Deepdo Toolbar
|
Description:
|
Toolbar
|
|
Risk Level:
|
Low
|
|
Date of First Occurence:
|
Tuesday, May 13, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Toolbar/adware that creates pop-ups and advertisements on an infected computer.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
RIMUOVI SPYWARE »
Geographical Distribution of Threat "Deepdo Toolbar"
Threat Info
View All
Detected Items
- Detected Files:
%PROGRAMFILES%\Deepdo\DeepdoBar\Favorite\Update.exe
MD5: 9F565644C8CBD15F48D82555088AB6F4 Size:28672
%PROGRAMFILES%\Deepdo\DeepdoBar\Favorite\FavBlock.dll
MD5: D1C9415A650A9020CEBFA402F411E397 Size:86016
- Detected Files with variable Filenames:
Detecting items list:
- Files by Name
%PROGRAMFILES%\Deepdo\DeepdoBar\CenterDll.dll
%PROGRAMFILES%\Deepdo\DeepdoBar\CtrlCenter.exe
%PROGRAMFILES%\Deepdo\DeepdoBar\DeepdoBar.dll
%PROGRAMFILES%\Deepdo\DeepdoBar\Notes.dll
%PROGRAMFILES%\Deepdo\DeepdoBar\Uninstall.exe
%PROGRAMFILES%\Deepdo\DeepdoBar\Update.exe
%PROGRAMFILES%\Deepdo\DeepdoBar\Favorite\FavBlock.dll
%PROGRAMFILES%\Deepdo\DeepdoBar\Favorite\Favorite.dll
%START_PROGRAMS%\È ¾À\ Ø È ¾À.lnk
%START_PROGRAMS%\È ¾À\È ¾À.lnk
%DESKTOP%\È ¾À.lnk
- Files by Directories
%PROGRAMFILES%\Deepdo\DeepdoBar %START_PROGRAMS%\È ¾À
- Files by CLSID or Name
CLSID=00BE86F6-2E61-4c1e-A36B-AE233EE21FA1
CLSID=34AB74C4-DC63-40F6-AE0D-47496174CFF5
CLSID=76330A0D-617F-463A-97C1-16250DD664D9
CLSID=CD8BFE70-5809-4C73-9EEE-E5672C2B79D7
CLSID=F91E7727-37B1-45FB-8858-34B7D072F336
CLSID=FDF853FA-7837-435F-B17E-601ADFBCE20C
- Registry Keys
HKCR\Deepdo.DeepdoObj
HKCR\Deepdo.DeepdoObj.1
HKCR\FavBlock.FavHook
HKCR\FavBlock.FavHook.1
HKCR\FavBlock.MyExternal
HKCR\FavBlock.MyExternal.1
HKCR\ToolBand.Blocker
HKCR\ToolBand.Blocker.1
HKCR\ToolBand.Deepdo
HKCR\ToolBand.Deepdo.1
HKCU\Software\Deepdo\Toolbar
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CD8BFE70-5809-4C73-9EEE-E5672C2B79D7}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CCC40AF-207E-4D51-BB4D-1C67E04306C5}
- Registry Values
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser ValueName={00BE86F6-2E61-4C1E-A36B-AE233EE21FA1}
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar ValueName={00BE86F6-2E61-4c1e-A36B-AE233EE21FA1}
«
Go to Software Database