Home Malware Programs Spyware Spyware.ADH

Spyware.ADH

Posted: December 15, 2010

Spyware.ADH is a fake security application designed to monitor your computer activity. Spyware.ADH is not a good program in that it has the ability to record keystrokes and send them to a remote user for purposes of stealing your personal information. Spyware.ADH may put you at risk for identity theft if it is not removed. Spyware.ADH may be difficult to remove manually. Spyware.ADH may have a similar name to other programs on the market but you must not download or install the rogue SpyMyPC.

Aliases

BackDoor-DVB.gen.w (McAfee)
Trojan:Win32/Redosdru.K (Microsoft)
Backdoor.Win32.FirstInj (Ikarus)
Win-Trojan/Malware.130738.W (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Profiles%\Local User\windmad.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
Loading...