Home Malware Programs Browser Hijackers VirtualMaid

VirtualMaid

Posted: June 9, 2006

VirtualMaid is an adware program that displays advertisements. VirtualMaid may contact msxpsupport.com periodically and copies itself copies itself as %System%\helper.exe. Similar programs that are associated with VirtualMaid are SearchMaid, PSGuard, Security iGuard and Smitfraud. They may hijack your Internet Explorer start page and hijack search engines to change the search queries.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 1.bmp
    2 2.bmp
    3 5e60971403.exe
    4 govm.dll
    5 govm.dll.htm
    6 helper.exe
    7 logo.bmp
    8 msole32.exe
    9 pop-uper.exe
    10 uninstall.bat
    11 virtualmaid.dll
    12 virtualmaid.xml
    13 vm.exe
    14 vminstaller.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\software\virtualmaidHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversionguidHKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\govm.contextitemHKEY_CLASSES_ROOT\govm.contextitem.1HKEY_CLASSES_ROOT\vm.vmobjHKEY_CLASSES_ROOT\vm.vmobj.1HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}virtualmaidvirtualmaid
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}42c7653a-5834-45a1-899a-ed0dfa370d21ab2dde8c-cbff-491a-9825-87b8bb4cbfe0835baa68-b5e5-47d5-a18d-2a4e0f5b72d58b0b6f79-c50d-4ea6-8f65-bdf18005de2077b2f8de-cb3f-4b6b-839b-807dd1adba1c
Loading...