Összefoglaló
Adware.GreatArcadeHits egy adware program, amely hirdetéseket fecskendez be a weboldalakra.
Leírás
Amikor a program feltelepül, akkor a következő mappákat hozza létre:
- %UserProfile%/Start Menu/Programs/GreatArcadeHits
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}/chrome
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}/chrome/content
Ezt követően létrehozza a következő fájlokat:
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/GAHUninstaller.exe
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/GAHUpdate.exe
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/GreatArcadeHitsIE.dll
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/Play Games online on GreatArcadeHits.com.url
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/application.ico
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/cookies.js
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/gahcrx.zip
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/gahff.xpi
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/premium.pem
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/static.js
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}/chrome.manifest
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}/chrome/content/application.js
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}/chrome/content/overlay.xul
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}/chrome/content/page.js
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}/chrome/content/static.js
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}/icon.png
- %UserProfile%/Local Settings/Application Data/GreatArcadeHits/{B21F5E31-B8E8-41CD-B74C-168A71A10E49}/install.rdf
- %UserProfile%/Start Menu/Programs/GreatArcadeHits/Play Games online on GreatArcadeHits.com.url
- %UserProfile%/Start Menu/Programs/GreatArcadeHits/Uninstall GreatArcadeHits.lnk
- %SystemDrive%/WINDOWS/Tasks/GreatArcadeHits.job
A kéretlen szoftver létrehozza a kövekező bejegyzéseket a regisztráció adatbázisban:
- HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{D0C21091-FF8E-432C-9006-0540E81BA9D7}”@” = “GreatArcadeHits Add-on”
- HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{D0C21091-FF8E-432C-9006-0540E81BA9D7}”NoExplorer” = “1”
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionUNINSTALL{856AD396-519D-4C7A-BED6-6785F64924BC}”UninstallString” = “%UserProfile%Local SettingsApplication DataGreatArcadeHitsGAHUninstaller.exe”
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionUNINSTALL{856AD396-519D-4C7A-BED6-6785F64924BC}”URLInfoAbout” = “www.GreatArcadeHits.com”
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionUNINSTALL{856AD396-519D-4C7A-BED6-6785F64924BC}”Publisher” = “GreatArcadeHits”
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionUNINSTALL{856AD396-519D-4C7A-BED6-6785F64924BC}”HelpLink” = “www.GreatArcadeHits.com”
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionUNINSTALL{856AD396-519D-4C7A-BED6-6785F64924BC}”DisplayVersion” = “1.0”
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionUNINSTALL{856AD396-519D-4C7A-BED6-6785F64924BC}”DisplayName” = “GreatArcadeHits”
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionUNINSTALL{856AD396-519D-4C7A-BED6-6785F64924BC}”DisplayIcon” = “%UserProfile%Local SettingsApplication DataGreatArcadeHitsapplication.ico”
- HKEY_CURRENT_USERSoftwareMOZILLAFIREFOXEXTENSIONS”{B21F5E31-B8E8-41CD-B74C-168A71A10E49}” = “%UserProfile%Local SettingsApplication DataGreatArcadeHits{B21F5E31-B8E8-41CD-B74C-168A71A10E49}”
- HKEY_CLASSES_ROOTTypeLib{5530C971-3D8F-471B-AC49-4CC23FA955E2}1.0HELPDIR”@” = “%UserProfile%Local SettingsApplication DataGreatArcadeHits”
- HKEY_CLASSES_ROOTTypeLib{5530C971-3D8F-471B-AC49-4CC23FA955E2}1.0FLAGS”@” = “0”
- HKEY_CLASSES_ROOTTypeLib{5530C971-3D8F-471B-AC49-4CC23FA955E2}1.0″@” = “GAHPremiumObject”
- HKEY_CLASSES_ROOTTypeLib{5530C971-3D8F-471B-AC49-4CC23FA955E2}1.0 win32″@” = “%UserProfile%Local SettingsApplication DataGreatArcadeHitsGreatArcadeHitsIE.dll”
- HKEY_CLASSES_ROOTInterface{EE0C9EF1-B2AD-407B-9707-0124CC9BF85E}TypeLib”@” = “{5530C971-3D8F-471B-AC49-4CC23FA955E2}”
- HKEY_CLASSES_ROOTInterface{EE0C9EF1-B2AD-407B-9707-0124CC9BF85E}TypeLib”Version” = “1.0”
- HKEY_CLASSES_ROOTInterface{EE0C9EF1-B2AD-407B-9707-0124CC9BF85E}ProxyStubClsid”@” = “{00020420-0000-0000-C000-000000000046}”
- HKEY_CLASSES_ROOTInterface{EE0C9EF1-B2AD-407B-9707-0124CC9BF85E}ProxyStubClsid32″@” = “{00020420-0000-0000-C000-000000000046}”
- HKEY_CLASSES_ROOTInterface{EE0C9EF1-B2AD-407B-9707-0124CC9BF85E}”@” = “_IContentControlEvents”
- HKEY_CLASSES_ROOTInterface{7FBC7ADD-4D75-4685-9BD4-30D3FBDD3AB4}TypeLib”@” = “{5530C971-3D8F-471B-AC49-4CC23FA955E2}”
- HKEY_CLASSES_ROOTInterface{7FBC7ADD-4D75-4685-9BD4-30D3FBDD3AB4}TypeLib”Version” = “1.0”
- HKEY_CLASSES_ROOTInterface{7FBC7ADD-4D75-4685-9BD4-30D3FBDD3AB4}ProxyStubClsid”@” = “{00020424-0000-0000-C000-000000000046}”
- HKEY_CLASSES_ROOTInterface{7FBC7ADD-4D75-4685-9BD4-30D3FBDD3AB4}ProxyStubClsid32″@” = “{00020424-0000-0000-C000-000000000046}”
- HKEY_CLASSES_ROOTInterface{7FBC7ADD-4D75-4685-9BD4-30D3FBDD3AB4}”@” = “IContentControl”
- HKEY_CLASSES_ROOTCLSID{D0C21091-FF8E-432C-9006-0540E81BA9D7}Version”@” = “1.0”
- HKEY_CLASSES_ROOTCLSID{D0C21091-FF8E-432C-9006-0540E81BA9D7}TypeLib”@” = “{5530C971-3D8F-471B-AC49-4CC23FA955E2}”
- HKEY_CLASSES_ROOTCLSID{D0C21091-FF8E-432C-9006-0540E81BA9D7}InprocServer32″@” = “%UserProfile%Local SettingsApplication DataGreatArcadeHitsGreatArcadeHitsIE.dll”
- HKEY_CLASSES_ROOTCLSID{D0C21091-FF8E-432C-9006-0540E81BA9D7}InprocServer32″ThreadingModel” = “Apartment”
- HKEY_CLASSES_ROOTCLSID{D0C21091-FF8E-432C-9006-0540E81BA9D7}”@” = “GreatArcadeHits Add-on“
A program ezután kiemeli szavakat a weblapok, és ha a felhasználó az aláhúzott szavak fölé viszi az egérmutatót, akkor jeleníti meg a hirdetéseket.
Támadás típusa
Manipulation of dataHatás
Loss of confidentiality (Bizalmasság elvesztése)Szükséges hozzáférés
Remote/Network (Távoli/hálózat)Hivatkozások
Egyéb referencia: www.symantec.com