Home Malware Programs Spyware Adware.Rotator

Adware.Rotator

Posted: May 12, 2011

Adware.Rotator is a malignant adware program which usually initiates, shows, or downloads advertisements to the corrupted computer. Adware.Rotator creates malicious registry entries to mess up your computer files covertly. Adware.Rotator adds a start-up entry to allow its automatic execution every time Windows starts. Adware.Rotator aims to gather information about targeted users and transmit it to host computers without any awareness and authorization. Adware.Rotator will create a browser helper object for Internet Explorer named Brincome Browser Plugin. Adware.Rotator sends specially crafted HTTP POST requests to predetermined websites. Adware.Rotator will change your web browser code and disable you to set your web browser options. It is best to remove Adware.Rotator immediately upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%/[RANDOM FILE NAME TWO].exe
    2 %System%/[RANDOM FILE NAME].dll
    3 %System%/_[RANDOM FILE NAME].dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\"[RANDOM ID]" = "brincome browser plug-in"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\[RANDOM ID]\"InProcServer32" = "%System%\[RANDOM FILE NAME].dll"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"[RANDOM FILE NAME]" = "%System%\regsvr32.exe %System%\[RANDOM FILE NAME].dll"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}[RANDOM FILE NAME TWO]\"DisplayName" = "Performance Solution Brincome."[RANDOM FILE NAME TWO]\"UninstallString" = "%System%\[RANDOM FILE NAME 2].exe /i=%systemdir%\[RANDOM FILE NAME].dll" /d=[RANDOM FILE NAME TWO]"
Loading...