Home / malwarePDF  

Adware:Win32/Adparatus


First posted on 31 July 2010.
Source: SecurityHome

Aliases :

There are no other names known for Adware:Win32/Adparatus.

Explanation :

Adware:Win32/Adparatus is a program that may display pop-up advertisements when certain links are visited.
Top

Adware:Win32/Adparatus is a program that may display pop-up advertisements when certain links are visited. Installation Adware:Win32/Adparatus may create the following mutexes:

  • Adparatus Ad Windows Mutex
  • Global\AdparatusUninstallerMutex
  • Global\AdparatusSetupMutex
  • When installed, it may drop the following files:
  • %ProgramFiles%\Adparatus\Adparatus.dll
  • %ProgramFiles%\Adparatus\Adparatus.exe
  • %ProgramFiles%\Adparatus\Adparatus.ico
  • %ProgramFiles%\Adparatus\AdparatusResources.dll
  • %ProgramFiles%\Adparatus\Support.url
  • %ProgramFiles%\Adparatus\Uninstall.exe
  • It may also add the following shortcut files:
  • <start menu>\Programs\Adparatus\About Adparatus.lnk
  • <start menu>\Programs\Adparatus\Adparatus Support.lnk
  • <start menu>\Programs\Adparatus\Uninstall Adparatus.lnk
  • Note: <start menu> refers to a variable location that is determined by the malware by querying the Operating System. The default location for the 'Start Menu' folder for Windows 9x, Me, NT, 2000, XP and 2003 is '%USERPROFILE%\Start Menu'. For Windows Vista and 7, the default location is '%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu'. Execution Displays advertisements Adware:Win32/Adparatus may display the following pop-up advertisements when the following links are visited:
  • search.duhiki.com
  • search.adparatus.com
  • search.yahoo.com
  • search.live.com
  • search.msn.com
  • google.com


  • Analysis by Francis Allan Tan Seng

    Last update 31 July 2010

     

    TOP