180searchAssistant
|
Description:
|
Adware
|
|
Risk Level:
|
High
|
|
Date of First Occurence:
|
Monday, April 14, 2008
|
|
Software Developer:
|
180solutions, Inc.
|
|
Brief Info:
|
180searchAssistant is an adware program that monitors the contents of Web browser windows.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
SCAN & REMOVE NOW »
Geographical Distribution of Threat "180searchAssistant"
Threat Info
View All
Detected Items
- Detected Files:
%WINDIR%\180ax.exe
MD5: DDE19D5FAE845C0D6A8E3202607598EB Size:8960
MD5: D028B99AB8842815B5F5BF890FCC4288 Size:22016
MD5: A89DDB6F2C69A9940C9E60EA88FE449A Size:309760
MD5: 02857FE84871867021C156B4C56001B6 Size:27904
MD5: 97ADA022ECC47888012AFF0C5903FB58 Size:32000
MD5: E9CE0428C9AB17F45CEB09C36B68DA65 Size:14848
MD5: 5A36BA3F5234B4423E95FEE5439C7495 Size:10752
MD5: C55522505CA81291211E42F0CDC5EBE2 Size:32768
MD5: 25C154CF0527B392B006E520164E278E Size:32256
MD5: BBA48A351A4E00CFBC3D5E196DC935B2 Size:23564
MD5: 07994B751EF25B117120FAC964F61131 Size:17664
MD5: 2861653B12909F9AC31C6C9D4F888D2A Size:311808
and more....
%WINDIR%\salm.exe
MD5: EBB0A7A65A790955BC459D69A3AC8C9A Size:18176
MD5: 43E06F273BDA5280369B09826453B19B Size:9728
MD5: 0C21CF67DDCF784B31B4DF68CDC813E8 Size:14592
MD5: 30B4F1406E0ACB672684E7294EC4549D Size:11520
MD5: 3EEC8D2496F5983988C59815BA18D171 Size:18688
MD5: C8982B06E4569EBF8379F2D9FD422F0D Size:12032
MD5: 0B4ECC89A1B41B9CBDF92E6D8F327F04 Size:31488
MD5: CBB8316D79A6F67EC6F4FB6CDC2A839D Size:29440
MD5: 3381F7284B869AC23CE1A66BBFF59047 Size:22016
MD5: B9ABA147FD75978F710A4BB6C9F4A17B Size:32512
MD5: 48B6A6310A3825AA572A86D15799CB8B Size:19200
MD5: D7729356A830A30C5338A19699669DDE Size:27904
and more....
%PROGRAMFILES%\180Search Assistant\sau.exe
MD5: 3B35E01BBA184D685BA1EAAD6AADE40B Size:29440
MD5: B610270536EC27B3BD1A1972E846C559 Size:8192
MD5: 05570A624999BC78374A13CB6A157759 Size:13056
MD5: A71FA3B1794647CF1D5C6EA236A23199 Size:23296
MD5: A32BA1B4CA411360DDA0837DFA2E02DE Size:26880
MD5: 7C48847A27D9D71F7CA96263F48534B0 Size:27392
MD5: F69AB9C8EF7B1320AF483E23B8335BE4 Size:26624
MD5: B975F571AB224261B557A17FCC0A4C59 Size:15360
MD5: 9C4171D9DA98088966D12BDB1E8BA22F Size:9472
MD5: FF86FC0EDE3301E67D55A611715B8005 Size:18688
MD5: 80EA959A0D74AFF36E34FE8EC7294E0C Size:91204
MD5: 0F7DB9157C16B965F881C3670D121FDE Size:28160
and more....
%PROGRAMFILES%\180Search Assistant\180sa.exe
MD5: 13AC2EEB32496D97F781BEC83B4D1EDF Size:20736
MD5: B58454A76E672C4BEEF255B1C145C44E Size:18176
MD5: 682F88A3B1E8834D9928B3EC814D0BA7 Size:29440
MD5: 0067B4DA2C6A11E866628491DAD2DB14 Size:25856
MD5: E41F7C94D075033DE205093FAA8007A4 Size:23552
MD5: C2D8D9C5777828EF0CAEEB7063F64D73 Size:22016
MD5: 4A21C01B167DFAC0FC7127B3F7285EDD Size:20480
MD5: 81BEFDAE8FA5BD69B58CC9B2E85781C1 Size:21504
MD5: 7A72C6D31D4455FEE75DEF75C95A6900 Size:8960
MD5: DE85907619B4029C51ED08C7DFBE9858 Size:22016
MD5: 24176A7809E64FC0426CFD1E54879EB8 Size:9216
MD5: B1F7AEAD983BBFF3FA0C49C33FBD747B Size:15872
and more....
%DOWNLOADEDPROGRAMFILES%\ClientAX.dll
MD5: 08ABDDD6EC7A4688AE72D5D1049980ED Size:1173616
MD5: A945C0696238D948676CA1EB4A42BC75 Size:602112
MD5: A549932817B636E601832441C663AEB5 Size:1224704
MD5: 76F715947580CE53767E94CD4A1FEB67 Size:602112
MD5: ABB10E08A2AD7EEF762421A58A4DAA72 Size:1230960
MD5: EC9255F0D410ABB72031164C0BBBF5AA Size:1296496
MD5: AFD717EF2EE5D9B0D366F7A256A86893 Size:1290240
MD5: 3272AD324A1600B561B33EE3AB44660C Size:577536
MD5: 754AEB4CEF837687B9B1F5B010E86784 Size:999424
MD5: A611605551A1880BC786A4BC2524878C Size:385024
MD5: F8DD33CE128C1659FC7E8455A206DBBD Size:1224704
MD5: D6F6B2489DDA30E4D4082D94CBD473A6 Size:999424
and more....
%DOWNLOADEDPROGRAMFILES%\ClientAx.dll
MD5: 3983C2B73930E198C2F9DF1C38BA617F Size:1220608
MD5: 8C518E5E92A736918C980A327F186DE3 Size:1226864
MD5: 38B995929A50EB7BEF84A708D952FB7C Size:1226864
MD5: FD138450DF07B1A46577AFA8040D3D84 Size:1224704
MD5: F7E4F4261246F2D55E5FC0986C689F9F Size:1048576
MD5: 461E7FCD5628FB61848B1C85700400B4 Size:1216512
MD5: 45BBF4E6E708BCB1EB3AAE2C61D55C60 Size:602112
MD5: 427C89CD331FF7F51DA9A23F8A4BBA1C Size:385024
MD5: A516B0154EC495EEA369A46B361051A7 Size:577536
MD5: 2E41D941773381C00407FCA28AB287E9 Size:1118208
MD5: 7270FB07EE114C4A178400DC6E93D1AB Size:1220608
MD5: 2B0D5ACD137730A73F970CB1037F0FCF Size:417792
and more....
%WINDIR%\salmbundle.exe
MD5: 8FC2CB8604A22207653BD0CB6AEBDA82 Size:177448
MD5: 2387A870475CDC45CA09CDCBBB52022D Size:12873
%PROGRAMFILES%\180search assistant\180sahook.dll
MD5: 183E3601A7CCF8E29F5CB5D623F14CC4 Size:118784
%WINDIR%\180ax.exe
MD5: FE72CFAC730DB358706347061469D14C Size:12288
MD5: 5993D6C3D04327EF0098BEAAFA56A9EA Size:29952
MD5: 88D43DDD74F93A2E20EB9223D4EE05D7 Size:14848
MD5: 17ADA9FBAF3A0B7A822E5D8DD98F56C5 Size:22528
MD5: 660D6A4B7CB24502EE0C32F229C92325 Size:10240
MD5: 443D0671B42103EE209905383FCFA49D Size:282624
MD5: D8F8AA9E595F53FEA07AD501A614E130 Size:20992
MD5: 069D172660B5379C0D1996455A1873FD Size:30208
MD5: B59AF8A9F37EF44492A1664DFFE768EA Size:30720
MD5: 464C5F5758183F0FF0018F74CC6CEF1F Size:23296
MD5: D186F16A216135E8C63DBDCDDD577090 Size:12032
MD5: 01F6F60016D400548F54C210238E0B3E Size:9216
and more....
%DOWNLOADEDPROGRAMFILES%\ClientAX.dll
MD5: 2172C8A9E17F029A199B1E550A6EBD88 Size:487424
MD5: 0E5C0AB94AB92D0537976E05D3330005 Size:602112
MD5: BF9CC51D7C7FA17C2B3EE74C43670132 Size:618496
MD5: 35F00DFF35DCEC2037735053A2FE6E23 Size:602112
MD5: 2376D3D00784C7B5E581AA6B23790069 Size:1173616
%WINDIR%\180ax.exe
MD5: 845E46AE37105D6397489D9CF899B1DF Size:18432
MD5: E7D195CAB75F21FCFA54AECF7815A5B4 Size:23296
MD5: C039A871877DF9C3822D9D1D86568E75 Size:15360
MD5: 1B1B3CD2A174C6802A22C0EE52241018 Size:11264
MD5: 86CBF34DA8CA9F9DEFB6F4AE929E90A6 Size:28672
MD5: 9D21906DCDD8445BD49DE9D68D63FE32 Size:14336
MD5: 4A1BBA2573EE06C141A9D0B5FA8976B4 Size:28160
MD5: B87A1C1CEA2DA961A51F21F1CB329CE3 Size:24320
MD5: 505E00B989088C2FA9939117A743C1A0 Size:26112
MD5: EB701E4E0571B53DA47804C593E84A45 Size:20736
MD5: D030988887190922C8C59DF546212F55 Size:25344
MD5: 12E6851E86E725B12035EE2101038611 Size:24576
and more....
%WINDIR%\salm.exe
MD5: 99FAF36BA1D852AD205AE5AC90D2DA70 Size:18432
MD5: 20B86BE6EF3D7C9CE375F487492756BC Size:23296
MD5: BD28AD8224AE3F5844DFC0D21DA55140 Size:17664
MD5: A431377531E7348CE17F65B1824D497E Size:14336
MD5: EC7F7C42ECBEB90B63B0D2549A298975 Size:12544
MD5: 82BDEF93FC6A3875BEF4AC1EEB096122 Size:16640
MD5: 94328B62E708484B160CCD33457B0445 Size:22784
MD5: E7FD90AD51D990E8ABEDD9A4415F2A82 Size:19968
MD5: 3909FBD1696E2FE1B79F82A049FC2F4C Size:23296
MD5: 33514228EA75C69E0A788F93F51969D3 Size:27136
MD5: EA5B8C0B6AA7E822D0B318FFD4D13AC7 Size:16384
MD5: C79698A440A957CEB68DC334C66599A1 Size:22272
and more....
%PROGRAMFILES%\180Search Assistant\sau.exe
MD5: B964659A7EB6E6D28F26E7EACCAD3074 Size:18688
MD5: 913CD90736A599251FAF635BB5D4FF5B Size:9728
MD5: 330282A7A70DEB75714E252884981DFD Size:11776
MD5: 4D2BA2E71778CEFA2F1578E3391F5F84 Size:27136
MD5: CCE39D9F1EE0E0C6D152A041151847B0 Size:31232
MD5: E1E8C630945D8CFC21FFDBABCBE7AC0C Size:9216
MD5: 662B3D0FFF214D218F2DE7FA1389F9F4 Size:19456
MD5: 02276F3878BC9A9C863F645D4D8F452C Size:32256
MD5: D8F82B3387D0AE7BF6DFE235880CF09A Size:11776
MD5: 23220246F635B87BCB8B406E53FD817F Size:14848
MD5: 791FBB65036C68119BF2D43AA10A85A6 Size:9472
%PROGRAMFILES%\180Search Assistant\180sa.exe
MD5: F7715B225546B38632BA7E29F7D40F58 Size:11008
MD5: EB25E6DE9C4BE5A0A523C661DF0FD8C9 Size:9984
MD5: B8E2C22C414DA8FD5381D3F52C2445C5 Size:26112
MD5: A78B2CDEE81E0CD153D730DC1E594E53 Size:25600
MD5: 48E2AA661CD5D21C8CDBE29994EE3740 Size:24832
MD5: 78A09424F13AB11E2DEDF84FD0F1FB5C Size:19968
MD5: 78D68632DA3CA17C5D8C03496C7B019C Size:29184
MD5: DCB6BD21F059AFD5E9AEA3662CF6FC56 Size:17152
MD5: 0395247E9A34D450AB9F3D59F747091C Size:8704
MD5: BB411D43AF7DEA53B744EF18909928E3 Size:26112
MD5: 185BE6EDCDAEFE9E5F828B8F29E7619C Size:29184
%DOWNLOADEDPROGRAMFILES%\ClientAx.dll
MD5: 356CA895E975E01BF08CF28B84C35E19 Size:385024
MD5: B4FEFE56C29328A0C9F0432BD921F655 Size:430080
MD5: 006C77D25308BE2EB435C574B749BB83 Size:1173616
MD5: 15D17EA6AD18EE9E8A97DD53D0AA23A2 Size:1230960
MD5: D1689FEDA3ACD6303A38FE0587FDD5FF Size:1222768
MD5: EF7AAFB0A300066AFCEE8EFCED5EB6C7 Size:1222768
%WINDIR%\180ax.exe
MD5: 4DBD02B080EEEECE2579B852E8B4C7DE Size:18176
MD5: B29B9966B6910A0C7A0996A3FD5A09B2 Size:32000
MD5: 20AD8C1B60D1D8213FF6C3E3CFAA078C Size:19968
MD5: 1BD5FEAAE6249DD1CDA73EBEBD3CCD8E Size:23552
MD5: D0624A07A057760DD4043DB397BF7DE5 Size:15360
MD5: B6178E89A4D3CDFE040B9B6E2191F7A4 Size:17408
MD5: F4C30C32A4FBA9630359535146755EBC Size:27392
MD5: 1A9359FF34C8B85FE4D9F7C21A19EE00 Size:27648
MD5: E1CFDE814D5F97C47232B87F5BCD8A89 Size:27392
MD5: 45AA6067544B7A73A384450F6DEB40F0 Size:12544
MD5: 993552DFAA6285C76CDF3A73CE3584C8 Size:27648
MD5: 9C06A28A498E91B928C84027FC019446 Size:30464
and more....
%WINDIR%\salm.exe
MD5: A32C27882835D9D76E561D085DC18737 Size:17408
MD5: 55E9F17813CCF11ABBD13D76617862D8 Size:11264
MD5: 93043278F9A26D6DC394B902D81BFEB9 Size:22016
MD5: EFE717148F25B9A91D423E3321CB4D18 Size:31488
MD5: 9872CF3350611A4361DC656AC8545450 Size:25600
MD5: D2026CF6656CA61491E06790088B91B1 Size:20736
MD5: 81E2DFAE6207DCB923D2B531E35862CF Size:32256
MD5: 3E4B751069FB36179E1F04783E26C892 Size:11520
MD5: 0CAF1823053CDC2AE0AD91EF478933C9 Size:12288
%TEMP%\SeekmoInstaller.exe
MD5: 182A1BB5EC8AB6D4D587B8654E018269 Size:710768
%WINDIR%\180ax.exe
MD5: 4C2E3FB76C2CA01F74F7FCF4DBD91492 Size:27904
MD5: 6FDA5117205660E3AF2956B0570051CD Size:27904
MD5: 8E7B81853FE620C52FB68A7608170E9A Size:29696
MD5: D0B69EE6EE18684084B225D793505761 Size:25088
- Detected Files with variable Filenames:
MD5: E2E6B01D43C2555B1BE3F46D8297D409 Size: 700416
%SystemDiskRoot%\StubInstaller.exe
e:\StubInstaller.exe
%USERDOCUMENTS%\Software\StubInstaller.exe
%PROGRAMFILES%\LimeWire\StubInstaller.exe
%DESKTOP%\Sauv Steph\StubInstaller.exe
d:\StubInstaller.exe
%SystemDiskRoot%\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP48\A0046260.exe
G:\StubInstaller.exe
%SystemDiskRoot%\RECYCLER\S-1-5-21-2660825490-542047655-3551873755-1012\Dc30.exe
l:\StubInstaller.exe
%SystemDiskRoot%\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP1496\A0053442.exe
and next 332 variations.
MD5: BF8489EF5E9BDFC21FFD2B7DE5BB546C Size: 94208
%WINDIR%\wjglmj.exe
%WINDIR%\wdwr.exe
%TEMP%\Del27.tmp
%WINDIR%\jczar.exe
%WINDIR%\roxqh.exe
%TEMP%\Del41.tmp
%TEMP%\DelE.tmp
%WINDIR%\bixud.exe
%WINDIR%\duxglez.exe
%WINDIR%\yryd.exe
%WINDIR%\sxadqt.exe
and next 71 variations.
MD5: A89DDB6F2C69A9940C9E60EA88FE449A Size: 309760
%WINDIR%\180ax.exe
%PROGRAMFILES%\180search assistant\saap.exe
MD5: 1C1119EDA85669B743F7AD53F794643A Size: 621056
%PROGRAMFILES%\180search assistant\180sa.exe
%PROGRAMFILES%\180Search Assistant\bak\180sa.exe
MD5: 09DF16C6A2596378B0FDFC6A610DFFEB Size: 106496
%PROGRAMFILES%\180search assistant\saaphook.dll
%PROGRAMFILES%\180Search Assistant\saaphook.dll.ren
MD5: D80BB08696A289DA5B1AEEF05EB0F8A4 Size: 137728
%WINDIR%\vyp.exe
%WINDIR%\cnap.exe
%WINDIR%\ajcxwr.exe
%TEMP%\Del24C.tmp
MD5: E0E0F44AD296D5A28943D79156ED2017 Size: 412160
%PROGRAMFILES%\180SearchAssistant\sais.exe
%PROGRAMFILES%\180searchassistant\salm.exe
Detecting items list:
- Files by Name
%windir%\bohafwt.exe
%PROGRAMFILES%\180SearchAssistant\sain.exe
%PROGRAMFILES%\180Search Assistant\180sa.exe
%PROGRAMFILES%\180SearchAssistant\180sa.exe
%PROGRAMFILES%\180Search Assistant\180sahook.dll
%windir%\wbclargz.exe
%windir%\salm.exe
%windir%\salmbundle.exe
%windir%\salmhook.dll
%sysdir%\180.dll
%windir%\180ax*.exe
%PROGRAMFILES%\180Search Assistant\180sahook.dll
%PROGRAMFILES%\180SearchAssistant\sau.exe
%PROGRAMFILES%\180SearchAssistant\sac.exe
%PROGRAMFILES%\180SearchAssistant\salm.exe
%PROGRAMFILES%\180SearchAssistant\sau.dll
%PROGRAMFILES%\180SearchAssistant\salmhook.dll
%START_PROGRAMS%\180search Assistant\Uninstall 180search Assistant Instructions.lnk
%DOWNLOADEDPROGRAMFILES%\ClientAx.dll
%DOWNLOADEDPROGRAMFILES%\ClientAx.inf
%windir%\SJGLUX.EXE
%windir%\180.exe
- Files by MD5
MD5: BF8489EF5E9BDFC21FFD2B7DE5BB546C Size: 94208
MD5: D80BB08696A289DA5B1AEEF05EB0F8A4 Size: 137728
MD5: 1C8E6F022BE91A20466A411DAE77E695 Size: 581807
MD5: BFF063E564DA92554333608A0782DDF9 Size: 206823
MD5: E2E6B01D43C2555B1BE3F46D8297D409 Size: 700416
MD5: 182A1BB5EC8AB6D4D587B8654E018269 Size: 710768
- Files by Directories
%PROGRAMFILES%\180SearchAssistant
%PROGRAMFILES%\180Search Assistant
%START_PROGRAMS%\180search Assistant
- Files by CLSID or Name
CLSID=0AC49246-419B-4EE0-8917-8818DAAD6A4E
CLSID=B10031B2-F184-4803-9A88-D239C0641D70
CLSID=2B0ECEAC-F597-4858-A542-D966B49055B9
CLSID=7B178417-3CDA-444F-94FF-312C0A3A78A8
CLSID=A79F8202-E09D-4F0F-AD4D-DCAE1DAC5994
CLSID=DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD
CLSID=F1F1E775-1B21-454D-8D38-7C16519969E5
CLSID=5B6689B5-C2D4-4DC7-BFD1-24AC17E5FCDA
CLSID=68BF4626-D66B-4383-A6AF-62E57E9B6CD4
CLSID=F2BF4713-E933-4B66-8694-22ED243709C7
CLSID=e43dfaa6-8c16-4519-b022-8792408505a4
CLSID=bdddf1a5-51a9-4f51-b38d-4cd0ad831b31
CLSID=a16650a9-b065-40ec-bbd1-f8d370d17fb1
CLSID=f31a5d11-bf0b-4a4e-90af-274f2090aaa6
CLSID=7fa8976f-d00c-4e98-8729-a66569233fb5
CLSID=6c092742-10fe-4db2-988d-fc71948de70c
CLSID=51cf80dc-a309-4735-bb11-ef18bf4e3ad9
CLSID=8be3faba-7468-4851-b97c-0750af2b908e
- Registry Keys
HKLM\Software\sac
HKLM\Software\sau
HKLM\Software\sain
HKLM\Software\salm
HKLM\Software\180ax
HKCU\Software\sac
HKCU\Software\sau
HKCU\Software\sain
HKCU\Software\salm
HKCU\Software\180ax
HKCU\Software\180solutions
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\sac
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\180ax
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\nCASE
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\msbb
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\sain
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\salm
HKLM\software\classes\clientax.requiredcomponent.1
HKLM\software\classes\clientax.requiredcomponent
HKLM\software\classes\seekmohook.sabho
HKLM\software\classes\seekmohook.sabho.1
HKLM\software\classes\clientax.zangoclientax.1
HKLM\software\classes\clientax.zangoclientax
HKLM\software\classes\lmgr180.wmdrmax
HKLM\software\classes\lmgr180.wmdrmax.1
- Registry Values
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=sac
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=sac
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=sau
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=sain
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=salm
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=180ax
HKLM\Software\Microsoft\Windows\CurrentVersion\Run ValueName=MSBB
«
Go to Software Database