Home Malware Programs Potentially Unwanted Programs (PUPs) Aducky

Aducky

Posted: May 13, 2014

Threat Metric

Ranking: 16,415
Threat Level: 2/10
Infected PCs: 27,100
First Seen: May 13, 2014
Last Seen: January 20, 2025
OS(es) Affected: Windows


Aducky is a potentially unwanted program (PUP), which may occur on Windows XP, Windows Vista, Windows 7 and Windows 8 operating systems. Aducky may be download accidentally as an extra program bundled with other free software, or voluntarily, as a valuable application that can help computer users save time and money when shopping online. Aducky may perform numerous unwanted activities on the PC, such as continuously reroute computer users to suspicious websites that may be advertising, create and show annoying pop-up ads and messages and slow down any web browser installed on a computer. Aducky may track the PC user's browsing routine and collect information such as visited websites and data, which was entered there.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\MRS\SystemUpdatekb70007\WindowsUpdater.exe File name: WindowsUpdater.exe
Size: 29.18 KB (29184 bytes)
MD5: 5697da626175096815169a1d53829f53
Detection count: 1,787
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\MRS\SystemUpdatekb70007
Group: Malware file
Last Updated: June 10, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\aduckySOFTWARE\Classes\.adckam1SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{AAC12757-BDAF-4F9A-8DE8-513C3615590F}SOFTWARE\Wow6432Node\aduckySYSTEM\ControlSet001\services\eventlog\Application\SystemUpdatekb70007SYSTEM\ControlSet001\services\SystemUpdatekb70007SYSTEM\CurrentControlSet\services\eventlog\Application\SystemUpdatekb70007SYSTEM\CurrentControlSet\services\SystemUpdatekb70007

Additional Information

The following directories were created:
%PROGRAMFILES%\MSR\System Update kb70007%PROGRAMFILES%\MSR\backup\System Update kb70007%PROGRAMFILES(x86)%\MSR\System Update kb70007%PROGRAMFILES(x86)%\MSR\System Update kb77500%PROGRAMFILES(x86)%\MSR\System Update kb77600%PROGRAMFILES(x86)%\MSR\backup\System Update kb70007%WINDIR%\Microsoft\AV.G Security%WINDIR%\Microsoft\Sound Helper 1.0%WINDIR%\Microsoft\System Update kb70007%WINDIR%\Microsoft\SystemUpdatekb70007%WINDIR%\Microsoft\UpdatingService%WINDIR%\Microsoft\sogrSho
Loading...