[Symptom of Infection]
[Adware.DonkeyClean.253135] is an adware that is installed without user agreement.
- It adds itself to registry for automatic execution on system reboot.
[PIC 1] Main Feature

[PIC 2] Desktop Icon

<Related URL>
hxxp://log.(...).com/logonmuz/adexp.php?zone=(...) hxxp://(...).co.kr/connect/installcount.php?pid=(...) hxxp://uck.(...).co.kr/app/update/VerChk.php?pid=(...) hxxp://uck.(...).co.kr/app/down/(...)/ad.ndb hxxp://uck.(...).co.kr/app/down/(...)/adp.ndb hxxp://uck.(...).co.kr/app/down/(...)/adcr.ndb hxxp://uck.(...).co.kr/app/down/(...)/DonkeyClean.exe hxxp://uck.(...).co.kr/app/down/(...)/DonkeyCleanEA.dll hxxp://uck.(...).co.kr/app/down/(...)/DonkeyCleanUPK.dll hxxp://uck.(...).co.kr/app/down/(...)/DonkeyCleanR.exe hxxp://uck.(...).co.kr/app/update/VerChk.php?pid=(...)
<File> [Adware.DonkeyClean.253135] creates files like below.
(Quick Launch Folder)\DonkeyClean.lnk (Desktop Folder)\DonkeyClean.lnk (Startup Folder)\DonkeyClean.lnk (Programs Folder)\DonkeyClean\adcr.ndb (Programs Folder)\DonkeyClean\Config.dat (Programs Folder)\DonkeyClean\DonkeyCleanUPK.dll (Programs Folder)\DonkeyClean\Version.dat
<Registry>
[Adware.DonkeyClean.253135] creates registries like below. HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{75CF4C66-5A70-4423-A5BD-8F9762D4A4F0} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DonkeyClean HKLM\SOFTWARE\DonkeyClean HKLM\SOFTWARE\DCNetLic HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Name: DonkeyClean Value: "(Programs Folder)\DonkeyClean\DonkeyClean.exe" /shide"
<Folder> [Adware.DonkeyClean.253135] creates folders like below.
(Startup Folder)\Programs\DonkeyClean (Programs Folder)\DonkeyClean
<Notation>
- "(All Users Account Folder)" could be different by user settings, and generally this is "C:\Documents and Settings\(All Users Account)".
- "(Desktop Folder)"could be different by OS and generally this is "C:\Documents and Settings\(User Account)\Desktop".
- "(Quick Launch Folder)" could be different by OS(or User), and generally this is "C:\Documents and Settings\(User Account)\Application Data\Microsoft\Internet Explorer\Quick Launch".
- "(Temp Folder)" could be different by OS, and generally this is "C:\Documents and Settings\(User Account)\Local Settings\Temp".
- "(Programs Folder)" could be different by OS and generally this is "C:\Program Files".
- "(Windows Folder)" could be different by OS and generally this is "C:\Windows".
- "(System Folder)" could be different by OS and generally this is "C:\Windows\System32"
|