Home Malware Programs Adware SearchMall

SearchMall

Posted: March 28, 2006

SearchMall is an adware spyware that sends a web browser to a predetermined web site and then shows undesirable links and advertisements. It also changes Internet Explorer default home page to the www.thesearchmall.com site. The spyware can secretly get into the computer while visiting some unsafe web resources. It runs every time the user launches Internet Explorer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 winsrm32.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTSoftwareshare_srmHKEY_CLASSES_ROOTwinsrm.amoHKEY_CLASSES_ROOTwinsrm.amo.1HKEY_CLASSES_ROOTwinsrm.dbiHKEY_CLASSES_ROOTwinsrm.dbi.1HKEY_CLASSES_ROOTwinsrm.iiitttHKEY_CLASSES_ROOTwinsrm.iiittt.1HKEY_CLASSES_ROOTwinsrm.momoHKEY_CLASSES_ROOTwinsrm.momo.1HKEY_CLASSES_ROOTwinsrm.ohbHKEY_CLASSES_ROOTwinsrm.ohb.1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}66E377BD-6FF9-43E9-9A5D-DAC6FD7A05ACE53B0BE9-B055-4230-9F9D-68FB0C76F1309DD1AD56-8D03-4BA8-BEE2-7C9A46182ED28B6D1A16-E636-4127-9EF6-4F1DD93AC2A96CE5322C-F6B3-4AC5-973C-6E0E2098EBF041F108A6-539D-4D0F-B93B-8A446A18645D34BAFAAF-99C5-472D-8613-EB309903FDC574F25A2C-22B3-4023-8F1A-CA616C30A8B54B8F38C7-62FC-4762-B9A0-27E63F76816741D13E9A-BB94-402A-8502-AFA78526B63D356F7928-CB5D-4E2F-906C-04CB8DB29BE20AEE4D0C-4B38-4196-AE32-70ACE5656647
Loading...