Home Malware Programs Adware AdWare.Win32.EzSearch.e

AdWare.Win32.EzSearch.e

Posted: September 20, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 7
First Seen: September 20, 2011
Last Seen: October 31, 2020
OS(es) Affected: Windows

AdWare.Win32.EzSearch.e is a malicious adware program created by hackers to generate and distribute various annoying advertisements to the affected computer system. AdWare.Win32.EzSearch.e spreads via malicious email attachments and shared files, or can come bundled with other harmful programs. AdWare.Win32.EzSearch.e can avoid detection of security software to stealthily monitor a computer, program or even a network. AdWare.Win32.EzSearch.e can modify the registry and download and install additional malware infection onto the corrupted PC. AdWare.Win32.EzSearch.e should be uninstalled as quickly as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\Microsoft\Windows Ez2pop\Ez2popkey.dat File name: %AppData%\Microsoft\Windows Ez2pop\Ez2popkey.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\Microsoft\Windows Ez2pop\Ez2popUDF.exe File name: %AppData%\Microsoft\Windows Ez2pop\Ez2popUDF.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\Microsoft\Windows Ez2pop\Ez2pop.exe File name: %AppData%\Microsoft\Windows Ez2pop\Ez2pop.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\Microsoft\Windows Ez2pop\Ez2popDll.exe File name: %AppData%\Microsoft\Windows Ez2pop\Ez2popDll.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\nsg2.tmp\SelfDelete.dll File name: %Temp%\nsg2.tmp\SelfDelete.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%AppData%\Microsoft\Windows Ez2pop\Ez2pop.dll File name: %AppData%\Microsoft\Windows Ez2pop\Ez2pop.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%AppData%\Microsoft\Windows Ez2pop\Ez2popurl2.dat File name: %AppData%\Microsoft\Windows Ez2pop\Ez2popurl2.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\Microsoft\Windows Ez2pop\Ez2popurl.dat File name: %AppData%\Microsoft\Windows Ez2pop\Ez2popurl.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\Microsoft\Windows Ez2pop\Ez2popurl1.dat c:\DelUS.bat File name: %AppData%\Microsoft\Windows Ez2pop\Ez2popurl1.dat c:\DelUS.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\ProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D04D4A4-27FB-46BA-BF6A-D5CA22762A1E}\1.0\0HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76E789D4-F839-4203-8DBD-7A74B1FC7A29}\ProxyStubClsid32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76E789D4-F839-4203-8DBD-7A74B1FC7A29}\ProxyStubClsidHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76E789D4-F839-4203-8DBD-7A74B1FC7A29}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\VersionIndependentProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\TypeLibHKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D04D4A4-27FB-46BA-BF6A-D5CA22762A1E}\1.0HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D04D4A4-27FB-46BA-BF6A-D5CA22762A1E}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76E789D4-F839-4203-8DBD-7A74B1FC7A29}\TypeLibHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\Programmable
Loading...