Home Malware Programs Potentially Unwanted Programs (PUPs) Aducky

Aducky

Posted: May 13, 2014

Threat Metric

Ranking: 12,379
Threat Level: 2/10
Infected PCs: 27,061
First Seen: May 13, 2014
Last Seen: October 9, 2023
OS(es) Affected: Windows


Aducky is a potentially unwanted program (PUP), which may occur on Windows XP, Windows Vista, Windows 7 and Windows 8 operating systems. Aducky may be download accidentally as an extra program bundled with other free software, or voluntarily, as a valuable application that can help computer users save time and money when shopping online. Aducky may perform numerous unwanted activities on the PC, such as continuously reroute computer users to suspicious websites that may be advertising, create and show annoying pop-up ads and messages and slow down any web browser installed on a computer. Aducky may track the PC user's browsing routine and collect information such as visited websites and data, which was entered there.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\WINDOWS\Microsoft\System Update kb70007\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 16.38 KB (16384 bytes)
MD5: 90ef46c5e48b21087b6b4d07edfdf6e3
Detection count: 8,872
File type: Executable File
Mime Type: unknown/exe
Path: C:\WINDOWS\Microsoft\System Update kb70007\WindowsUpdater.exe
Group: Malware file
Last Updated: October 2, 2021
C:\Windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 18.94 KB (18944 bytes)
MD5: cabd5bf30a009765d8e550bf90ad209e
Detection count: 3,597
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe
Group: Malware file
Last Updated: May 10, 2023
%APPDATA%\MRS\SystemUpdatekb70007\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 29.18 KB (29184 bytes)
MD5: 5697da626175096815169a1d53829f53
Detection count: 1,787
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\MRS\SystemUpdatekb70007
Group: Malware file
Last Updated: June 10, 2014
%WINDIR%\Microsoft\System Update kb77600\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 17.92 KB (17920 bytes)
MD5: 441d708772b3a4d7b3453723bf3c6152
Detection count: 1,267
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\System Update kb77600
Group: Malware file
Last Updated: May 19, 2014
%WINDIR%\Microsoft\Sound Helper 1.0\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 16.89 KB (16896 bytes)
MD5: cc53d321b3e71bb24a6e315e3185519c
Detection count: 1,164
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\Sound Helper 1.0
Group: Malware file
Last Updated: May 19, 2014
%WINDIR%\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 15.87 KB (15872 bytes)
MD5: 22c2066399424ada53128de9ccada49c
Detection count: 586
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\SystemUpdatekb70007
Group: Malware file
Last Updated: May 15, 2014
%WINDIR%\Microsoft\system update kb77500\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 17.4 KB (17408 bytes)
MD5: bcc8ad7d5e1c750db7fbafb74ea03900
Detection count: 513
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\system update kb77500
Group: Malware file
Last Updated: May 19, 2014
%WINDIR%\Microsoft\System Update kb77600\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 17.4 KB (17408 bytes)
MD5: 6eb02779c3a94f3d813d4d191a2e4ae3
Detection count: 440
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\System Update kb77600
Group: Malware file
Last Updated: May 19, 2014
%WINDIR%\Microsoft\System Update kb77200\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 17.92 KB (17920 bytes)
MD5: f8376079d288bd2d735678d15b2e5787
Detection count: 150
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\System Update kb77200
Group: Malware file
Last Updated: May 19, 2014
%WINDIR%\Microsoft\system update kb77400\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 17.92 KB (17920 bytes)
MD5: 378956abd09992706088cb66cb02391e
Detection count: 148
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\system update kb77400
Group: Malware file
Last Updated: May 19, 2014
%WINDIR%\Microsoft\System Update kb70007\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 16.38 KB (16384 bytes)
MD5: 8233b8e3f2e01530e2d2a5631533e2f1
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\System Update kb70007
Group: Malware file
Last Updated: May 19, 2014
%WINDIR%\Microsoft\System Update kb77500\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 17.4 KB (17408 bytes)
MD5: 3c57be74f76383faa472a4b6f137b91f
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\System Update kb77500
Group: Malware file
Last Updated: May 19, 2014
%WINDIR%\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 18.94 KB (18944 bytes)
MD5: 9e8698cc5c2e2ede321741c4268e1b93
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Microsoft\SystemUpdatekb70007
Group: Malware file
Last Updated: December 16, 2021

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\aduckySOFTWARE\Classes\.adckam1SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{AAC12757-BDAF-4F9A-8DE8-513C3615590F}SOFTWARE\Wow6432Node\aduckySYSTEM\ControlSet001\services\eventlog\Application\SystemUpdatekb70007SYSTEM\ControlSet001\services\SystemUpdatekb70007SYSTEM\CurrentControlSet\services\eventlog\Application\SystemUpdatekb70007SYSTEM\CurrentControlSet\services\SystemUpdatekb70007

Additional Information

The following directories were created:
%PROGRAMFILES%\MSR\System Update kb70007%PROGRAMFILES%\MSR\backup\System Update kb70007%PROGRAMFILES(x86)%\MSR\System Update kb70007%PROGRAMFILES(x86)%\MSR\System Update kb77500%PROGRAMFILES(x86)%\MSR\System Update kb77600%PROGRAMFILES(x86)%\MSR\backup\System Update kb70007%WINDIR%\Microsoft\AV.G Security%WINDIR%\Microsoft\Sound Helper 1.0%WINDIR%\Microsoft\System Update kb70007%WINDIR%\Microsoft\SystemUpdatekb70007%WINDIR%\Microsoft\UpdatingService%WINDIR%\Microsoft\sogrSho
Loading...