This adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 690,376 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 03 Oct 2012
Arrival Details
This adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This adware drops the following files:
- %User Temp%\nsr2E.tmp\rkverify.exe
- %Program Files%\Drunken Obama\Drunken Obama.exe
- %Program Files%\Drunken Obama\uninst.exe
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.. %Program Files% is the default Program Files folder, usually C:\Program Files.)
It creates the following folders:
- %Program Files%\Drunken Obama
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)
Other System Modifications
This adware adds the following registry entries as part of its installation routine:
HKEY_CURRENT_USER\Software\GetFunGame
UID = "296451073"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\App Paths\
Drunken Obama.exe
{default} = "%Program Files%\Drunken Obama\Drunken Obama.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Drunken Obama
DisplayName = "Drunken Obama 1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Drunken Obama
UninstallString = "%Program Files%\Drunken Obama\uninst.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Drunken Obama
DisplayIcon = "%Program Files%\Drunken Obama\Drunken Obama.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Drunken Obama
DisplayVersion = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Drunken Obama
Publisher = "GetFunGame"
It adds the following registry keys as part of its installation routine:
HKEY_CURRENT_USER\Software\GetFunGame
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\App Paths\
Drunken Obama.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
Drunken Obama
Other Details
This adware connects to the following possibly malicious URL:
Connect with us on
| | | |