Home Malware Programs Adware Adware:Win32/CloverPlus

Adware:Win32/CloverPlus

Posted: November 14, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 85
First Seen: July 16, 2011
OS(es) Affected: Windows

Adware:Win32/CloverPlus is an adware application that connects to a certain server to display advertisements on the screen of the affected computer when the PC user is online. Adware:Win32/CloverPlus may also create URL shorcuts on the Desktop and Favorites folders. Once executed, Adware:Win32/CloverPlus creates potentially malicious files on the corrupted machine. Adware:Win32/CloverPlus also modifies the Windows Registry. Adware:Win32/CloverPlus may create the certain registry entry so that it can run automatically every time you start Windows. Adware:Win32/CloverPlus also creates the certain registry entry as part of its installation process. Adware:Win32/CloverPlus is usually installed by an installer that may have the .exe file names. Adware:Win32/CloverPlus checks if the targeted computer is connected to the Internet by attempting to access 'google.com' and 'microsoft.com'. If the corrupted PC is connected to the Internet, Adware:Win32/CloverPlus attempts to connect to the certain servers to receive commands as to what advertisements to display on the infected computer. Adware:Win32/CloverPlus may also create URL shortcuts to the Desktop and Favorites folders connecting to the advertisement websites.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



clover_updater.exe File name: clover_updater.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
c_updater.exe File name: c_updater.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\brainclan cp\ File name: %ProgramFiles%\brainclan cp\
Group: Malware file
%ProgramFiles%\koreamessenger cp\ File name: %ProgramFiles%\koreamessenger cp\
Group: Malware file
%ProgramFiles%\artsnews cp\ File name: %ProgramFiles%\artsnews cp\
Group: Malware file
%ProgramFiles%\CloverPlus\ File name: %ProgramFiles%\CloverPlus\
Group: Malware file
%ProgramFiles%\intothemap cp\ File name: %ProgramFiles%\intothemap cp\
Group: Malware file
%ProgramFiles%\drapt cp\ File name: %ProgramFiles%\drapt cp\
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run = "clover_u" = "[installation folder]\clover_updater.exe"HKEY_CURRENT_USER\Software\Microsoft\CloverPlus = "pid" = "[random hex number]"HKEY_CURRENT_USER\Software\Microsoft\CloverPlus = "sidebar_loaddate" = "[current month and day]"HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\CloverPlus
Loading...