Home Malware Programs Adware Elodu

Elodu

Posted: March 24, 2010

Elodu is an Adware program that displays commercial pop-ups. It functions as an Internet Explorer add-on, which means every time a website is accessed it runs automatically. Elodu hides from the user by operating in stealth and staying resident in the background. Elodu will steal the computer user's web habits and use this for malicious advertising. Use a proven anti-virus program to remove Elodu immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 diskcheck.exe
    2 explorer.exe
    3 lsmgr.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC564D32-0F1A-4367-8A9B-4A9F57688D03}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\Shell\Open\Command\Default=%System%\explorer.exe %1HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1CFFD533-46FE-4031-A3FF-5370943BA025}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E704673-BE49-4C13-8E36-288326D14709}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lsmgr.mssgrHKEY_LOCAL_MACHINE\SOFTWARE\Classes\lsmgr.mssgr.1HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D1EDDE84-E67E-4ccd-B28E-73AD3B71A7C9}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EC564D32-0F1A-4367-8A9B-4A9F57688D03}
Loading...