcher

CHOCOSUPPORTER.EXE hash:

  • MD5: b70fffbb490d9a94d14dc0f520347342
The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.
How to quickly detect CHOCOSUPPORTER.EXE presence?

Registry:
  • HKLM\Software\Classes\CLSID\{2E70ECB3-FDB6-40E6-BF93-B72386F2F1FF}\InprocServer32\: “C:\PROGRA~1\CHOCOS~1\CHOCOS~1.DLL”
  • HKLM\Software\Classes\CLSID\{98D68C3C-CF16-4CA8-BBDB-11E0EDB62E36}\InProcServer32\: “%Program Files%\Choco Supporter\keywordTab.dll”
  • HKLM\Software\Classes\CLSID\{C6FE01C2-7E37-4953-934A-DDBC0E5C179A}\InprocServer32\: “C:\PROGRA~1\CHOCOS~1\CHOCOS~1.DLL”
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Choco Supporter: “”%Program Files%\Choco Supporter\ChocoSupporter.exe”"
Folders:
  • %Program Files%\Choco Supporter
Files:
  • %Program Files%\Choco Supporter\ChocoSupporter.exe
  • %Program Files%\Choco Supporter\ChocoSupporterh.dll
  • %Program Files%\Choco Supporter\keywordTab.dll
  • %Program Files%\Choco Supporter\KeywordTab.exe

Remove it now!

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!