SpywareSignatures.com
Security Email Alerts & Updates
Quick Links: Malware List | Malware Categories

00froud

00froud is an adware bundler that installs Adware-Purityscan (Outerinfo) with itself.Purityscan scans Internet Explorer files such like: browser, cache, history, and cookies for adult related material. After scanning these files for adult related keywords then ads will be served up to your computer.

General information:

Malware Name:00froud
Malware Type:Adware Bundler
Company Name:Unknown
Company URL:
Threat Level:Low Risk
Operating System:WIN XP
Installation Type:Installed through EXE
Operation:Time of After Installation

Company Description:

Spyware Description:

00froud is an adware bundler that installs Adware-Purityscan (Outerinfo) with itself.Purityscan scans Internet Explorer files such like: browser, cache, history, and cookies for adult related material. After scanning these files for adult related keywords then ads will be served up to your computer.

Characteristics/Symptoms:

    -> It installs Adware-Purityscan (Outerinfo) with itself. -> Purityscan scans Internet Explorer files such like: browser, cache, history, and cookies for adult related material. After scanning these files for adult related keywords then ads will be served up to your computer.

Additional information might be found here:

googleSearch at Google for 00froud
bingSearch at Bing for 00froud
yahooSearch at Yahoo for 00froud

Processes Running:

00froud.zip

File information Created after Installation:

File LocationSize (Bytes)Type
C:\Documents and Settings\All Users\Desktop\AAA Screensavers Downloads.lnk459Shortcut
C:\Documents and Settings\[USER]\Start Menu\Programs\Outerinfo\Uninstall.lnk1487Shortcut
C:\Program Files\Outerinfo\Terms.rtf18031Rich Text Format

Folder information Created after Installation:

Folder Location
C:\Program Files\AAA Screensaver
C:\Program Files\AAA Screensavers\00frou

Registry information Created after Installation:

Main Registry KeySub Registry KeyKey Value Name
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\408871709A0670846A329905E392D64F\SourceListLastUsedSource
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\408871709A0670846A329905E392D64F\SourceList\MediaDiskPrompt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{8D806D2A-54E8-4A88-BB1A-7EFE48A8668F}Changed