Home Malware Programs Browser Hijackers ToolbarCC

ToolbarCC

Posted: March 28, 2006

ToolbarCC is a browser hijacker that detects when the user performs a search in a popular Internet search engine Google and sends a web browser to a predetermined web site instead of showing Google search results. ToolbarCC records all entered search keywords and addresses of visited web sites and sends gathered data to its home server. The spyware runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 mss.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMatrixScreenSaver=mss.exe
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}1F48AA48-C53A-4E21-85E7-AC7CC6B5FFaF1F48AA48-C53A-4E21-85E7-AC7CC6B5FFa81F48AA48-C53A-4E21-85E7-AC7CC6B5FFA7
Loading...