Home Malware Programs Adware Oemji

Oemji

Posted: October 11, 2006

Oemji is an IE toolbar that installs as a browser helper object (BHO). Oemji hijacks your browser
and changes the default search provider, without your permission, to the Oemji search provider. Oemji s search engine is of low quality and instead of providing the best available results, it mainly shows paid products that on other search engines you can easily find for free.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 oemjiinstall.exe
    2 oemjipls.dll
    3 pbhelper.dll
    4 sfbnsp.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{d240dc29-c093-4388-b71f-a7103c796b0c}HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser\{804db5c7-31e6-4885-850a-f1941b58a4c7}HKEY_CURRENT_USER\software\oemjiHKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{9a91af9e-e985-4586-89cc-c776db86d97b}HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{804db5c7-31e6-4885-850a-f1941b58a4c7}HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\program files\common files\oem common\bayesobj.dllHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\program files\common files\oem common\robj1.dllHKEY_LOCAL_MACHINE\software\oemji toolbar\uninstallHKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\bayesobj.bayesianobjectHKEY_CLASSES_ROOT\bayesobj.mailitemHKEY_CLASSES_ROOT\bayesobj.whitelistobjectHKEY_CLASSES_ROOT\cconfirmationobject.cconfirmationobHKEY_CLASSES_ROOT\cconfirmationobject.cconfirmationob.1.0HKEY_CLASSES_ROOT\cemailprompt.cemailpromptHKEY_CLASSES_ROOT\cemailprompt.cemailprompt.1.0HKEY_CLASSES_ROOT\clsid\{5e022a40-7cc4-4eba-a143-8d5c3b8838db}HKEY_CLASSES_ROOT\clsid\{6c90276e-8ec4-4ded-b67d-061e92569e72}HKEY_CLASSES_ROOT\clsid\{804db5c7-31e6-4885-850a-f1941b58a4c7}HKEY_CLASSES_ROOT\clsid\{ad2069f5-4ecd-48e0-a478-2d0e34d6dc32}HKEY_CLASSES_ROOT\clsid\{b2fc70c6-b39a-4d80-ac64-45bbfa82256f}HKEY_CLASSES_ROOT\clsid\{d240dc29-c093-4388-b71f-a7103c796b0c}HKEY_CLASSES_ROOT\clsid\{d7f152aa-2fe1-4cfa-9838-6782bf85c929}HKEY_CLASSES_ROOT\clsid\{d8cb10e7-601a-4176-b6b5-cefa244d4dea}HKEY_CLASSES_ROOT\clsid\{ee7fadf9-31da-49ab-a026-ef9366ceb8b0}HKEY_CLASSES_ROOT\interface\{0cfc2012-205b-4e00-9417-35822237c52c}HKEY_CLASSES_ROOT\interface\{5ec4d98f-ccf4-47b0-8c92-45b764a602a6}HKEY_CLASSES_ROOT\interface\{e4a5b138-6be5-4a0d-a5c3-d2de4a62ebdc}HKEY_CLASSES_ROOT\noah.cdownloadprogresscontrollerHKEY_CLASSES_ROOT\noah.registrationobjHKEY_CLASSES_ROOT\oemjisearchplus.iefriendlyHKEY_CLASSES_ROOT\pbhelper.pbtoolbarhosterHKEY_CLASSES_ROOT\typelib\{0ac17d72-80f3-4f79-bfcc-9a779ba70334}HKEY_CLASSES_ROOT\typelib\{828bc5d5-9c49-4dfd-b3c5-0436707df5b3}HKEY_CLASSES_ROOT\typelib\{aef5eb3e-0739-4a12-83f3-77249d80f63f}HKEY_CLASSES_ROOT\typelib\{b0ddf13b-2d10-472d-b409-f10476e9a12a}HKEY_CLASSES_ROOT\typelib\{be7b3ed5-dd42-43ad-a444-dd08f3e45621}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}oemji toolbar
Loading...