WhenU.SearchToolbar

Popis: Adware
Úroveň rizika: Vysoké
Datum 1. výskytu: Monday, April 14, 2008
Poskytovatel Softwaru: WhenU.com, Inc.
Stručné informace: WhenU/SearchToolbar is a desktop toolbar that monitors internet traffic and collects search profiles.
Odstranění: Tento škodlivý software může být odstraněn pomocí "Spyware Terminatora"

ODSTRANIT SPYWARE »

Geogr. rozdělení softwaru "WhenU.SearchToolbar"

Info o škodlivém softwaru

Zobrazit vše

Detected Items

  1. Detected Files: %PROGRAMFILES%\WhenUSearch\Uninst.exe MD5: 796C71AD81700F397F9DC37472F472B8 Size:53896 MD5: D7D7485745D1788A11CD9F2B63B91CB5 Size:57992 MD5: 763F4F33875438BEF187B31213A7BEC0 Size:53896 MD5: 4B4A127FB77D442DC3E03CCFEBD44AC9 Size:38975 %PROGRAMFILES%\WhenUSearch\search.dll MD5: 3B1B325628A62EC8C1EAEBED602AEAF8 Size:242760 MD5: 9484DA07BF174F0F72D91609C7754942 Size:234568 MD5: 7669C1FC40DE6B5928F1EBB0CA1CEAD8 Size:243264 MD5: 793F6D330DE983ECF51630626B73A960 Size:199168 %PROGRAMFILES%\WhenUSearch\searchupdate.exe MD5: 61279ADB337F5A5BC9861FDB4C8D14A7 Size:688200 %PROGRAMFILES%\WhenUSearch\whse.exe MD5: 246B77406B6DF0F10B12AF1445D72618 Size:173128 MD5: FD39DA1CE7EED37DC271122986331B25 Size:177736 %PROGRAMFILES%\WhenUSearch\Search.exe MD5: 06C71B7AB449039C4AD8F246A1BD54A3 Size:301128 MD5: 5E1F64993F096CE273977A181CAFD72F Size:350856 MD5: 38360E41E2EF11C4C5061FA1BAEDF484 Size:301128
  2. Detected Files with variable Filenames:

Detecting items list:

  1. Files by Name %PROGRAMFILES%\WhenUSearchB\Searchdt.exe %PROGRAMFILES%\WhenUSearch\whse.exe %ProgramFiles%\WhenUSearch\search.exe %ProgramFiles%\WhenUSearch\uninst.exe
  2. Files by MD5 MD5: 83262945DCE64C0BA54D304CDA2BE0B4 Size: 126520
  3. Files by Directories %START_PROGRAMS%\WhenUSearch %START_PROGRAMSALL%\WhenUSearch %PROGRAMFILES%\WhenUSearch
  4. Files by CLSID or Name CLSID=45E5DADB-DFDF-4FC3-A46C-DD34B6CDDB38 CLSID=763BD795-24AE-44D7-82D8-F9A1EE799729 CLSID=BA2325ED-F9EB-4830-8FCE-0BC35B16969B
  5. Registry Keys HKLM\SOFTWARE\whenusearch HKCU\SOFTWARE\whenusearch
  6. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=WhenUSearchB HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=WhenUSearch

« Jít do Databáze softwaru