Home Malware Programs Dialers 7AdPower

7AdPower

Posted: March 28, 2006

7AdPower is a specific ActiveX control that secretly downloads from the Internet and installs one or more dialers without asking for user permission. Such dialers connect an affected PC to the Internet by dialing high-cost phone numbers using a modem. 7AdPower can silently get into the computer while visiting some insecure web sites.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 belgio_ver[XVS].ocx
    2 emsat_ver[XVS].ocx
    3 internazionale_ver[XVS].ocx

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREClassesVacPro.belgio_ver[XVS]HKEY_LOCAL_MACHINESOFTWAREClassesVacPro.internazionale_ver[XVS]
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}795EB484-BD6D-4125-93DB-D6FF015325E9490C4042-5C17-4AC0-A046-000CB7FC02171DD8DB5A-7EFC-48EC-8910-40A1AAA8D2F3BF5B2E01-73BF-4AE4-8198-A8745C3235F69829CFE6-F89A-4A1A-8804-4DCA0BE27518929BB4FA-0AF1-4A01-A0AE-023F4B421DA269A5250D-6E72-46FD-95BD-7FE4F6191C0C66BD1BD0-3655-42E4-8CE9-16D3613B0B2512E919BC-C70F-432B-B831-1180DE734505EE20D8BE-C0A8-4585-B11A-4E4E264C95AB970BF476-3CF2-4572-9EF9-4479E1591DB89E98E84C-79E1-49C3-82EB-798FCD552EFB
Loading...