FFinder

Description: Spyware
Risk Level: High
Date of First Occurence: Friday, May 09, 2008
Software Developer: (unknown)
Brief Info: FFinder redirects search queries to a predetermined Web site. It also downloads other adware programs.
Removal: This threat can be removed using "Spyware Terminator"

REMOVER SPYWARE »

Geographical Distribution of Threat "FFinder"

Threat Info

View All

Detected Items

  1. Detected Files: %SYSDIR%\preuninstallql.exe MD5: 330EF3779E72AFD686A7B9BE3E36FD16 Size:49152 MD5: 1BA2BF9406B0223BDD73A305004275CE Size:24576 %SYSDIR%\preuninstallcom.exe MD5: 782F6CAFD593993498198BE4D183FB4D Size:49152 MD5: FA863479B942F7E1348FFFCD11E2A9FB Size:49152 %SYSDIR%\stb.exe MD5: F9D67C581E8FEA4FC637EAFF2461C7B9 Size:40960 %SYSDIR%\communicator.dll MD5: C05EA773CD94B7983620908EA0588090 Size:1263616 MD5: 442B8A15ABC263CEDE7FAF989E0644D7 Size:1263616 MD5: C2DAC61BD548B7B877DC905BAD074D45 Size:49152 %SYSDIR%\qlink32.dll MD5: 456BAE829F5978ADFE60D67BE096079F Size:200704 MD5: 758E360BB1B44BE940FBE70F9C88635B Size:200704 MD5: 1C6395A9BCE1E9D98F382B8E52A8F084 Size:200704 %PROGRAMFILES%\QL\qlink32.dll MD5: A40A3251CC1BD04EF15790100B9C043F Size:200704
  2. Detected Files with variable Filenames: MD5: CDFE76889203C70DA5583030338BD4A8 Size: 11776 %PROGRAMFILES%\quick links\uninst.exe %PROGRAMFILES%\related sites toolbar\uninst.exe

Detecting items list:

  1. Files by Name %ProgramFiles%\QL\qlink32.dll %Sysdir%\stb.exe %Sysdir%\qlink32.dll %Sysdir%\qldf.bin %Sysdir%\preuninstallql.exe %Sysdir%\preuninstallcom.exe %Sysdir%\communicator.dll %programfiles%\related sites toolbar\uninst.log %programfiles%\related sites toolbar\uninst.exe %programfiles%\quick links\uninst.log %programfiles%\quick links\uninst.exe
  2. Files by Directories %programfiles%\communicator toolbar
  3. Files by CLSID or Name CLSID=8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22 CLSID=EA420048-2898-4110-88C3-1F660B0C7FF3 CLSID=4162D910-6167-42E7-91AE-6A522C4121D2 CLSID=DFAA31C8-A356-4313-9D95-5EDAB46C5070 CLSID=4E7BD74F-2B8D-469E-8DBC-A42EB79CB429 CLSID=4E7BD74F-2B8D-469E-8DBC-A42EB79CB428

« Go to Software Database