Adware/ShopAtHomeSelect is an Adware Agent downloaded from www.ShopAtHomeSelect.com.
This agent is installed when the user registers from the site.
By selecting the option "to download Golden Retriever software"
and accepting the certificate from the site,
the agent will be installed into the computer.
|
While installing, it downloads a compressed file from the site
and extract into the following files:
|
|
C:/WINNT/Downloaded Program Files/aj8sml3fo_.exe
C:/WINNT/Downloaded Program Files/h63v2629j_.exe
C:/WINNT/Downloaded Program Files/lcp4q80t9_.dll
C:/WINNT/Downloaded Program Files/uu1en13ec_.exe
C:/WINNT/Downloaded Program Files/WEBInstaller.dll
|
|
Then, it modifies the registry to include the files extracted:
|
|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C0EF89EE-EEC7-4535-A041-F1EBF79560A7}\Contains\Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
|
|
This agent also updates the Security Setting of Internet Explorer
allowing the affected machine to download and execute unsigned ActiveX Controls.
|
When the visiting the site, the data are cache into the following cookies:
|
|
cookies for
ehg-shopathome.hitbox
hitbox.txt
www.shopathomeselect.txt
|
|