Home Malware Programs Browser Hijackers UniversalTB

UniversalTB

Posted: March 28, 2006

UniversalTB is an additional Internet Explorer toolbar with browser hijacker functionality. It changes the web browser's default start and search pages to sites on simplenter.com domain. UniversalTB doesn't spread and must be manually installed. It starts every time the user opens Internet Explorer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 utility.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerURLSearchHooksHKEY_CURRENT_USERSoftwareUniversalHKEY_LOCAL_MACHINESOFTWAREClassesDadu.DaduObjHKEY_LOCAL_MACHINESOFTWAREClassesDadu.DaduObj.1HKEY_LOCAL_MACHINESOFTWAREClassesGoSrch.ContextItemHKEY_LOCAL_MACHINESOFTWAREClassesGoSrch.ContextItem.1HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainSearchBar=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchSearchAssistant=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallUniversalSearchToolbar
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}6D335DE7-E980-4400-AADE-9AC771AB77E3EAF23CEF-21AF-4707-9FF3-4959FD5055537B9A715E-9D87-4C21-BF9E-F914F2FA953FFC2499DE-A673-49FD-A2DE-EFE03E9572A35F7AB1DB-A899-46c1-8345-B72B4567EE86
Loading...