ADW_SULPUA
Publish Date: 27 de kwietnia de 2015
Riskware/Salus (Fortinet), a variant of Win32/Adware.Salus.A application (ESET-NOD32)
PLATFORM:
Windows
OVER ALL RISK RATING:
DAMAGE POTENTIAL::
DISTRIBUTION POTENTIAL::
REPORTED INFECTION:
INFORMATION EXPOSURE:
Low
Medium
High
Critical
Threat Type:
Adware
Destructiveness:
No
Encrypted:
In the wild::
Yes
OVERVIEW
TECHNICAL DETAILS
File size: 2,391,040 bytes
File type: EXE
Memory resident: No
INITIAL SAMPLES RECEIVED DATE: 23 marca 2015
Instalación
Infiltra los archivos siguientes:
- {adware path}\{adware filename}.log
- {adware path}\SSL\Salus CA.ce
- {adware path}\SSL\Salus CA.pvk
Crea las carpetas siguientes:
- {adware path}
- {adware path}\SSL
Otras modificaciones del sistema
Agrega las siguientes entradas de registro como parte de la rutina de instalación:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services
{adware filename} =
Agrega las siguientes entradas de registro:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\{adware filename}
DisplayName = "{adware filename}"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\{adware filename}
Group = "PNP_TDI"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\{adware filename}
ImagePath = "system32\drivers\{adware filename}.sys"