Home Malware Programs Adware not-a-virus:FraudTool.Win32.EvidenceEraser.q

not-a-virus:FraudTool.Win32.EvidenceEraser.q

Posted: May 26, 2011

not-a-virus:FraudTool.Win32.EvidenceEraser.q is a malicious and annoying adware program that will bombard an affected user's computer with various types of advertisements. not-a-virus:FraudTool.Win32.EvidenceEraser.q will control a victim's browsing habits and show advertisements accordingly. The advertisements related to not-a-virus:FraudTool.Win32.EvidenceEraser.q may come in the form of pop-ups or banners. not-a-virus:FraudTool.Win32.EvidenceEraser.q may also drop other malware threats onto an infected machine which will steal a targeted user's personal details. Remove not-a-virus:FraudTool.Win32.EvidenceEraser.q once it's detected on a computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\EvidenceEraser\Log\2011 May 20 - 01_32_54 PM_300.log
    2 %AppData%\EvidenceEraser\Log\2011 May 20 - 01_33_26 PM_675.log
    3 %AppData%\EvidenceEraser\Log\2011 May 20 - 01_33_26 PM_956.log
    4 %AppData%\EvidenceEraser\Log\2011 May 20 - 01_33_27 PM_472.log
    5 %AppData%\EvidenceEraser\Settings\CustomScan.stg
    6 %AppData%\EvidenceEraser\Settings\IgnoreList.stg
    7 %AppData%\EvidenceEraser\Settings\ScanInfo.stg
    8 %AppData%\EvidenceEraser\Settings\SelectedFolders.stg
    9 %AppData%\EvidenceEraser\Settings\Settings.stg
    10 %CommonPrograms%\EvidenceEraser\EvidenceEraser on the Web.lnk
    11 %CommonPrograms%\EvidenceEraser\EvidenceEraser.lnk
    12 %CommonPrograms%\EvidenceEraser\Uninstall EvidenceEraser.lnk
    13 %DesktopDir%\EvidenceEraser.lnk
    14 %ProgramFiles%\EvidenceEraser\DataBase.ref
    15 %ProgramFiles%\EvidenceEraser\EvidenceEraser.exe
    16 %ProgramFiles%\EvidenceEraser\EvidenceEraser.url
    17 %ProgramFiles%\EvidenceEraser\gdiplus.dll
    18 %ProgramFiles%\EvidenceEraser\Launcher.exe
    19 %ProgramFiles%\EvidenceEraser\license.rtf
    20 %ProgramFiles%\EvidenceEraser\PrivacyShell.dll
    21 %ProgramFiles%\EvidenceEraser\unins000.dat
    22 %ProgramFiles%\EvidenceEraser\unins000.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EvidenceEraserHKEY_CURRENT_USER\Software\EvidenceEraser\EvidenceEraserHKEY_CURRENT_USER\Software\EvidenceEraser\EvidenceEraser\EvidenceEraserHKEY_CURRENT_USER\Software\EvidenceEraser\EvidenceEraser\RegInfoHKEY_CURRENT_USER\Software\EvidenceEraser\EvidenceEraser\SettingsHKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\PrivacyShellExtHKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\PrivacyShellExtHKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\PrivacyShell.DLLHKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D9A9DE7F-A259-4BC1-A348-87BC1053C4E8}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D642CFA-40F8-4AE0-9144-538BC1D725E4}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D642CFA-40F8-4AE0-9144-538BC1D725E4}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\PrivacyShellExtHKEY_LOCAL_MACHINE\SOFTWARE\EvidenceEraserHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}EvidenceEraser_is1
Loading...