View Single Post
Old 01-18-2005, 03:05 PM  
Snake
Confirmed User
 
Industry Role:
Join Date: Mar 2001
Posts: 126
Got this from sophos.com

Troj/Midaddle-C is a downloader Trojan for the Windows platform related to the MidAddle adware.
When executed Troj/Midaddle-C attempts to update MidAddle adware applications by downloading files from the following locations:
http://www.midaddle.com/config/update.xml
http://www.yellow-sticky.com/reload/clicks.dll
http://www.yellow-sticky.com/reload/clicksversion.txt
In order to be able to run automatically when Windows starts up Troj/Midaddle-C adds a new entry to the following registry key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run \
with the path ot the current file.
Also Troj/Midaddle-C sets the registry entries:
HKCU\Software\Microsoft\Internet Explorer\Main\Updater
HKCU\Software\Microsoft\Internet Explorer\Main\Enable Browser Extensions
The adware software installed by Troj/Midaddle-C can typically be uninstalled via the Add or Remove Programs dialog in the Windows Control Panel (Start ->Settings -> Control Panel -> Add/Remove Programs) by selecting the 'midADdle' entry.


Hope that helps
Snake is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote