Home Malware Programs Browser Hijackers StartNow Toolbar By Zugo

StartNow Toolbar By Zugo

Posted: February 21, 2013

Threat Metric

Ranking: 3,910
Threat Level: 5/10
Infected PCs: 27,260
First Seen: February 21, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{1C888195-0160-4883-91B7-294C0CE2F277}{2CBD2A57-2FD5-4F1A-9FC8-90ED48FA4187}{38BF9661-BDA0-4A74-BB3B-576EC7AE16DC}{5911488E-9D1E-40ec-8CBB-06B231CC153F}{6857AC4A-95B4-4E2C-B2D2-8A235FCCEF4A}{6E13D095-45C3-4271-9475-F3B48227DD9F}{7E8A36EA-2501-4ED3-A3C8-CFA9143FB169}{99ACA0F7-D864-45CB-8C40-FD42A077E7CA}{E65F40C8-3CEB-47C2-9E01-BF73323DF4E7}{FAA8C612-F1B6-461B-8B60-B54D74D9642E}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\AppID\Toolbar.DLLSOFTWARE\Classes\AppID\ToolbarBroker.EXESOFTWARE\Classes\Toolbar.BandObjectSOFTWARE\Classes\Toolbar.BandObject.1SOFTWARE\Classes\Toolbar.ToolbarHelperObjectSOFTWARE\Classes\Toolbar.ToolbarHelperObject.1SOFTWARE\Classes\Wow6432Node\AppID\Toolbar.DLLSOFTWARE\Classes\ZGClnt.MngrSOFTWARE\Classes\ZGClnt.Mngr.1SOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}SOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{6E13D095-45C3-4271-9475-F3B48227DD9F}SOFTWARE\Wow6432Node\Classes\AppID\Toolbar.DLLSOFTWARE\Wow6432Node\Classes\AppID\ToolbarBroker.EXESOFTWARE\Wow6432Node\StartNow ToolbarSoftware\ZugoHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}StartNow Toolbar

Additional Information

The following directories were created:
%PROGRAMFILES%\StartNow Toolbar%PROGRAMFILES(x86)%\StartNow Toolbar
Loading...