KoolBar
|
Description:
|
Adware
|
|
Risk Level:
|
Low
|
|
Date of First Occurence:
|
Monday, April 21, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Adware
Software that is displaying pop-up/pop-under windows containing advertisements when the primary user interface is not visible or displayed advertisements are not related to the product.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
REMOVER SPYWARE »
Geographical Distribution of Threat "KoolBar"
Threat Info
View All
Detected Items
- Detected Files:
%SYSDIR%\nsq49.dll
MD5: 2E4B11ACABB95BC64E859A829863F157 Size:554496
%SYSDIR%\nsr37.dll
MD5: 8C209F661C8886D5528D4E6D8BD794DD Size:350208
%SYSDIR%\nsu3B.dll
MD5: 879C7900099D041AC47B258F8C32A98A Size:233472
- Detected Files with variable Filenames:
Detecting items list:
- Files by Name
%SYSDIR%\nsr37.dll
%SYSDIR%\nsu3B.dll
%SYSDIR%\nsq49.dll
- Files by CLSID or Name
CLSID=9ADE0443-2AB2-4B23-A3F8-AC520773DE12
CLSID=BC54B24C-5A97-4C19-9181-8B8A05B2E931
CLSID=BD9584EF-C28C-4F6D-8D49-0CEE3C0E442F
CLSID=C7888681-1A83-4C14-B9A5-95F91240B44F
- Registry Keys
HKCR\btnetw.amo
HKCR\btnetw.amo.1
HKCR\btnetw.iiittt
HKCR\btnetw.iiittt.1
HKCR\btnetw.momo
HKCR\btnetw.momo.1
HKCR\btnetw.ohb
HKCR\btnetw.ohb.1
HKCU\Software\nsq49.dll
HKCU\Software\nsr37.dll
HKCU\Software\nsu3B.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12}
«
Go to Software Database