Threat Database Adware Adware:Win32/CloverPlus

Adware:Win32/CloverPlus

By GoldSparrow in Adware

Adware:Win32/CloverPlus is an adware program that connects to a certain server to show advertisements on the screen of the compromised PC when the computer user is online. Adware:Win32/CloverPlus may also create URL shorcuts on the Desktop and Favorites folders. When activated, Adware:Win32/CloverPlus creates infectious files on the infected computer system. Adware:Win32/CloverPlus also makes modifications to the Windows Registry. Adware:Win32/CloverPlus may create the certain registry entry so that it can load automatically whenever you boot up Windows. Adware:Win32/CloverPlus also creates the certain registry entry as part of its installation process. Adware:Win32/CloverPlus is usually installed by an installer that may have the file names with the .exe extension. Adware:Win32/CloverPlus checks if the affected PC is connected to the Internet by striving to access Google and Microsoft websites. If the targeted computer is connected to the Internet, Adware:Win32/CloverPlus strives to connect to the certain servers to receive instructions on what advertisements to show on the corrupted PC. Adware:Win32/CloverPlus may also create URL shortcuts to the Desktop and Favorites folders connecting to the advertising websites.

File System Details

Adware:Win32/CloverPlus may create the following file(s):
# File Name Detections
1. c_updater.exe
2. clover_updater.exe

Registry Details

Adware:Win32/CloverPlus may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\CloverPlus = "pid" = "[random hex number]"
HKEY_CURRENT_USER\Software\Microsoft\CloverPlus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run = "clover_u" = "[installation folder]\clover_updater.exe"
HKEY_CURRENT_USER\Software\Microsoft\CloverPlus = "sidebar_loaddate" = "[current month and day]"

Trending

Most Viewed

Loading...