Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:ADWARE/Baxia.A
Date discovered:01/10/2012
Type:Adware/Spyware
In the wild:No
Reported Infections:Low to medium
Distribution Potential:Low
Damage Potential:Low
VDF version:7.11.44.208 - Monday, October 1, 2012
IVDF version:7.11.44.208 - Monday, October 1, 2012

 General Method of propagation:
   • No own spreading routine


Alias:
   •  Eset: a variant of Win32/InstallCore.AW application


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003
   • Windows Vista
   • Windows Server 2008
   • Windows 7


Side effects:
   • Registry modification


Right after execution the following information is displayed:


 Files The following files are created:

– Non malicious files:
   • %temp%\ish154656\css\ie6_main.css; %temp%\ish154656\css\main.css;
      %temp%\ish154656\css\sdk-ui\browse.css;
      %temp%\ish154656\css\sdk-ui\button.css;
      %temp%\ish154656\css\sdk-ui\checkbox.css;
      %temp%\ish154656\css\sdk-ui\images\button-bg.png;
      %temp%\ish154656\css\sdk-ui\images\progress-bg-corner.png;
      %temp%\ish154656\css\sdk-ui\images\progress-bg.png;
      %temp%\ish154656\css\sdk-ui\images\progress-bg2.png;
      %temp%\ish154656\css\sdk-ui\progress-bar.css;
      %temp%\ish154656\csshover3.htc;
      %temp%\ish154656\defaultOffer\images\toolbar.png;
      %temp%\ish154656\form.bmp.Mask; %temp%\ish154656\images\bg.png;
      %temp%\ish154656\images\close.png; %temp%\ish154656\images\close_hover.png;
      %temp%\ish154656\images\color_btn.png;
      %temp%\ish154656\images\color_btn_hover.png;
      %temp%\ish154656\images\grey_btn.png;
      %temp%\ish154656\images\grey_btn_hover.png;
      %temp%\ish154656\images\icon_generic.png;
      %temp%\ish154656\images\loader.gif; %temp%\ish154656\images\pause_btn.png;
      %temp%\ish154656\images\progress.png;
      %temp%\ish154656\images\progress_bar.png;
      %temp%\ish154656\images\resume_btn.png; %temp%\ish154656\images\sheild.jpg;
      %temp%\ish154656\images\sheild.png;
      %temp%\ish154656\images\welcome_prod_box.png;
      %temp%\is701137889\1125036979.cfg; %temp%\is701137889\1269731322.cfg

– Temporary files that might be deleted afterwards:
   • %temp%\ish154656\bootstrap_49979.html
   • %temp%\000290EB.log
   • %temp%\000292A1.log
   • %temp%\0003A7DA.log
   • %temp%\0003A837.log
   • %temp%\00025C01.log

 Miscellaneous Internet connection:
In order to check for its internet connection the following DNS servers are contacted:
   • os.bai**********cdn.com/Baixaki/?v=2.0&c=1786031361
   • dl.bai**********.com.br/programas/48923/aTube_Catcher_Setup.exe
   • www.bai**********.com.br/imagens/2011/10/programas/489231015854-o.jpg
   • cdneu.bai**********cdn.com/ofr/FunmoodsLatest.cis

Description inserted by Wensin Lee on Wednesday, October 3, 2012
Description updated by Wensin Lee on Wednesday, October 3, 2012

Back . . . .