Alias/esAdware/AbetterIntrnt.A, Adware/Abetterintrnt.DLDR, Adware/Abetterintrnt.DR, Hijacker/AbetterInternet | ||||||||||||
Detection Availability
| ||||||||||||
Visible Symptoms
| ||||||||||||
Detailed AnalysisThis Adware is a utility that downloads files and "upgrades" software. The files are commonly retrieved from these web sites -www.abetterinternet.com download.abetterinternet.com The executable programs initially connect to 'thinstall.abetterinternet.com' to download additional files. The following files are secretly downloaded and detected as follows: Ceres.cab => Adware/Betterinternet Csnopol.cab => Adware/Betterinternet Polau2c.exe => Download/Agent.AY Farmmext.exe => Download/Stubby.C After downloading, the Cab files are installed in the system and the exe programs are copied into the System32 directory. These exe files, Farmmext.exe and Ceres.DLL (from Ceres.cab), are hooked up into the registry to execute whenever the system is started. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrenVersion\Run | ||||||||||||
Recommended Action
|