Home Malware Programs Adware Expand

Expand

Posted: March 28, 2006

Expand adware records keywords the user enters into popular Internet search engines. The application installs additional Internet Explorer toolbar, which shows advertising links based on logged keywords. Expand must be manually installed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 barbho.dll
    2 mygeek.dll
    3 mygeekremove.exe
    4 reg2.exe
    5 sidebar.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREClassesBarBHO.Class1HKEY_LOCAL_MACHINESOFTWAREClassesMyGeek.ComHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstalleXpandSearch_is1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}48977F6E-4120-4F88-8C4B-A6399BD0DD0847D616A1-B588-45D1-AD71-33AC15FB69409F9D3D1F-E697-4A86-90C7-58CECF6A26347BD45240-7166-4768-A845-8CE375C5E096CD2A865B-6C0F-44F9-BAA1-7CDB31E04BC8C431BF1E-9E71-4BB6-9C4E-8496D158DB1F

Related Posts

Loading...