Scan Spyware on Twitter
Friday, March 19, 2010

Bookmark and Share



adblock


Description: AdBlock is a program to stop advertisement popup windows from Internet Explorer. When AdBlock is installed, it adds a toolbar button to the Internet Explorer and redirects the IE search settings to unwanted advertisement web pages. AdBlock also monitors user browsing habbits and sends them to its controlling server.

Malware Threat

adblock

Files

  • C:\Windows\Downloaded Program Files\APHelper.dll

Registry Keys

  • HKEY_CLASSES_ROOT\\APHelper.APConfig
  • HKEY_CLASSES_ROOT\\APHelper.APConfig.1
  • HKEY_CLASSES_ROOT\\APHelper.APInstaller
  • HKEY_CLASSES_ROOT\\APHelper.APInstaller.1
  • HKEY_CLASSES_ROOT\\APHelper.APToolBarHelper
  • HKEY_CLASSES_ROOT\\APHelper.APToolBarHelper.1
  • HKEY_LOCAL_MACHINE\Software\Classes\APHelper.APConfig
  • HKEY_LOCAL_MACHINE\Software\Classes\APHelper.APConfig.1
  • HKEY_LOCAL_MACHINE\Software\Classes\APHelper.APInstaller
  • HKEY_LOCAL_MACHINE\Software\Classes\APHelper.APInstaller.1
  • HKEY_LOCAL_MACHINE\Software\Classes\APHelper.APToolBarHelper
  • HKEY_LOCAL_MACHINE\Software\Classes\APHelper.APToolBarHelper.1
  • HKEY_CLASSES_ROOT\CLSID\{54EC170F-6EB1-47C6-9C4D-EB0BE20CE45E}
  • HKEY_CLASSES_ROOT\CLSID\{93829908-07C2-44A2-95DB-F78F201A9B48}
  • HKEY_CLASSES_ROOT\CLSID\{CCF99CD5-1BCF-4DB2-8197-E9864A99702B}
  • HKEY_CLASSES_ROOT\TypeLib\{A37D57BD-5A27-4F8C-AB59-E0F6A7A0E95A}
  • HKEY_CLASSES_ROOT\Interface\{12DEBC84-B743-423A-825C-049AD85309DC}
  • HKEY_CLASSES_ROOT\Interface\{9B33399E-89A6-4EA5-91A9-5DC72B7AF60A}
  • HKEY_CLASSES_ROOT\Interface\{EE1BC3C2-D245-4E64-A6B6-06425A3A5997}
  • HKEY_CURRENT_USER\SOFTWARE\Linkz
  • HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{54EC170F-6EB1-47C6-9C4D-EB0BE20CE45E}
  • HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{93829908-07C2-44A2-95DB-F78F201A9B48}
  • HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{CCF99CD5-1BCF-4DB2-8197-E9864A99702B}
  • HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{A37D57BD-5A27-4F8C-AB59-E0F6A7A0E95A}
  • HKEY_LOCAL_MACHINE\Software\Classes\Interface\{12DEBC84-B743-423A-825C-049AD85309DC}
  • HKEY_LOCAL_MACHINE\Software\Classes\Interface\{9B33399E-89A6-4EA5-91A9-5DC72B7AF60A}
  • HKEY_LOCAL_MACHINE\Software\Classes\Interface\{EE1BC3C2-D245-4E64-A6B6-06425A3A5997}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{7E34CCAC-2531-450E-8746-80DA107ADAF5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D1E435DB-EE0C-4A71-84A8-A270F03B3EE7}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{54EC170F-6EB1-47C6-9C4D-EB0BE20CE45E}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{93829908-07C2-44A2-95DB-F78F201A9B48}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54EC170F-6EB1-47C6-9C4D-EB0BE20CE45E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{93829908-07C2-44A2-95DB-F78F201A9B48}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\%windir%/Downloaded Program Files/APHelper.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{93829908-07C2-44A2-95DB-F78F201A9B48}

Registry Values

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\%windir%\Downloaded Program Files\APHelper.dll

Clsids

  • {54EC170F-6EB1-47C6-9C4D-EB0BE20CE45E}
  • {93829908-07C2-44A2-95DB-F78F201A9B48}