NewtonKnows

Popis: Adware
Úroveň rizika: Vysoké
Datum 1. výskytu: Monday, April 21, 2008
Poskytovatel Softwaru: Virtumundo, Inc.
Stručné informace: NewtonKnows comprises a IE search-hijacker and toolbar, and a targeting pop-up system that works across many browsers.
Odstranění: Tento škodlivý software může být odstraněn pomocí "Spyware Terminatora"

ODSTRANIT SPYWARE »

Geogr. rozdělení softwaru "NewtonKnows"

Info o škodlivém softwaru

Zobrazit vše

Detected Items

  1. Detected Files: %SYSDIR%\jkhff.dll MD5: F05600E790FC15E5364A8DB53173418F Size:235008 MD5: 13E2544EAD020247FE4E63BB45780254 Size:90164 MD5: 9EF2862821346B503ECFD93DAA71955C Size:280576 MD5: 5EB696EE38621F563C0041917DC5F160 Size:323072 MD5: 2D189B7114F98E44DE08FB7D6629BDB2 Size:306752 MD5: EEC48F20CB1C73CCE49F4194F9ED1514 Size:325216 MD5: E3A3227334339169EC1B7FD1BF472FE6 Size:280064 MD5: FF5ED54BBC96444727BD19A60E063B30 Size:324672 %SYSDIR%\DDAYV.DLL MD5: 5B09D09C9EDA9F9255461AB952755757 Size:231520 MD5: 2DB7134DA997D1662D090CC74926BDC3 Size:320064 MD5: B4523BB9B6FC520C3723AB8E0797EDDD Size:38925 MD5: 9E2BBD4280CF24EB07C8EAEF6C7D8E66 Size:274432 %WINDIR%\explorertoolbar.dll MD5: AB1684F7A1F36CF641BC333EDD445045 Size:499712 %SYSDIR%\ddcyw.dll MD5: 875972D2C81400116C9CC3829FB4F8C8 Size:327264 MD5: A1EF6C2752C80974429B73D0F85ED174 Size:311904 MD5: B85E00F192D73986C2BFCECB5E141430 Size:278528 MD5: EF91E3E2ABBF1B4077CE2D62ABB0EDD7 Size:330816 MD5: 0A2413F7A1693BA0D69D214F756A56C7 Size:33300 MD5: 0C649A9F633622773100542B5AF1792D Size:314752 %SYSDIR%\geebb.dll MD5: 98C53AFCE8AF2C86D1DC967C6E39FCDA Size:180517 MD5: AA87B791052DBCB6BAE85B5CBC4D2485 Size:329312 MD5: D497C1959F58C3D5B3A06D80EE0FF889 Size:277044 MD5: 0ACA7A1E29FB0C0DD4D74D715EA742D9 Size:280576 MD5: 6111F0D38EB824E5E8D118F6FE4DCBDD Size:28173 MD5: 7061073DBE1176C7BE57CE32143B51C9 Size:244832 MD5: 67C0BA05E33220E5EC8876918382E0CA Size:6600 %SYSDIR%\ddcyy.dll MD5: 915643508AAAF0D5668EC038E643E8F2 Size:90164 MD5: C280975897C4F60026CF50FA1E81A612 Size:331360 MD5: 5178DF207F375C81F12ED93CA3AEDFC1 Size:301056 MD5: BBEC8D1A96CB7CD81CD7460B75AC76DC Size:324608 MD5: A288F19DB6306A78C0B7405E48B13F0F Size:268288 %SYSDIR%\AWTQO.DLL MD5: 2E949BC44ADCA97743E19C26E539C156 Size:278524 MD5: 2A4074C4B07F54EAD9E7971C5BDEE2BE Size:326752 MD5: 8CAE831CF196836D1AC38983DC2786D5 Size:281600 MD5: D8613DB8115867C3881FDC2D486557D3 Size:280064 MD5: B2CF91C3325E624081E3485812315A06 Size:155712 %SYSDIR%\awtqr.dll MD5: 8252092FB377E770BAFC3BDBB9AAFC5F Size:316000 MD5: BBB62788FC5208EAB55EFDCA3048FED0 Size:280064 MD5: 58EC65E1814D26E204FF76FAFC9DD09E Size:314832 MD5: B93537A599083DAE5C033F4B68AC49D9 Size:278016 MD5: A3B6E2E83A885BB1ADF03E1A0A3BFA33 Size:38413 MD5: D4E1C8863CB14DD4866691ED6908485A Size:280064 %SYSDIR%\awtqo.dll MD5: 4676BCC059CB02A95B08A02C997C1D65 Size:283232 MD5: 53F695773E1AB7534FAC55EE9CB4C85A Size:280576 MD5: E25A9431B1B488C79964624822DEDCBA Size:282624 MD5: 8D2A6F5876D8FEC344530C2CA10B2DB9 Size:278016 %SYSDIR%\awvtt.dll MD5: 42B3FAB83F1A2F477594305B8E55FA74 Size:316096 MD5: C55F0AC814AC7A710B36706585F375CD Size:344576 MD5: E769F4ADD0E4474F6030120E3585CC84 Size:278528 MD5: ECAF54795304C50A6DAA0405CC6D16BE Size:273408 %PROGRAMFILES%\newton knows\Toolbar\MyAdsManager\myadsmanager.dll MD5: 25C40EE81B376FEC6B2557FB3730FE61 Size:114688 %PROGRAMFILES%\newton knows\Toolbar\amberalerts\amberalerts.dll MD5: 51BE262671DEFBD971AE8D5B986326FA Size:126976 %PROGRAMFILES%\newton knows\Toolbar\MyNewsAlerts\mynewsalerts.dll MD5: FC111E4ABA17063AA17462E6DDB8058D Size:131072 %PROGRAMFILES%\newton knows\Toolbar\MyAuctionItems\myauctionitems.dll MD5: 0DAE5BCD55237D860E27D2D581954484 Size:274432 %PROGRAMFILES%\newton knows\setphlpr.exe MD5: 9128453E005C423D6A965414E358A8B8 Size:90112 %PROGRAMFILES%\newton knows\NewtInj.dll MD5: 7DD567C2751D2C6BC59AD44D6992DA97 Size:118784 %PROGRAMFILES%\newton knows\NewtonKn.dll MD5: 5AA97E64149CBE759DA207E17F970AD1 Size:229376 %PROGRAMFILES%\newton knows\NewtnUpd.dll MD5: 2D0202B47DF18B692FC02B3D99440FCA Size:385024 %PROGRAMFILES%\newton knows\NewtonKn.exe MD5: E9CD43933E5603301B2B9183F400ED54 Size:299008 %PROGRAMFILES%\newton knows\SpOrder.dll MD5: 97F50C3E6EEB45CBE2413431F1BB52FB Size:8464 %PROGRAMFILES%\Newton Knows\NewtnTra.exe MD5: 7812A4C5C2BC280C4C3E14000D4B591A Size:143360 %PROGRAMFILES%\NEWTON KNOWS\NEWTKNOW.EXE MD5: EB84A185FE9F91691E228E4FEC134C8A Size:110592 %PROGRAMFILES%\NEWTON KNOWS\NEWTNUPD.EXE MD5: 5A894E0F81D1A6693C0A92C518227351 Size:253952 %PROGRAMFILES%\newton knows\ntoolbar.dll MD5: E83A6808E0F8F50E0B18608046CF2155 Size:569344 %PROGRAMFILES%\Newton Knows\vMain.dll MD5: 05B9F488BCBD66C5118E01119E896429 Size:208896 %SystemDiskRoot%\Disco D\cpqapps\Administrador\Configuracin local\Temp\Install.exe MD5: 6DB3529F48401D659B8BEF4FF5D7B32D Size:32768 %SYSDIR%\ddayv.dll MD5: 3A85CE5997E4FAEC2489226E31EAD2B0 Size:323680
  2. Detected Files with variable Filenames: MD5: 0ADBA66921F6A5C6E642F4C17A2A1AF0 Size: 69632 %SYSDIR%\adwarepopupstopper.dll %SystemDiskRoot%\I386\adwarepopupstopper.dll %TEMP%\AdwarePopupStopper.dll %SystemDiskRoot%\Disco D\cpqapps\Administrador\Configuracin local\Temp\AdwarePopupStopper.dll MD5: 6111F0D38EB824E5E8D118F6FE4DCBDD Size: 28173 %SYSDIR%\geebb.dll %SYSDIR%\awvtt.dll MD5: 2D189B7114F98E44DE08FB7D6629BDB2 Size: 306752 %SYSDIR%\jkhff.dll %SYSDIR%\DDAYV.DLL

Detecting items list:

  1. Files by Name %programfiles%\newton knows\vmain.dll %sysdir%\inetadpt.dll %sysdir%\awtqr.dll %sysdir%\DDAYV.DLL %sysdir%\AWTQO.DLL %sysdir%\ddcyy.dll %sysdir%\awvtt.dll %sysdir%\ddcyw.dll %sysdir%\geebb.dll %sysdir%\jkhff.dll %SYSDIR%\adwarepopupstopper.dll
  2. Files by MD5 MD5: 6DB3529F48401D659B8BEF4FF5D7B32D Size: 32768
  3. Files by Directories %programfiles%\newton knows
  4. Files by CLSID or Name CLSID=E9407738-A996-421A-A309-5C93C699E10A CLSID=6600d22f-083f-11d6-99de-d172e92ebc2a CLSID=8ae10ee3-84be-4d3c-8106-7020bf3f0142 CLSID=ee392a64-f30b-47c8-a363-cda1cec7dc1b CLSID=6D33B121-5C4C-4450-9D1F-7B67085CC199 CLSID=C25FA7CE-23EA-4271-A66D-06C4D5C22F78 CLSID=FC148228-87E1-4D00-AC06-58DCAA52A4D1 CLSID=9B7AA30F-8FEF-4896-8DA0-D858AE072976
  5. Registry Keys HKLM\software\virtumundo\program\newton knows HKCU\software\virtumundo\program\newton knows HKLM\SOFTWARE\Classes\Bar.Event HKLM\SOFTWARE\Classes\Bar.Event.1 HKLM\SOFTWARE\Classes\Bar.WebBar HKLM\SOFTWARE\Classes\Bar.WebBar.1 HKCR\AdwarePopupStopper.Class1 HKCR\Bar.Event HKCR\Bar.Event.1 HKCR\Bar.WebBar HKCR\Bar.WebBar.1

« Jít do Databáze softwaru