Besoin d’aide ? Fais appel à la communauté ou embauche un spécialiste.
Aller à Avira Answers
Virus:Adware/Adkubru.A.4
Date discovered:14/08/2012
Type:Adware/Spyware
In the wild:No
Reported Infections:Low to medium
Distribution Potential:Low
Damage Potential:Low
File size:92.160 Bytes
MD5 checksum:f46bb7130F6f081f3a700872e53f3784
VDF version:7.11.39.202 - Tuesday, August 14, 2012
IVDF version:7.11.39.202 - Tuesday, August 14, 2012

 General Method of propagation:
   • No own spreading routine


Aliases:
   •  Grisoft: Generic5.HHX
   •  Eset: a variant of Win32/Adware.Facetheme.D application
     Norman: Aggressive commersial W32/Suspicious_Gen4.ASCCB


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003
    Windows Vista
    Windows Server 2008
    Windows 7


Side effects:
   • Registry modification

 Registry It registers a browser helper object (BHO) by adding the following keys:

[HKCR\AppID\{186E19A3-B909-4F48-B687-BB81EB8BC7CE}]
   • "(Default)"="bho_project"

[HKCR\AppID\bho_project.DLL]
   • "AppID"="{186E19A3-B909-4F48-B687-BB81EB8BC7CE}"

[HKCR\Interface\{3AE26843-9171-4F23-A8E5-5421701276A4}]
   • "(Default)"="Ibho_object"

[HKCR\TypeLib\{B00FE392-639D-4688-976E-A1BFF368CB96}\1.0]
   • "(Default)"="bho_project 1.0 Type Library"

[HKCR\TypeLib\{B00FE392-639D-4688-976E-A1BFF368CB96}\1.0\0\win32]
   • "(Default)"="c:\sample.dll"

[HKLM\SOFTWARE\Classes\AppID\
   {186E19A3-B909-4F48-B687-BB81EB8BC7CE}]
   • "(Default)"="bho_project"

[HKLM\SOFTWARE\Classes\AppID\bho_project.DLL]
   • "AppID"="{186E19A3-B909-4F48-B687-BB81EB8BC7CE}"

[HKLM\SOFTWARE\Classes\Interface\
   {3AE26843-9171-4F23-A8E5-5421701276A4}]
   • "(Default)"="Ibho_object"

[HKLM\SOFTWARE\Classes\TypeLib\
   {B00FE392-639D-4688-976E-A1BFF368CB96}\1.0]
   • "(Default)"="bho_project 1.0 Type Library"

[HKLM\SOFTWARE\Classes\TypeLib\
   {B00FE392-639D-4688-976E-A1BFF368CB96}\1.0\0\win32]
   • "(Default)"="c:\sample.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
   Browser Helper Objects\{BA0454C5-FD30-428E-8DB9-3FF87A612F64}]
   • "(Default)"="BHO_PROJECT"
   • "NoExplorer"="dword:0x00000001"

Description insérée par Wensin Lee le jeudi 16 août 2012
Description mise à jour par Wensin Lee le jeudi 16 août 2012

Retour . . . .
https:// Cet écran est crypté pour votre sécurité.