Updated: February 13, 2007 11:39:47 AM
Type: Adware
Version: 1.26.0.10
Publisher: Joltid
Risk Impact: Low
File Names: P2P Networking.exe,Marshal.dll
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
When the adware runs, it does the following:
- Creates the following files:
- %System%\P2P Networking\Peer-to-peer networking.exe
Peer-enabler client, detected as Adware.P2PNetworking
- %System%\P2P Networking\Marshal.dll
Data gathering and formatting component for peer-to-peer networking
- %System%\P2P Networking\P2P Networking.eng
- %System%\P2P Networking v126.cpl
Control panel component
- %System%\P2P Networking\Cache\*.*
Content cache
- %System%\P2P Networking\Cache\Database
Database cache
- %Windir%\Downloaded Program Files\WebP2PInstall.dll
Web installer, not always present
Notes:
- %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
- %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).
- Creates the following registry entries:
HKEY_CLASSES_ROOT\CLSID\{C91E8926-D4BE-4685-99F4-0D996B96BAC0}
HKEY_CLASSES_ROOT\CLSID\{1D6711C8-7154-40BB-8380-3DEA45B69CBF}
HKEY_CURRENT_USER\Software\P2P Networking
HKEY_LOCAL_MACHINE\Sofware\P2P Networking
- Adds the value:
"P2P Networking"="%System%\P2P Networking\P2P Networking.exe"
to the registry key, so that the adware runs when Windows is started:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run