Home Malware Programs Browser Hijackers Startsear.ch Hijacker

Startsear.ch Hijacker

Posted: September 27, 2013

Threat Metric

Ranking: 5,097
Threat Level: 5/10
Infected PCs: 43,348
First Seen: September 27, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\VshareComplete\64\VshareComplete64.dll File name: VshareComplete64.dll
Size: 167.41 KB (167416 bytes)
MD5: 767d596925e3e156179802be3484fb03
Detection count: 7,659
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Users\<username>\AppData\Roaming\VshareComplete\64\VshareComplete64.dll
Group: Malware file
Last Updated: December 7, 2022
%APPDATA%\VshareComplete\VshareComplete.dll File name: VshareComplete.dll
Size: 139.76 KB (139768 bytes)
MD5: 93152c7fa0269fefe8e911a58cc794ec
Detection count: 3,188
File type: Dynamic link library
Mime Type: unknown/dll
Path: %APPDATA%\VshareComplete
Group: Malware file
Last Updated: April 23, 2020
C:\Users\<username>\AppData\Roaming\VshareComplete\VshareComplete.dll File name: VshareComplete.dll
Size: 139.76 KB (139768 bytes)
MD5: e0c256256b8e4501941227e864d9ad3d
Detection count: 91
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Users\<username>\AppData\Roaming\VshareComplete\VshareComplete.dll
Group: Malware file
Last Updated: June 7, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{08337871-0e50-4031-9110-3bd21ca3c065}{3D782BB2-F2A5-11D3-BF4C-000000000000}{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}{79D60450-56C5-4A8C-9321-6D5BC2A81E5A}{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}{8F97BFF8-488B-4107-BCEE-B161AB4E4183}{BB49DAC0-7542-405C-B2C0-672B78885B56}{BB7256DD-EBA9-480B-8441-A00388C2BEC3}{C876A2AD-D4BA-11D3-9D38-D0D087C500CC}{DB1F5554-582C-4F53-82CC-458D2C04A2F1}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{08337871-0E50-4031-9110-3BD21CA3C065}Software\Microsoft\Internet Explorer\Approved Extensions\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}Software\Microsoft\Internet Explorer\Approved Extensions\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6BD63EF5-F376-4104-B390-F6E1E3BEDAAC}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{08337871-0e50-4031-9110-3bd21ca3c065}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}Software\StartSearchSoftware\vShare.tvSoftware\VsharecompleteSoftware\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{6BD63EF5-F376-4104-B390-F6E1E3BEDAAC}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}StartSearch ToolbarvShare.tv plugin{ec4b6105-e039-42fb-8e18-c8aa393f0018}_is1

Additional Information

The following directories were created:
%APPDATA%\VshareComplete%PROGRAMFILES%\StartSearch plugin%PROGRAMFILES%\VshareComplete%PROGRAMFILES%\vShare.tv plugin%PROGRAMFILES(x86)%\StartSearch plugin%PROGRAMFILES(x86)%\VshareComplete%PROGRAMFILES(x86)%\vShare.tv plugin
The following URL's were detected:
startsear.ch
Loading...