Home Malware Programs Adware Adware.Rugo

Adware.Rugo

Posted: December 10, 2009

Adware.Rugo is a rogue adware program designed to display annoying pop-up advertisements on an infected computer. Adware.Rugo will also attempt to drop a malicious file and run it everytime the compromised PC is turned on. Adware.Rugo poses a threat to PC security and should be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CommonAppData%\t\a2293.dat
    2 %CommonAppData%\t\b2293.dat
    3 %CommonAppData%\t\k2293.dat
    4 %CommonAppData%\t\p2293.dat
    5 %CommonAppData%\t\r2293.dat
    6 %System%\2de1.dll
    7 %System%\7010022-60
    8 %System%\9el9.dll
    9 %System%\e7rd.exe
    10 %Temp%\fvq1.tmp
    11 %Windir%\79e7.bmp
    12 %Windir%\92b7.flv
    13 %Windir%\e7df.exe
    14 %Windir%\Tasks\ms.job

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
Loading...