Home Malware Programs Browser Hijackers CoolWebSearch.xpsystem

CoolWebSearch.xpsystem

Posted: March 28, 2006

A variant of CoolWebSearch that sends your searches to the sites search.thestex.com, t.rack.cc or awebfind.biz.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 SERVICES.EXE
    2 Y.EXE

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunDeletethevaluexpsystemHKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}5321E378-FFAD-4999-8C62-03CA8155F0B3
Loading...