Home Malware Programs Adware Adware.Win32/Nieguide

Adware.Win32/Nieguide

Posted: November 6, 2009

Adware.Win32/Nieguide is a dangerous adware infection that is able to display fake advertisements that lead to the installation of other malware. Adware.Win32/Nieguide can load at startup from malicious registry entries that it has flooded the windows registry with. Adware.Win32/Nieguide is generally installed through a security hole or browser exploit and should be removed from the compromised system immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Internet Explorer\iexplore.exe
    2 %ProgramFiles%\nieguideplus\nieguideplus.exe
    3 %ProgramFiles%\nieguideplus\nieguideup.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21F5CA43-95FD-4C03-BEF3-3784C4B531F6}\Implemented Categories\{00021493-0000-0000-C000-000000000046}][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D2D31EA-93B8-4EEA-9C88-B8347A33621F}\InprocServer32[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D2D31EA-93B8-4EEA-9C88-B8347A33621F}\ProgID][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D2D31EA-93B8-4EEA-9C88-B8347A33621F}\TypeLib[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D2D31EA-93B8-4EEA-9C88-B8347A33621F}\VersionIndependentProgID
Loading...