Dudu Accelerator
|
Description:
|
Adware
|
|
Risk Level:
|
Low
|
|
Date of First Occurence:
|
Wednesday, June 18, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Adware
Software that is displaying pop-up/pop-under windows containing advertisements when the primary user interface is not visible or displayed advertisements are not related to the product.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
ELIMINAR SPYWARE »
Geographical Distribution of Threat "Dudu Accelerator"
Threat Info
View All
Detected Items
- Detected Files:
%PROGRAMFILES%\DuDu\Speed\ddsdudupros.exe
MD5: 3EEC737FCC7E89B187842C08D0B32C6F Size:360448
%PROGRAMFILES%\DuDu\Speed\dhtiaal.dll
MD5: F0F9FD73778300A3B468C46F32D4CA3C Size:323584
- Detected Files with variable Filenames:
Detecting items list:
- Files by Name
%PROGRAMFILES%\DuDu\Speed\btdl.dll
%PROGRAMFILES%\DuDu\Speed\ddddl.dll
%PROGRAMFILES%\DuDu\Speed\dddiemon.dll
%PROGRAMFILES%\DuDu\Speed\dddmext.dll
%PROGRAMFILES%\DuDu\Speed\dddrec.dll
%PROGRAMFILES%\DuDu\Speed\dddsch.dll
%PROGRAMFILES%\DuDu\Speed\dhtiwl.dll
%PROGRAMFILES%\DuDu\Speed\DuDuAcc.exe
%PROGRAMFILES%\DuDu\Speed\dudupros.exe
%PROGRAMFILES%\DuDu\Speed\recorder.exe
%PROGRAMFILES%\DuDu\Speed\rsen.dll
%PROGRAMFILES%\DuDu\Speed\UnInst.exe
%START_PROGRAMSALL%\DuDu Speed\Run DuDu Speed.lnk
%START_PROGRAMSALL%\DuDu Speed\Uninstall DuDu Speed.lnk
%SystemDiskRoot%\Documents and Settings\All Users\Desktop\DuDu Speed.lnk
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\DuDu Speed.lnk
- Files by Directories
%PROGRAMFILES%\DuDu\Speed %START_PROGRAMSALL%\DuDu Speed
- Files by CLSID or Name
CLSID=00018593-C6BD-46F7-9349-DBA1AA674C90
CLSID=93F643D6-4CC8-4aa7-990F-F82C13E24373
CLSID=C572FB5D-9C65-47FD-899A-1166C90B8136
- Registry Keys
HKCR\.dd!
HKCR\ddd.dd!
HKCR\Dddiemon.customdl
HKCR\Dddiemon.customdl.1
HKCR\Dddiemon.dddmont
HKCR\Dddiemon.dddmont.1
HKCR\Dddmext.dlmgr
HKCR\Dddmext.dlmgr.1
HKLM\SOFTWARE\Dudu
HKLM\SOFTWARE\Dudu\Speed
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9B4C4803-1A68-4D45-B9CC-7D9F9BF7ABE7}
«
Go to Software Database