Home Malware Programs Adware PerMedia

PerMedia

Posted: March 28, 2006

PerMedia is an adware spyware that shows unexpected pop-up advertisements while you surf the Internet. The threat sends e-mail messages to all the contacts in the Microsoft Outlook address book. These letters contain links leading to the web site that distributes PerMedia. The adware can download from the Internet and install unsolicited potentially harmful software. It also has the ability to automatically update itself. PerMedia can get into the computer while visiting some web resources, which links are distributed by e-mail.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 otdock.dll
    2 otglove.dll
    3 otms.exe
    4 otupdate.exe
    5 winsrvc.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWARECLASSESIEEvtCatcher.IEEvtCatcherObjHKEY_LOCAL_MACHINESOFTWARECLASSESIEEvtCatcher.IEEvtCatcherObj.1HKEY_LOCAL_MACHINESOFTWARECLASSESIEMsgSvr.IEMsgSvrObjHKEY_LOCAL_MACHINESOFTWARECLASSESIEMsgSvr.IEMsgSvrObj.1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunPMediaHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallWinSrvReg
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}3972ADCE-8737-45DE-A6E2-A253348E5A1E059D8C85-A00F-40AF-8078-7692A0A79F197677C920-9CC3-4621-AF8C-AD45402DC2FD7011471D-3F74-498E-88E1-C0491200312D

Related Posts

Loading...