Home Malware Programs Adware Adware:Win32/Enumerate

Adware:Win32/Enumerate

Posted: December 7, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 36
First Seen: December 7, 2012
OS(es) Affected: Windows

Adware:Win32/Enumerate is an adware application that registers itself as a Browser Helper Object (BHO), and may use your search queries to display advertisements. Once installed and executed, on the infected computer system, Adware:Win32/Enumerate makes system changes by adding potentially malicious files, registry entries and keys. Adware:Win32/Enumerate controls what websites the affected PC user visits. Based on what searches the PC user makes or websites he/she visits, it may display advertisements or open other websites. Adware:Win32/Enumerate displays ads from the certain websites. Adware:Win32/Enumerat can update itself by connecting to a certain URL.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



enumerate_gtu.exe File name: enumerate_gtu.exe
Size: 929.79 KB (929792 bytes)
MD5: ec5d534b03921e01a7e4966ad6f53e9d
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 6, 2013
94fdccde92ea229c9f55d6bc37b98697 File name: 94fdccde92ea229c9f55d6bc37b98697
Size: 98.5 KB (98501 bytes)
MD5: 94fdccde92ea229c9f55d6bc37b98697
Detection count: 75
Group: Malware file
Last Updated: March 6, 2013
dcd1612bda9d8c9a479cf9474cb09088 File name: dcd1612bda9d8c9a479cf9474cb09088
Size: 1.71 MB (1716736 bytes)
MD5: dcd1612bda9d8c9a479cf9474cb09088
Detection count: 74
Group: Malware file
Last Updated: March 6, 2013
6dd6193b3784c4d65791ad0e629029fd File name: 6dd6193b3784c4d65791ad0e629029fd
Size: 135.48 KB (135482 bytes)
MD5: 6dd6193b3784c4d65791ad0e629029fd
Detection count: 63
Group: Malware file
Last Updated: March 6, 2013
%ProgramFiles%\enumerate\gtenumerate_gtu.exe File name: %ProgramFiles%\enumerate\gtenumerate_gtu.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\enumerate\gtenumerate_gt.dll File name: %ProgramFiles%\enumerate\gtenumerate_gt.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\enumerate\gtuninstall.exe File name: %ProgramFiles%\enumerate\gtuninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\enumerate\gtenumst.exe File name: %ProgramFiles%\enumerate\gtenumst.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ "@" = "Enumerate Top Search - GT"HKEY_LOCAL_MACHINE\SOFTWARE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ "NoExplorer"= "dword:00000001"HKEY_CLASSES_ROOT\CLSID\ "@" = "Enumerate Top Search - GT"HKEY_CLASSES_ROOT\CLSID\{RANDOM CLSID}\InprocServer32 "@" = "%ProgramFiles%\enumerate\gt\enumerate_gt.dll"HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\SOFTWARE\Classes\AppID\enumerate_gt_goalplay.DLLHKEY_CURRENT_USER\Software\enumerate_gtHKEY_LOCAL_MACHINE\SOFTWARE\SOFTWARE\Classes\enumerate_gt_search02.enumerate_gt_searHKEY_LOCAL_MACHINE\SOFTWARE\SOFTWARE\Classes\enumerate_gt_goalplay.enumerate_gt_goal
Loading...