Home Malware Programs Adware Application.CorruptedNSIS

Application.CorruptedNSIS

Posted: November 24, 2009

Application.CorruptedNSIS is a potentially dangerous adware program designed to deliver various advertisements to the users' systems. Application.CorruptedNSIS comes bundled with malicious trojans which create a backdoor for Application.CorruptedNSIS to be secretly installed onto the unsuspecting users computer. Application.CorruptedNSIS produces annoying pop-up and pop-under advertisements and eventually convinces the user to purchase a useless anti-adware program for the system to run smoothly again. Application.CorruptedNSIS is a deceitful parasite and should be terminated once detected.

Aliases

not-a-virus:AdWare.Win32.Cinmus.bhzf (Kaspersky Lab)
Adware-Cinmus!n (McAfee)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Common Files\PushWare\cpush.dll
    2 %ProgramFiles%\Common Files\PushWare\cpush0.dll
    3 %ProgramFiles%\Common Files\PushWare\Uninst.exe
    4 %Temp%\UPD3.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CDE9EB54-A08E-4570-B748-13F5DDB5781C}\InprocServer32][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CDE9EB54-A08E-4570-B748-13F5DDB5781C}\ProgID][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CDE9EB54-A08E-4570-B748-13F5DDB5781C}\TypeLib][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CDE9EB54-A08E-4570-B748-13F5DDB5781C}\VersionIndependentProgID][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CDE9EB54-A08E-4570-B748-13F5DDB5781C}][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0AD3AB16-6D0E-4F04-8660-FB1F36BC2DC0}\ProxyStubClsid32][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0AD3AB16-6D0E-4F04-8660-FB1F36BC2DC0}\TypeLib]
Loading...