Home Malware Programs Viruses Win32/DownloadAdmin.G

Win32/DownloadAdmin.G

Posted: April 17, 2013

Threat Metric

Ranking: 2,105
Threat Level: 1/10
Infected PCs: 47,008
First Seen: April 17, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

Win32/DownloadAdmin.G is a virus that is associated with rootkits. Win32/DownloadAdmin.G is hard to find and remove by many security tools. Win32/DownloadAdmin.G drops other PC threats on the corrupted PC, such as spyware, adware, Trojans, and many other. Win32/DownloadAdmin.G can install it partially or in fill as it executes the loads with hacked Administrator's authorizations. Win32/DownloadAdmin.G may hijack the targeted web browser and cause annoying redirects to suspicious websites. Win32/DownloadAdmin.G may display unwanted pop-up ads while the victim is surfing the Internet.

Aliases

Generic.B09 [AVG]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%LOCALAPPDATA%\UpdateAdmin\UpdateAdmin.exe File name: UpdateAdmin.exe
Size: 225.55 KB (225552 bytes)
MD5: 716f86364ccebb506308ab8cbec238b3
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\UpdateAdmin
Group: Malware file
Last Updated: May 30, 2017
%LOCALAPPDATA%\UpdateAdmin\UpdateAdmin.exe File name: UpdateAdmin.exe
Size: 4.71 MB (4710160 bytes)
MD5: a2626b7668c0058fed2731b240f7a2ab
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\UpdateAdmin
Group: Malware file
Last Updated: May 30, 2017

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttp_www.downloadadmin.com_0.localstoragehttp_www.downloadadmin.com_0.localstorage-journalservice.updateadmin[1].xmlwww.downloadadmin[1].xmlHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Installer\Features\45B71F1875D5E58488CC6F2DD0665B0ESOFTWARE\Classes\Installer\Features\5C59CF75147BC96468703BC9CE248342SOFTWARE\Classes\Installer\Products\45B71F1875D5E58488CC6F2DD0665B0ESOFTWARE\Classes\Installer\Products\5C59CF75147BC96468703BC9CE248342SOFTWARE\Classes\Installer\UpgradeCodes\E71AAEE8659CC5148A67A8122969D921Software\DownloadAdminSoftware\EscoladeSoftware\Microsoft\Internet Explorer\DOMStorage\downloadadmin.comSoftware\Microsoft\Internet Explorer\DOMStorage\service.updateadmin.comSoftware\Microsoft\Internet Explorer\DOMStorage\updateadmin.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.downloadadmin.comSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdateAdminSOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\E71AAEE8659CC5148A67A8122969D921SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UpdateAdminHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{07B4B423-E4DA-47D1-8327-B589EB4BEB58}{2DDF4FAF-F9ED-4D76-BB6C-29027CE4202C}{57FC95C5-B741-469C-8607-B39CEC423824}{81F17B54-5D57-485E-88CC-F6D20D66B5E0}{8F1CD30B-3A84-4B95-BFA4-CC0F885B8463}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\UpdateAdmin%ALLUSERSPROFILE%\Start Menu\Programs\UpdateAdmin%APPDATA%\Microsoft\Windows\Start Menu\Programs\UpdateAdmin%LOCALAPPDATA%\UpdateAdmin%USERPROFILE%\Local Settings\Application Data\UpdateAdmin
Loading...