Home Malware Programs Adware ABetterInternet

ABetterInternet

Posted: April 3, 2005

ABetterInternet runs at your system's start-up and may track your Internet activity. If A Better Internet gathers personal information about yourself and your web browsing habits, it may target pop-up advertisements at you, redirect certain URLs, and automatically update itself and install third-party software, files and desktop icons.

www.ABetterInternet.com

File System Modifications

  • The following files were created in the system:
    # File Name
    1 60baa28d63.exe
    2 687a5e1585.exe
    3 8c8b6c2158.exe
    4 abiuninst[1].exe
    5 adt14150.exe
    6 adware-win32-betterinternet-ac.exe
    7 ahreco.exe
    8 apledit.cpy.dll
    9 atm24100.exe
    10 aurareco.exe
    11 aurora.exe
    12 bhehfbdj60.exe
    13 bi.dll
    14 ceres.dll
    15 n.dll
    16 payload.exe
    17 pgdarxr.exe
    18 poller(1).exe
    19 poller.exe
    20 qbuninstaller.exe
    21 randreco.exe
    22 reciperewards.exe
    23 rmuybf.exe
    24 rndrcus.exe
    25 s_girl.exe
    26 ssuvtmr.dll
    27 ssuvtmr6.dll
    28 tboncomp.dll
    29 utils_21.dll
    30 vbalicom6.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\SOFTWARE\Microsoft\Windows\CurrentVersion\{ModuleUsage}c:/winnt/kmg14100.exe.ownerHKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\software\dbibii1d2ofsdistHKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\guardianHKEY_LOCAL_MACHINE\software\twaintecHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run59ac6bevHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runbeltHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runlkmkrljHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runvjuraoHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}abi-1dbi
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}000006b1-19b5-414a-849f-2a3c64ae693900000097-7c67-4ba6-8b42-05128941688a00000049-8f91-4d9c-9573-f016e762648479849612-a98f-45b8-95e9-4d13c7b6b35c30000273-8230-4dd4-be4f-6889d1e74167

Related Posts

Loading...