Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

OCSETUPHLP.DLL is Adware OpenCandy

$
0
0

We received the file OCSETUPHLP.DLL and detected that OCSETUPHLP.DLL is not good.
OCSETUPHLP.DLL is Adware. You should remove the file OCSETUPHLP.DLL.
Kill the process OCSETUPHLP.DLL and remove OCSETUPHLP.DLL from Windows.

Malware Analysis of OCSETUPHLP.DLL
Full path on a computer: %Program Files%\RealArcade\Installer\bin\OCSetupHlp.dll

Detected by UnHackMe:

OCSETUPHLP.DLL
Default location: %Program Files%\RealArcade\Installer\bin\OCSetupHlp.dll

Removal Results: Success
Number of reboot: 1

OCSETUPHLP.DLL is known as:

Adware.OpenCandy

OCSETUPHLP.DLL hash:

  • MD5: 4ec193b95cc7fa7efc42f3ae24858f5c
How to quickly detect OCSETUPHLP.DLL presence?
Registry:
  • HKLM\Software\Classes\CLSID\{102A897A-FC92-4F8B-A7D5-7DE434FE7D3E}\InprocServer32\: “%Program Files%\RealArcade\Installer\bin\InstallerDlg.dll”
  • HKLM\Software\Classes\CLSID\{28DFE5B9-610E-4df7-9ADD-615BE7F7CAFA}\InprocServer32\: “%Program Files%\RealArcade\Installer\bin\GCHROME.dll”
  • HKLM\Software\Classes\CLSID\{5818813E-D53D-47A5-ABBB-37E2A07056B5}\InprocServer32\: “%Program Files%\RealArcade\Installer\bin\InstallerDlg.dll”
  • HKLM\Software\Classes\CLSID\{748744E8-6812-4F07-9F57-5F40395BDE65}\InprocServer32\: “%Program Files%\RealArcade\Installer\bin\InstallerDlg.dll”
  • HKLM\Software\Classes\CLSID\{7B5C103F-DAAF-425E-B3A9-DEDE61F3A6F4}\InprocServer32\: “%Program Files%\RealArcade\Installer\bin\InstallerDlg.dll”
  • HKLM\Software\Classes\CLSID\{80AB3FB6-9660-416C-BE8D-0E2E8AC3138B}\InprocServer32\: “%Program Files%\RealArcade\Installer\bin\InstallerDlg.dll”
  • HKLM\Software\Classes\CLSID\{C8F76629-E4F4-4646-AFC0-665082D167B1}\InprocServer32\: “%Program Files%\RealArcade\Installer\bin\InstallerDlg.dll”
  • HKLM\Software\Classes\RealArcade.rgi\shell\Open\command\: “”%Program Files%\RealArcade\Installer\bin\gameinstaller.exe” “%Program Files%\RealArcade\Installer\bin\..\installerMain.clf” “%1″”
  • HKLM\Software\Classes\RealArcade.rguninst\shell\Open\command\: “”%Program Files%\RealArcade\Installer\bin\gameinstaller.exe” “%Program Files%\RealArcade\Installer\bin\..\installerMain.clf” “%1″”
Folders:
  • %Program Files%\RealArcade
  • %Program Files%\RealArcade\Installer
  • %Program Files%\RealArcade\Installer\bin
  • %Program Files%\RealArcade\Installer\Extensions
  • %Program Files%\RealArcade\Installer\Resources
  • %Program Files%\RealArcade\Installer\Resources\zylom
  • %Program Files%\RealArcade\Installer\socket
  • %Program Files%\RealArcade\Installer\socket\mime
  • %Program Files%\RealArcade\Installer\socket\socket
Files:
  • %Temp%\installLog.txt
  • %Program Files%\RealArcade\Installer\bin\bstrapinstall.exe
  • %Program Files%\RealArcade\Installer\bin\gameinstaller.exe
  • %Program Files%\RealArcade\Installer\bin\gamewrapper.exe
  • %Program Files%\RealArcade\Installer\bin\gcapi_dll.dll
  • %Program Files%\RealArcade\Installer\bin\GCHROME.dll
  • %Program Files%\RealArcade\Installer\bin\gtapi_signed.dll
  • %Program Files%\RealArcade\Installer\bin\gtbCom.dll
  • %Program Files%\RealArcade\Installer\bin\InstallerDlg.dll
  • %Program Files%\RealArcade\Installer\bin\lua50.dll
  • %Program Files%\RealArcade\Installer\bin\luacom.dll
  • %Program Files%\RealArcade\Installer\bin\OCSetupHlp.dll
  • %Program Files%\RealArcade\Installer\bin\RAInstallerPaths.dll
  • %Program Files%\RealArcade\Installer\bin\ServerTransaction.dll
  • %Program Files%\RealArcade\Installer\bin\UnRar.exe
  • %Program Files%\RealArcade\Installer\blank.html
  • %Program Files%\RealArcade\Installer\blob
  • %Program Files%\RealArcade\Installer\compat-5.1.lua
  • %Program Files%\RealArcade\Installer\config.lua
  • %Program Files%\RealArcade\Installer\Extensions\CheckInstallChrome.clf
  • %Program Files%\RealArcade\Installer\Extensions\CheckInstallComcastGamesToolbar.clf
  • %Program Files%\RealArcade\Installer\Extensions\CheckInstallGoogleToolbar.clf
  • %Program Files%\RealArcade\Installer\Extensions\CheckInstallTwcDesktopWeather.clf
  • %Program Files%\RealArcade\Installer\installerMain.clf
  • %Program Files%\RealArcade\Installer\mrClean.clf
  • %Program Files%\RealArcade\Installer\Resources\zylom\spinner.gif
  • %Program Files%\RealArcade\Installer\Resources\zylom\wait.html
  • %Program Files%\RealArcade\Installer\Resources\zylom\waiting_bar.gif
  • %Program Files%\RealArcade\Installer\Resources\zylom\waiting_to_install.gif
  • %Program Files%\RealArcade\Installer\Resources\zylom\waiting_to_install2.gif
  • %Program Files%\RealArcade\Installer\Resources\zylom\waitProc.html
  • %Program Files%\RealArcade\Installer\socket\http.lua
  • %Program Files%\RealArcade\Installer\socket\ltn12.lua
  • %Program Files%\RealArcade\Installer\socket\mime\core.dll
  • %Program Files%\RealArcade\Installer\socket\mime.lua
  • %Program Files%\RealArcade\Installer\socket\socket\core.dll
  • %Program Files%\RealArcade\Installer\socket\socket.lua
  • %Program Files%\RealArcade\Installer\socket\url.lua
  • %Program Files%\RealArcade\Installer\tmp.xml
  • %Program Files%\RealArcade\Installer\wait.html
  • %Program Files%\RealArcade\Installer\waiting_bar.gif
  • %Program Files%\RealArcade\Installer\waiting_to_install.gif
  • %Program Files%\RealArcade\Installer\waitProc.html
  • %Program Files%\RealArcade\installLog.txt


Viewing all articles
Browse latest Browse all 38585

Trending Articles