Home Malware Programs Adware ResultsBay

ResultsBay

Posted: June 2, 2014

Threat Metric

Ranking: 17,058
Threat Level: 2/10
Infected PCs: 614
First Seen: June 2, 2014
Last Seen: August 25, 2023
OS(es) Affected: Windows


ResultsBay is a potentially unwanted browser plug-in that may declare to make the PC user's Web browsing activity more efficient by displaying associated content containing websites, permitting comparison shopping, discount coupons and adding other beneficial functionalities. ResultsBay may appear as a reliable browser extension but, in fact, it is categorized as adware. The makers of ResultsBay, SuperWeb LLC, have produced it to be compatible with the popular Web browsers such as Internet Explorer, Google Chrome, and Mozilla Firefox. ResultsBay may be distributed and access the PC as an optional program through the downloads of packaged free applications. ResultsBay may integrate itself into the computer system surreptitiously together with other free programs. After installation, ResultsBay may produce and show a variety of non-stop banner, interstitial, search, text link, full page, and transitional advertisement. The main aim of ResultsBay may be to gain benefit from clicks on ads.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\ResultsBay\ResultsBayuninstall.exe File name: ResultsBayuninstall.exe
Size: 240.42 KB (240427 bytes)
MD5: fe5fce2ff62c0e8595c5c18feb787748
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ResultsBay
Group: Malware file
Last Updated: June 3, 2014
system32\drivers\{e34ff9ce-e6b6-450a-ace7-3acd1926facd}Gw64.sys File name: {e34ff9ce-e6b6-450a-ace7-3acd1926facd}Gw64.sys
Size: 61.12 KB (61120 bytes)
MD5: 605e6123cbbb77b21e2261977e7ab3af
Detection count: 55
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 7, 2014
system32\drivers\{e34ff9ce-e6b6-450a-ace7-3acd1926facd}Gw64.sys File name: {e34ff9ce-e6b6-450a-ace7-3acd1926facd}Gw64.sys
Size: 61.12 KB (61120 bytes)
MD5: f908a67d1b115444fba75b10affb518c
Detection count: 26
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 7, 2014
%PROGRAMFILES(x86)%\ResultsBay\bin\ResultsBay.BrowserAdapter.exe File name: ResultsBay.BrowserAdapter.exe
Size: 95.52 KB (95520 bytes)
MD5: b07f90b6b0a080d2ec45e88c2a7b0501
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ResultsBay\bin
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES%\ResultsBay\bin\ResultsBay.PurBrowse.exe File name: ResultsBay.PurBrowse.exe
Size: 239.39 KB (239392 bytes)
MD5: fa852f80f54123fbdfd713fbe89d33ef
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ResultsBay\bin
Group: Malware file
Last Updated: June 3, 2014
%PROGRAMFILES%\ResultsBay\ResultsBay.FirstRun.exe File name: ResultsBay.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 03d6c1369ef96139263568f4d95b47ca
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ResultsBay
Group: Malware file
Last Updated: June 3, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{3CF5D16C-D3B2-41C7-8617-228BB180FB3F}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Tracing\ResultsBay_RASAPI32SOFTWARE\Microsoft\Tracing\ResultsBay_RASMANCSSOFTWARE\Microsoft\Tracing\updateResultsBay_RASAPI32SOFTWARE\Microsoft\Tracing\updateResultsBay_RASMANCSSOFTWARE\Microsoft\Tracing\utilResultsBay_RASAPI32SOFTWARE\Microsoft\Tracing\utilResultsBay_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{1b0cf41e-334a-4984-a8a0-aa5affeb5482}SOFTWARE\ResultsBaySOFTWARE\Wow6432Node\Microsoft\Tracing\ResultsBay_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\ResultsBay_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateResultsBay_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateResultsBay_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilResultsBay_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilResultsBay_RASMANCSSOFTWARE\Wow6432Node\ResultsBaySYSTEM\ControlSet001\services\eventlog\Application\Update ResultsBaySYSTEM\ControlSet001\services\eventlog\Application\Util ResultsBaySYSTEM\ControlSet001\services\Update ResultsBaySYSTEM\ControlSet001\services\Util ResultsBaySYSTEM\ControlSet002\services\eventlog\Application\Util ResultsBaySYSTEM\CurrentControlSet\services\eventlog\Application\Update ResultsBaySYSTEM\CurrentControlSet\services\eventlog\Application\Util ResultsBaySYSTEM\CurrentControlSet\services\Update ResultsBaySYSTEM\CurrentControlSet\services\Util ResultsBayHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ResultsBay

Additional Information

The following directories were created:
%PROGRAMFILES%\ResultsBay%PROGRAMFILES(x86)%\ResultsBay
The following URL's were detected:
ResultsBay
Loading...