Home Malware Programs Trojans Troj/AdClick-FR

Troj/AdClick-FR

Posted: July 27, 2009

Arriving on your system in the form of an innocent-looking Windows Media file called EroticPamela.mpg, Troj/AdClick-FR is a trojan virus that, once executed, begins shutting down your anti-virus programs and other security related software. Troj/AdClick-FR also alters the registry tools in order to begin running each time Windows starts up.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 \processor.bat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedHKCU\Software\Microsoft\Windows\CurrentVersion\Policies\SystemHKLM\SOFTWARE\Microsoft\Security CenterHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunHKEY..\..\..\..{RegistryKeys}0124\svchost.exeDisableRegistryToolsFirewallDisableNotifyFirewallOverrideFirstRunDisabledHKLM\SYSTEM\CurrentControlSet\Services\NtLmSspHKLM\SYSTEM\CurrentControlSet\Services\SharedAccessHKLM\SYSTEM\CurrentControlSet\Services\TlntSvrHKLM\SYSTEM\CurrentControlSet\Services\wuauservHiddenHideFileExtProcessorShowSuperHiddenStartUpdatesDisableNotify
Loading...