Home Malware Programs Browser Hijackers PortaldoSites.com Search

PortaldoSites.com Search

Posted: April 8, 2013

Threat Metric

Ranking: 4,740
Threat Level: 5/10
Infected PCs: 26,564
First Seen: April 8, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\System Volume Information\SystemRestore\FRStaging\Users\<username>\AppData\Local\Temp\eIntaller\B9FA133F551E42b3BAC8483AE01B3D8D\eXQ.exe File name: eXQ.exe
Size: 461.88 KB (461880 bytes)
MD5: 67cd4575597480529776360ac0f41a2a
Detection count: 682
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\SystemRestore\FRStaging\Users\<username>\AppData\Local\Temp\eIntaller\B9FA133F551E42b3BAC8483AE01B3D8D\eXQ.exe
Group: Malware file
Last Updated: June 30, 2023
eml_portaldosites(1).exe File name: eml_portaldosites(1).exe
Size: 472.65 KB (472656 bytes)
MD5: 8914c4a0adc9dda7dc3d9701901749c1
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 30, 2013
utd_ar_portaldosites.exe File name: utd_ar_portaldosites.exe
Size: 93.77 KB (93776 bytes)
MD5: bcfeaa3bb3f1ddbb1191f3e9af09881a
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 8, 2013

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttp_www.portaldosites.com_0.localstoragehttp_www.portaldosites.com_0.localstorage-journalportaldosites.lnkportaldosites.xmlHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\DOMStorage\portaldosites.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.portaldosites.comSoftware\Microsoft\Internet Explorer\LowRegistry\DOMStorage\portaldosites.comSoftware\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.portaldosites.comSOFTWARE\portaldositesSoftwareSOFTWARE\Wow6432Node\portaldositesSoftware

Additional Information

The following URL's were detected:
portaldosites.com
Loading...