Home Malware Programs Adware Onban

Onban

Posted: March 28, 2006

Onban is an adware spyware that serves unsolicited pop-up windows containing many commercial advertisements. The threat silently updates itself via the Internet. Onban is bundled with some ad-supported applications. It can also be manually installed. The adware runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ob2.dll
    2 ob4.dll
    3 onban000.exe
    4 onban004.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINECLASSESOnban002.ViewSourceHKEY_LOCAL_MACHINECLASSESOnban002.ViewSource.1HKEY_LOCAL_MACHINECLASSESOnban004.ViewSourceHKEY_LOCAL_MACHINECLASSESOnban004.ViewSource.1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}D897D800-4D10-4981-B927-ACA77586D8CAC465A061-CDA5-4553-9FEB-F5A4FA658BFD8DBFDE2A-A02C-4203-A3A1-CC848CA5355F87368154-7BA0-43BE-90F4-6D47BA01EB095A7CBCDC-9228-4104-A57D-738CE50FBA4F0F9E1CB9-1B32-436B-B44C-BC7B7369CB9B

Related Posts

Loading...