Trust Toolbar
|
Description:
|
Toolbar
|
|
Risk Level:
|
Medium
|
|
Date of First Occurence:
|
Tuesday, June 03, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Toolbar/adware that creates pop-ups and advertisements on an infected computer.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
ENTFERNEN SPYWARE »
Geographical Distribution of Threat "Trust Toolbar"
Threat Info
View All
Detected Items
- Detected Files:
%SYSDIR%\TTBSETUP.EXE
MD5: A66ED0B96C069C7A383354BBF0AD8591 Size:2396287
%SYSDIR%\TTBBHO.DLL
MD5: DADCCEA62A349AAD374FB75CEE74A76D Size:1130632
%SYSDIR%\SRHOOK.dll
MD5: 378A86DF52212863FB95DE29E3AB6976 Size:36864
%SYSDIR%\TTBSREB.DLL
MD5: E9F7AE0B2565E06CA224BD3857F9FE6B Size:290816
%SYSDIR%\wvo_util.dll
MD5: 13E3A6D01731B5C396E80FA9100003DE Size:69765
%SYSDIR%\WVO_CTRL.EXE
MD5: 0D17A36EC8C93ACFAFA2CDC67E399326 Size:36864
%SystemDiskRoot%\Hadayat-Apps\stealthisbookCD\Chapter 13 - The Internet Con Artists\TrustToolbar.exe
MD5: 396306F48B4D7EE0A50DE001E321027D Size:875064
- Detected Files with variable Filenames:
Detecting items list:
- Files by Name
%sysdir%\SRHOOK.dll
%sysdir%\TTBBHO.DLL
%sysdir%\TTBSETUP.EXE
%sysdir%\TTBSREB.DLL
%sysdir%\WVO_CTRL.EXE
%sysdir%\WVO_UTIL.DLL
- Files by MD5
MD5: 396306F48B4D7EE0A50DE001E321027D Size: 875064
MD5: DADCCEA62A349AAD374FB75CEE74A76D Size: 1130632
MD5: A66ED0B96C069C7A383354BBF0AD8591 Size: 2396287
MD5: E9F7AE0B2565E06CA224BD3857F9FE6B Size: 290816
- Files by Directories
%START_PROGRAMSALL%\TrustToolbar
%START_PROGRAMS%\TrustToolbar
- Files by CLSID or Name
CLSID=21C066EB-1E61-4ab1-98AE-FC102F30B5C7
CLSID=2C2C1BED-5B1C-4bf2-BC2A-86BF224B01AB
CLSID=4C1F4CE1-57BF-4DFD-BAFF-58B825254E6B
CLSID=BD49A497-F9CB-4c47-8606-AC420EFB68C3
CLSID=D80E1356-AC78-4218-961C-A7689B4CB7FE
- Registry Keys
HKCR\.wvo
HKCR\SearchHook.SrchHook
HKCR\SearchHook.SrchHook.1
HKCR\SearchHook.URLSearchHook
HKCR\SearchHook.URLSearchHook.1
HKCR\TrustToolbar
HKCR\TTBBHO.TrustToolbaBho
HKCR\TTBBHO.TrustToolbaBho.1
HKCR\WebVisibleObject
«
Go to Software Database