When Adware.Webentrance is installed, it performs the following actions:
- Modifies the value:
"Start Page" = "[http://]www.we[REMOVED]"
in the registry subkey:
HKEY_ALL_USERS\Software\Microsoft\Internet Explorer\Main
so that the Internet Explorer home page is changed to www.we[REMOVED].com.
- Adds one of the following registry values:
"MSys32" = "[PATH TO ADWARE]\morfitwe.exe"
"MSys32" = "[PATH TO ADWARE]\fe33c1ae.exe"
to the registry subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
so that the it runs every time Windows starts.
Note: If this registry subkey is not present, the risk adds one of the the same values to the following registry subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- Adds the value:
"Current" = "[VARIABLE]"
(where [VARIABLE] is a variable used by the program)
to the registry subkey:
HKEY_ALL_USERS\Software\sysM32\Current