Home Malware Programs Adware ThumbSnatcher

ThumbSnatcher

Posted: March 28, 2006

ThumbSnatcher is an adware application that serves unsolicited commercial advertisements. The threat is installed to the computer using an ActiveX installer while visiting certain web sites. ThumbSnatcher doesn't carry any destructive payload. It works as the web browser's add-on and therefore runs every time the user launches Internet Explorer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 gdiplus64.dll
    2 myaccess.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTPopupper.PopUpHKEY_CLASSES_ROOTPopupper.PopUp.1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}ECE19BAA-A2B5-4E77-9197-574B9873718C8522FD29-4D5F-4377-B4D6-B832954A7932FA79FA22-8DB3-43D1-997B-6DBFD8845569
Loading...