Home Malware Programs Adware Adware.Constant Fun

Adware.Constant Fun

Posted: December 16, 2015

Threat Metric

Ranking: 17,254
Threat Level: 2/10
Infected PCs: 3,087
First Seen: December 16, 2015
Last Seen: August 19, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Setup.exe File name: Setup.exe
Size: 316.16 KB (316168 bytes)
MD5: be44e26c5e972f6a356331fccef526cf
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{0FAA29E8-B9EF-4766-823A-2B3512C0AC25}{199D74B4-7B71-4192-BD95-5DCB44E66704}{999721D2-F4D1-4397-8608-38928DDC0932}{9d6b19f5-4a89-4db4-b650-44222af825b0}File name without pathconstantfun-a.akamaihd[1].xmlhttps_constantfun-a.akamaihd.net_0.localstoragehttps_constantfun-a.akamaihd.net_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}SOFTWARE\ConstantFunSOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{7C7454D5-8182-45ED-8777-20148FB0E5B7}Software\Microsoft\Internet Explorer\DOMStorage\constantfun-a.akamaihd.netSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\constantfun-a.akamaihd.netSOFTWARE\Wow6432Node\ConstantFunSYSTEM\ControlSet001\services\Service Mgr ConstantFunSYSTEM\ControlSet001\services\Update Mgr ConstantFunSYSTEM\ControlSet002\services\Service Mgr ConstantFunSYSTEM\ControlSet002\services\Update Mgr ConstantFunSYSTEM\CurrentControlSet\services\Service Mgr ConstantFunSYSTEM\CurrentControlSet\services\Update Mgr ConstantFunHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Constant Fun

Additional Information

The following directories were created:
%PROGRAMFILES%\Constant Fun%PROGRAMFILES(x86)%\Constant Fun%TEMP%\Constant Fun
The following URL's were detected:
getconstantfun.com
Loading...