Home Malware Programs Browser Plugins UpSpiralBar

UpSpiralBar

Posted: March 28, 2006

UpSpiralBar is a commercial Internet Explorer toolbar that secretly downloads and installs third-party advertising applications. It updates itself via the Internet. UpSpiralBar doesn't spread and must be manually installed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 snbupt.exe
    2 tbinstall.exe
    3 uninst2.exe
    4 uninstall.exe
    5 upspiral.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTupspiral.UPSPIRALHKEY_CLASSES_ROOTupspiral.UPSPIRALMenuButtonHKEY_CLASSES_ROOTupspiral.UPSPIRALToggleButtonHKEY_CURRENT_USERSoftwareUpspiralToolbarHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsnbupt=C:Windowssnbupt.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallUpspiral
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}4E7BD74F-2B8D-469E-DEFF-ED65A486AA2A4E7BD74F-2B8D-469E-DEFF-ED65A486AA294E7BD74F-2B8D-469E-DEFF-ED65A486AA284E7BD74F-2B8D-469E-D7F3-FA7EA480A97D
Loading...