Threat Database Trojans Troj/AdClick-FR

Troj/AdClick-FR

By ESGI Advisor in Trojans

Troj/AdClick-FR is a trojan horse that is executed when inexperienced users click on an unknown file that has been downloaded onto the computer. Once active, Troj/AdClick-FR disables anti-virus programs and security related software, while modifying the registry entries in order to begin running as soon as Windows starts up.

File System Details

Troj/AdClick-FR may create the following file(s):
# File Name Detections
1. \processor.bat

Registry Details

Troj/AdClick-FR may create the following registry entry or registry entries:
1
0
UpdatesDisableNotify
\svchost.exe
2
HKLM\SYSTEM\CurrentControlSet\Services\NtLmSsp
4
DisableRegistryTools
FirewallDisableNotify
FirstRunDisabled
Processor
Hidden
ShowSuperHidden
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
HKLM\SYSTEM\CurrentControlSet\Services\wuauserv
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKLM\SOFTWARE\Microsoft\Security Center
FirewallOverride
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
Start
HKLM\SYSTEM\CurrentControlSet\Services\TlntSvr

Trending

Most Viewed

Loading...