180searchAssistant
|
Popis:
|
Adware
|
|
Úroveň rizika:
|
Vysoké
|
|
Datum 1. výskytu:
|
Monday, April 14, 2008
|
|
Poskytovatel Softwaru:
|
180solutions, Inc.
|
|
Stručné informace:
|
180searchAssistant is an adware program that monitors the contents of Web browser windows.
|
|
Odstranění:
|
Tento škodlivý software může být odstraněn pomocí "Spyware
Terminatora"
|
Geogr. rozdělení softwaru "180searchAssistant"
Info o škodlivém softwaru
Zobrazit vše
Detected Items
- Detected Files:
%DOWNLOADEDPROGRAMFILES%\ClientAx.dll
MD5: D1689FEDA3ACD6303A38FE0587FDD5FF Size:1222768
MD5: 3983C2B73930E198C2F9DF1C38BA617F Size:1220608
MD5: BF9CC51D7C7FA17C2B3EE74C43670132 Size:618496
MD5: D9FAF4D6F357601512DF079AE622FBF1 Size:430080
MD5: 27743CDD95FFA32237B48AAE0CCD464E Size:417792
MD5: 0B9CBD5759EF62C58DC1048F867D3FAC Size:417792
MD5: EF23A43EEAF378FC1EACCAE57897C540 Size:1118208
MD5: 2B0D5ACD137730A73F970CB1037F0FCF Size:417792
MD5: 9EC282E25D51E95C73815575422CAAC5 Size:417792
MD5: 7270FB07EE114C4A178400DC6E93D1AB Size:1220608
MD5: 36D23D4BF3991B49F78CBA632661850C Size:1216512
MD5: 8C518E5E92A736918C980A327F186DE3 Size:1226864
and more....
%DOWNLOADEDPROGRAMFILES%\ClientAX.dll
MD5: 38B995929A50EB7BEF84A708D952FB7C Size:1226864
MD5: 461E7FCD5628FB61848B1C85700400B4 Size:1216512
MD5: 76F715947580CE53767E94CD4A1FEB67 Size:602112
MD5: EF7AAFB0A300066AFCEE8EFCED5EB6C7 Size:1222768
MD5: A549932817B636E601832441C663AEB5 Size:1224704
MD5: EC9255F0D410ABB72031164C0BBBF5AA Size:1296496
MD5: 08ABDDD6EC7A4688AE72D5D1049980ED Size:1173616
MD5: 2E41D941773381C00407FCA28AB287E9 Size:1118208
MD5: 3272AD324A1600B561B33EE3AB44660C Size:577536
MD5: A441079BDD0C985D657EE5B9ED7DC267 Size:1118208
MD5: 006C77D25308BE2EB435C574B749BB83 Size:1173616
MD5: A945C0696238D948676CA1EB4A42BC75 Size:602112
and more....
%PROGRAMFILES%\180Search Assistant\180sahook.dll
MD5: 183E3601A7CCF8E29F5CB5D623F14CC4 Size:118784
%PROGRAMFILES%\180search Assistant\180sa.exe
MD5: 1C1119EDA85669B743F7AD53F794643A Size:621056
%WINDIR%\180ax.exe
MD5: 24E257923242CB0A690954B7AAF1BB87 Size:29184
MD5: 20AD8C1B60D1D8213FF6C3E3CFAA078C Size:19968
MD5: D028B99AB8842815B5F5BF890FCC4288 Size:22016
MD5: 254C8252C88BFA8CE5935EB1C935D4F5 Size:17152
MD5: 2B91DF027E9F46903C5469A36769966A Size:26624
MD5: AC7C7D52C6B6206E6040B13964D901AD Size:10496
MD5: C55522505CA81291211E42F0CDC5EBE2 Size:32768
MD5: CE3A1A13055593D9D50AFD6D29FA0A8B Size:24064
MD5: 27159812F96EF45F88C084071373D84C Size:15104
MD5: 44D920C62F22C4DA5236759395DB31AC Size:65014
MD5: 96095E44A22ADF79B697F7572F4881F3 Size:20992
MD5: C1EF545B8FD8705F9D78D9F555B671E2 Size:8448
and more....
%PROGRAMFILES%\180Search Assistant\sau.exe
MD5: 2E62E1A17F6F6ADCB145AD3A5FE0C8A0 Size:8960
MD5: B610270536EC27B3BD1A1972E846C559 Size:8192
MD5: 1626284FE0003C7163CB55792B8409AB Size:20480
MD5: A32BA1B4CA411360DDA0837DFA2E02DE Size:26880
MD5: 771FCCFEEB2E36910F2321C7333739D4 Size:28416
MD5: B33A5A4BF8ED14E9285BF0A34E3AAB49 Size:32256
MD5: 39F517A665A000652FA48A41F82E30BB Size:8704
MD5: D8F82B3387D0AE7BF6DFE235880CF09A Size:11776
MD5: 37C96AB47B4782127968405028866E26 Size:31488
MD5: 3F892BA46330A76B36C51B82670C2A53 Size:19968
MD5: 60C3D32F157CD530A8D871653A8B74D0 Size:17152
MD5: FC384D5BF2CABB5A0815EE271BB2A1B4 Size:15360
and more....
%PROGRAMFILES%\180Search Assistant\180sa.exe
MD5: 414ED2BEAA20A0E7C80C0ED3EF6FA9B2 Size:24064
MD5: B58454A76E672C4BEEF255B1C145C44E Size:18176
MD5: 2DA41C7BF7DB743F76417F34FA9FD6C8 Size:23296
MD5: E41F7C94D075033DE205093FAA8007A4 Size:23552
MD5: 731140AF0FFCB8E8293C5F4B5D653FA5 Size:30208
MD5: 025EF3B1E14E200E74979646AF452E3C Size:16384
MD5: 14A2DF6CB09BD9D03E72B44A7DDC7D22 Size:10752
MD5: 0395247E9A34D450AB9F3D59F747091C Size:8704
MD5: B11373F3B94D32EF8AEDB99AD52B0FF8 Size:10240
MD5: 1BA7D3BFFBDF1E64AEE9182BFDF51813 Size:32768
MD5: B50C691F0F857D4C93E5F3ED5B7D37D1 Size:18688
MD5: D772A01D4F5127632E9F2881CD9D847D Size:29184
and more....
%WINDIR%\salm.exe
MD5: DAA0057E4B854B08ED3E063057272C35 Size:28672
MD5: 43E06F273BDA5280369B09826453B19B Size:9728
MD5: A1ABBF3998F65422ACCF69517ECB8458 Size:22784
MD5: 88CB8A6DF677CFA22770BE007A17D515 Size:13568
MD5: 1040D94E566C5AC9C4C5A543AD1DA5C3 Size:9472
MD5: 30B4F1406E0ACB672684E7294EC4549D Size:11520
MD5: 6DA97229F504551DF371A08C41238FCF Size:11520
MD5: EDEAC2A85A243FF9A60773F9B17D1173 Size:18432
MD5: 697745C820F2D3375604EA60B59A4205 Size:25856
MD5: 0A96923C6D1C51F92E0385A41FD7AB22 Size:14848
MD5: DA392F46EEAE91DF026E75749E6107EF Size:19712
MD5: 52D8B287AB54AA40E7B21197EACBA9D5 Size:26624
and more....
%WINDIR%\salmbundle.exe
MD5: 8FC2CB8604A22207653BD0CB6AEBDA82 Size:177448
MD5: 5AB86E4BFD2D9A454739372CFBC9D0D5 Size:2047
%WINDIR%\180ax.exe
MD5: 2A74025B880485103CF78F88C35E1E7E Size:12800
MD5: E7D195CAB75F21FCFA54AECF7815A5B4 Size:23296
MD5: 5C77A2DD3566DA0E2B30C9D6D8A93F79 Size:26368
MD5: 45AA6067544B7A73A384450F6DEB40F0 Size:12544
MD5: 361F83D7543083C01FB20E0E3C548CA1 Size:21248
MD5: 107185387CC62F5C40E23B15519C6EBF Size:26112
MD5: C14A3BA316FBF580309BCEB8133EBDEC Size:21248
MD5: FC9ABBFA6B58432B0B490F2D127AFEAB Size:16384
MD5: BB34E9638FF3057C771EFB8FEED16CE3 Size:25856
MD5: B6679A90EF603E2E16BD53BCF9B45BBC Size:19968
MD5: 709D7C365DC5BA778A17096710BAB6CA Size:32000
MD5: 09AA4AD27CB44FC075A285F3AF50CFFB Size:17152
and more....
%WINDIR%\salm.exe
MD5: D2026CF6656CA61491E06790088B91B1 Size:20736
MD5: C2CC0FCF54504F798F171D0D2040C742 Size:12544
MD5: A788863420730AC4EE75295B96A52197 Size:10240
MD5: 598D2A5C9D7EE0CBFB01718FA4365E00 Size:19456
MD5: 9A12622DC46C6F46A74E7FAFF7F2D900 Size:12032
MD5: 5EAD246927E4348E00ABF056B54E4777 Size:16640
MD5: D3FD5DDB850CDDFC918B131557DEEF1B Size:23808
MD5: 06679762198A4940721172AB23A1C63B Size:26368
MD5: A0561441A4F6C8A93E70A26949C47BE8 Size:20480
MD5: 398194936E0E1B7C910133422F1E5A0D Size:27392
MD5: C3401C8FDAF418E403C2DA5678F88E62 Size:14080
MD5: 3EEC8D2496F5983988C59815BA18D171 Size:18688
and more....
%DOWNLOADEDPROGRAMFILES%\ClientAX.dll
MD5: F9FD90530A6D65955B01380C256B24C1 Size:602112
MD5: 754AEB4CEF837687B9B1F5B010E86784 Size:999424
MD5: 3A1E3BC6BD36F1DE8F33B37D8430B980 Size:1173616
MD5: 1123BB0F6A303F95BBE0EB1E8755BEC4 Size:602112
MD5: F8DD33CE128C1659FC7E8455A206DBBD Size:1224704
MD5: 667B75081936EF28744DC70833220B09 Size:614400
MD5: F7E4F4261246F2D55E5FC0986C689F9F Size:1048576
MD5: ABB10E08A2AD7EEF762421A58A4DAA72 Size:1230960
MD5: AFD717EF2EE5D9B0D366F7A256A86893 Size:1290240
MD5: A611605551A1880BC786A4BC2524878C Size:385024
MD5: D6F6B2489DDA30E4D4082D94CBD473A6 Size:999424
%PROGRAMFILES%\180Search Assistant\sau.exe
MD5: DD92BC994D105FD6BAF59032AD74BE3B Size:26112
MD5: C79BB328AE6ACDD16251DF3622845B21 Size:19456
MD5: 4F9E49ED30BB763B99F42859583C4B2B Size:25088
MD5: C7041B5BABEDDDD20340C5A7E64A1928 Size:26368
MD5: 05570A624999BC78374A13CB6A157759 Size:13056
MD5: D4117FC071081EF2898AA4DF7C6C1380 Size:27136
MD5: 3B35E01BBA184D685BA1EAAD6AADE40B Size:29440
MD5: A71FA3B1794647CF1D5C6EA236A23199 Size:23296
MD5: 7C48847A27D9D71F7CA96263F48534B0 Size:27392
%WINDIR%\180ax.exe
MD5: 0A69F6407A4FA2A65508679EEA951A68 Size:24576
MD5: A89DDB6F2C69A9940C9E60EA88FE449A Size:309760
MD5: DE3B5C69466F563A65795918B5699BA5 Size:24832
MD5: 02857FE84871867021C156B4C56001B6 Size:27904
MD5: 8569422398B0CA324246086FA86F4A3B Size:29952
MD5: 6BAC3130DF7D2A9D5FA7A274F90B99CA Size:19712
MD5: D5454F3D114C1987E7ACC7F40C880C30 Size:14080
MD5: B000E20A0D348FFCF20CCBF02E8974F0 Size:28928
MD5: E9CE0428C9AB17F45CEB09C36B68DA65 Size:14848
MD5: 9B56241CF8F11225747599C1CEC02785 Size:15104
MD5: 12E6851E86E725B12035EE2101038611 Size:24576
MD5: DDE19D5FAE845C0D6A8E3202607598EB Size:8960
and more....
%PROGRAMFILES%\180Search Assistant\180sa.exe
MD5: 6E05EF8FB68C72C9C99726AB25017DEE Size:9984
MD5: 682F88A3B1E8834D9928B3EC814D0BA7 Size:29440
MD5: 854E8BC7387C0F1B0E744EB897C33E7D Size:10752
MD5: E670365A2F088F19443EA5F3B18082C1 Size:11520
MD5: 22DA53101C96B56D998625624E3CF902 Size:10496
MD5: 13AC2EEB32496D97F781BEC83B4D1EDF Size:20736
MD5: 0067B4DA2C6A11E866628491DAD2DB14 Size:25856
MD5: C2D8D9C5777828EF0CAEEB7063F64D73 Size:22016
%WINDIR%\salm.exe
MD5: BBC3BFC1CA300635A6DF8991564F4BF3 Size:18944
MD5: EA5B8C0B6AA7E822D0B318FFD4D13AC7 Size:16384
MD5: EBB0A7A65A790955BC459D69A3AC8C9A Size:18176
MD5: 0C21CF67DDCF784B31B4DF68CDC813E8 Size:14592
MD5: C8982B06E4569EBF8379F2D9FD422F0D Size:12032
MD5: 0B4ECC89A1B41B9CBDF92E6D8F327F04 Size:31488
%WINDIR%\180ax.exe
MD5: 97ADA022ECC47888012AFF0C5903FB58 Size:32000
MD5: 5A36BA3F5234B4423E95FEE5439C7495 Size:10752
MD5: 25C154CF0527B392B006E520164E278E Size:32256
MD5: BBA48A351A4E00CFBC3D5E196DC935B2 Size:23564
MD5: 07994B751EF25B117120FAC964F61131 Size:17664
MD5: 2861653B12909F9AC31C6C9D4F888D2A Size:311808
MD5: FE72CFAC730DB358706347061469D14C Size:12288
MD5: 5993D6C3D04327EF0098BEAAFA56A9EA Size:29952
MD5: 88D43DDD74F93A2E20EB9223D4EE05D7 Size:14848
%DOWNLOADEDPROGRAMFILES%\ClientAx.dll
MD5: FD138450DF07B1A46577AFA8040D3D84 Size:1224704
MD5: 45BBF4E6E708BCB1EB3AAE2C61D55C60 Size:602112
MD5: 427C89CD331FF7F51DA9A23F8A4BBA1C Size:385024
- Detected Files with variable Filenames:
MD5: E2E6B01D43C2555B1BE3F46D8297D409 Size: 700416
%SystemDiskRoot%\zolddrive\StubInstaller.exe
%SystemDiskRoot%\StubInstaller.exe
%DESKTOP%\back-up lordz\Installer\StubInstaller.exe
%SystemDiskRoot%\System Volume Information\_restore{FD51045B-EBB2-4C54-8E21-BC92991B3F58}\RP372\A0024506.exe
d:\StubInstaller.exe
d:\Bruno\refs\StubInstaller.exe
%SystemDiskRoot%\RECYCLER\S-1-5-21-1614895754-1644491937-725345543-1004\Dc5.exe
e:\StubInstaller.exe
g:\StubInstaller.exe
%SystemDiskRoot%\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP24\A0015430.exe
%SystemDiskRoot%\System Volume Information\_restore{499C0885-2D78-48B0-ADBE-865CCBB7C47F}\RP124\A0062962.exe
and next 293 variations.
MD5: BF8489EF5E9BDFC21FFD2B7DE5BB546C Size: 94208
%WINDIR%\wdwr.exe
%TEMP%\Del8.tmp
%WINDIR%\roxqh.exe
%WINDIR%\crulgfsr.exe
%TEMP%\DelE.tmp
%WINDIR%\xet.exe
%WINDIR%\sxadqt.exe
%WINDIR%\xgzwbab.exe
%TEMP%\Del2.tmp
%WINDIR%\cjifwb.exe
%WINDIR%\kncxwr.exe
and next 46 variations.
MD5: D80BB08696A289DA5B1AEEF05EB0F8A4 Size: 137728
%WINDIR%\ajgpwryf.exe
%SystemDiskRoot%\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1053\A0391331.exe
%WINDIR%\vyp.exe
%WINDIR%\cnap.exe
MD5: A89DDB6F2C69A9940C9E60EA88FE449A Size: 309760
%WINDIR%\180ax.exe
%PROGRAMFILES%\180search assistant\saap.exe
%PROGRAMFILES%\180Search Assistant\zanu.exe
MD5: 09DF16C6A2596378B0FDFC6A610DFFEB Size: 106496
%PROGRAMFILES%\180search assistant\saaphook.dll
%PROGRAMFILES%\180Search Assistant\saaphook.dll.ren
Detecting items list:
- Files by Name
%windir%\bohafwt.exe
%PROGRAMFILES%\180SearchAssistant\sain.exe
%PROGRAMFILES%\180Search Assistant\180sa.exe
%PROGRAMFILES%\180SearchAssistant\180sa.exe
%PROGRAMFILES%\180Search Assistant\180sahook.dll
%windir%\wbclargz.exe
%windir%\salm.exe
%windir%\salmbundle.exe
%windir%\salmhook.dll
%sysdir%\180.dll
%windir%\180ax*.exe
%PROGRAMFILES%\180Search Assistant\180sahook.dll
%PROGRAMFILES%\180SearchAssistant\sau.exe
%PROGRAMFILES%\180SearchAssistant\sac.exe
%PROGRAMFILES%\180SearchAssistant\salm.exe
%PROGRAMFILES%\180SearchAssistant\sau.dll
%PROGRAMFILES%\180SearchAssistant\salmhook.dll
%START_PROGRAMS%\180search Assistant\Uninstall 180search Assistant Instructions.lnk
%DOWNLOADEDPROGRAMFILES%\ClientAx.dll
%DOWNLOADEDPROGRAMFILES%\ClientAx.inf
%windir%\SJGLUX.EXE
%windir%\180.exe
- Files by MD5
MD5: BF8489EF5E9BDFC21FFD2B7DE5BB546C Size: 94208
- Files by Directories
%PROGRAMFILES%\180SearchAssistant
%PROGRAMFILES%\180Search Assistant
%START_PROGRAMS%\180search Assistant
- Files by CLSID or Name
CLSID=0AC49246-419B-4EE0-8917-8818DAAD6A4E
CLSID=B10031B2-F184-4803-9A88-D239C0641D70
CLSID=2B0ECEAC-F597-4858-A542-D966B49055B9
CLSID=7B178417-3CDA-444F-94FF-312C0A3A78A8
CLSID=A79F8202-E09D-4F0F-AD4D-DCAE1DAC5994
CLSID=DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD
CLSID=F1F1E775-1B21-454D-8D38-7C16519969E5
CLSID=5B6689B5-C2D4-4DC7-BFD1-24AC17E5FCDA
CLSID=68BF4626-D66B-4383-A6AF-62E57E9B6CD4
CLSID=F2BF4713-E933-4B66-8694-22ED243709C7
CLSID=e43dfaa6-8c16-4519-b022-8792408505a4
CLSID=bdddf1a5-51a9-4f51-b38d-4cd0ad831b31
CLSID=a16650a9-b065-40ec-bbd1-f8d370d17fb1
CLSID=f31a5d11-bf0b-4a4e-90af-274f2090aaa6
CLSID=7fa8976f-d00c-4e98-8729-a66569233fb5
CLSID=6c092742-10fe-4db2-988d-fc71948de70c
CLSID=51cf80dc-a309-4735-bb11-ef18bf4e3ad9
CLSID=8be3faba-7468-4851-b97c-0750af2b908e
- Registry Keys
HKLM\Software\sac
HKLM\Software\sau
HKLM\Software\sain
HKLM\Software\salm
HKLM\Software\180ax
HKCU\Software\sac
HKCU\Software\sau
HKCU\Software\sain
HKCU\Software\salm
HKCU\Software\180ax
HKCU\Software\180solutions
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\sac
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\180ax
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCASE
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\msbb
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\sain
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\salm
HKLM\software\classes\clientax.requiredcomponent.1
HKLM\software\classes\clientax.requiredcomponent
HKLM\software\classes\seekmohook.sabho
HKLM\software\classes\seekmohook.sabho.1
HKLM\software\classes\clientax.zangoclientax.1
HKLM\software\classes\clientax.zangoclientax
HKLM\software\classes\lmgr180.wmdrmax
HKLM\software\classes\lmgr180.wmdrmax.1
- Registry Values
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=sac
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=sac
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=sau
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=sain
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=salm
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=180ax
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=MSBB
«
Jít do Databáze softwaru