Home Malware Programs Browser Plugins YuupSearch

YuupSearch

Posted: March 28, 2006

YuupSearch is an additional Internet Explorer toolbar that opens a predefined commercial web site on every Windows startup. The spyware can be secretly installed while visiting malicious Internet resources. It creates a directory, installs main files and modifies the registry. YuupSearch doesn't have dangerous payload, but is quite difficult to remove. It may severely affect overall computer performance and Internet connection speed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 google_toolbar.dll
    2 ie_agent.exe
    3 run_dll.exe
    4 yoop.exe
    5 yuup_toolbar.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTToolBand.ToolHelperHKEY_CLASSES_ROOTToolBand.ToolHelper.1HKEY_CURRENT_USERSoftwareXBTB01500ToolbarHKEY_LOCAL_MACHINESOFTWAREClassesXBTB01500.IEToolbarHKEY_LOCAL_MACHINESOFTWAREClassesXBTB01500.IEToolbar.1HKEY_LOCAL_MACHINESOFTWAREClassesXBTB01500.XBTB01500HKEY_LOCAL_MACHINESOFTWAREClassesXBTB01500.XBTB01500.1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMSTask=%System%HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallXBTB01500.XBTB01500Toolbarun_dll.exe
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}99BBD747-391D-461F-883B-A3C6D41BB28DEABBB49A-4d7b-415B-8250-15C3B854E9FF0D5CC8AE-0BB0-49C3-BA33-BA4508EA44CCBBBE1C1A-89F7-4AF6-ABD1-F8FBCFA474081CBF31FC-3C23-4BA6-AF16-2CEC501BD837
Loading...