Pages: [1]
|
 |
|
Author
|
Topic: Adware.Ztoolbar (Read 1052 times)
|
|
TJ
|
Behavior Adware.Ztoolbar is an Internet Explorer search toolbar that may display advertisements.
Symptoms The files are detected as Adware.Ztoolbar.
Transmission
Adware.Ztoolbar is dropped by Trojan.Dropper together with Trojan.StartPage.J
technical details
When Adware.Ztoolbar is executed, it performs the following actions:
1. Creates the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar \{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} HKEY_LOCAL_MACHINE\SOFTWARE\ZSearchCo\ZSearch HKEY_CLASSES_ROOT\ZToolbar.StockBar HKEY_CLASSES_ROOT\ZToolbar.StockBar.1 HKEY_CLASSES_ROOT\CLSID\{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} HKEY_CLASSES_ROOT\ZToolbar.activator.1 HKEY_CLASSES_ROOT\ZToolbar.activator HKEY_CLASSES_ROOT\CLSID\{FFF5092F-7172-4018-827B-FA5868FB0478} HKEY_CLASSES_ROOT\ZToolbar.ParamWr.1 HKEY_CLASSES_ROOT\ZToolbar.ParamWr HKEY_CLASSES_ROOT\CLSID\{D7BF3304-138B-4DD5-86EE-491BB6A2286C} HKEY_CLASSES_ROOT\TypeLib\{84C94803-B5EC-4491-B2BE-7B113E013B77} HKEY_CLASSES_ROOT\Interface\{6DEEE498-08CC-43F0-BCA0-DBB5A25C9501} HKEY_CLASSES_ROOT\Interface\{DCFAB192-4A0E-4720-8E24-70D5F0CB8C39} HKEY_CLASSES_ROOT\Interface\{F4394F24-163D-430B-B5AF-B68B56031B99}
So that the Adware.Ztoolbar gets loaded as an Internet Explorer search toolbar.
2. All queries are sent to [http://]www.tnssearch.com/[REMOVED] when the search toolbar is used. Search results may contain advertisements.
To delete the value from the registry 1. Click Start > Run. 2. Type regedit
Then click OK. 3. Navigate to and delete the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar \{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} HKEY_LOCAL_MACHINE\SOFTWARE\ZSearchCo\ZSearch HKEY_CLASSES_ROOT\ZToolbar.StockBar HKEY_CLASSES_ROOT\ZToolbar.StockBar.1 HKEY_CLASSES_ROOT\CLSID\{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} HKEY_CLASSES_ROOT\ZToolbar.activator.1 HKEY_CLASSES_ROOT\ZToolbar.activator HKEY_CLASSES_ROOT\CLSID\{FFF5092F-7172-4018-827B-FA5868FB0478} HKEY_CLASSES_ROOT\ZToolbar.ParamWr.1 HKEY_CLASSES_ROOT\ZToolbar.ParamWr HKEY_CLASSES_ROOT\CLSID\{D7BF3304-138B-4DD5-86EE-491BB6A2286C} HKEY_CLASSES_ROOT\TypeLib\{84C94803-B5EC-4491-B2BE-7B113E013B77} HKEY_CLASSES_ROOT\Interface\{6DEEE498-08CC-43F0-BCA0-DBB5A25C9501} HKEY_CLASSES_ROOT\Interface\{DCFAB192-4A0E-4720-8E24-70D5F0CB8C39} HKEY_CLASSES_ROOT\Interface\{F4394F24-163D-430B-B5AF-B68B56031B99}
|
|
|
|
|
Logged
|
|
|
|
|
Pages: [1]
|
|
|
 |