Home Malware Programs Adware AdSafer

AdSafer

Posted: December 3, 2010

AdSafer is an annoying adware program which promotes Vista AntiMalware 2010. AdSafer produces popups stating the computer is infected and Vista Anti Malware 2010 must be purchased to remove the threats. Do not fall for this trickery and have AdSafer removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 C:\Documents and Settings\{username}\Desktop\setup_adsafer.exe
    2 C:\Documents and Settings\{username}\Start Menu\Programs\adsafer
    3 C:\Program Files\adsafer
    4 C:\Program Files\adsafer\adr.exe
    5 C:\Program Files\adsafer\adsafer.exe
    6 C:\Program Files\adsafer\config.ini
    7 C:\Program Files\adsafer\db
    8 C:\Program Files\adsafer\db\a.dat
    9 C:\Program Files\adsafer\filecheck.ini
    10 C:\Program Files\adsafer\report
    11 C:\Program Files\adsafer\skindir
    12 C:\Program Files\adsafer\skindir\alram.gif
    13 C:\Program Files\adsafer\skindir\bar_02.gif
    14 C:\Program Files\adsafer\skindir\bar_default.gif
    15 C:\Program Files\adsafer\skindir\ber.gif
    16 C:\Program Files\adsafer\skindir\ber_default.gif
    17 C:\Program Files\adsafer\skindir\icon_del.ico
    18 C:\Program Files\adsafer\skindir\install.jpg
    19 C:\Program Files\adsafer\skindir\left_btn_01.gif
    20 C:\Program Files\adsafer\skindir\left_btn_02.gif
    21 C:\Program Files\adsafer\skindir\left_btn_03.gif
    22 C:\Program Files\adsafer\skindir\left_btn_04.gif
    23 C:\Program Files\adsafer\skindir\left_btn_05.gif
    24 C:\Program Files\adsafer\skindir\left_btn_07.gif
    25 C:\Program Files\adsafer\skindir\left_btn_on_01.gif
    26 C:\Program Files\adsafer\skindir\left_btn_on_02.gif
    27 C:\Program Files\adsafer\skindir\left_btn_on_03.gif
    28 C:\Program Files\adsafer\skindir\left_btn_on_04.gif
    29 C:\Program Files\adsafer\skindir\left_btn_on_05.gif
    30 C:\Program Files\adsafer\skindir\left_btn_on_07.gif
    31 C:\Program Files\adsafer\skindir\loding.jpg
    32 C:\Program Files\adsafer\skindir\m.flg
    33 C:\Program Files\adsafer\skindir\main.jpg
    34 C:\Program Files\adsafer\skindir\mb.gif
    35 C:\Program Files\adsafer\skindir\memory_img.gif
    36 C:\Program Files\adsafer\skindir\sbg.gif
    37 C:\Program Files\adsafer\skindir\set.gif
    38 C:\Program Files\adsafer\skindir\Thumbs.db
    39 C:\Program Files\adsafer\skindir\title_2.gif
    40 C:\Program Files\adsafer\skindir\title_4.gif
    41 C:\Program Files\adsafer\skindir\title_5.gif
    42 C:\Program Files\adsafer\skindir\title_8.gif
    43 C:\Program Files\adsafer\skindir\view_img_6.gif
    44 C:\Program Files\adsafer\uninstall.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\adsaferHKEY_CURRENT_USER\Software\noadsaferHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\adsafer
Loading...