Home Malware Programs Bad Toolbars DownShotFree Toolbar

DownShotFree Toolbar

Posted: May 4, 2015

Threat Metric

Ranking: 4,902
Threat Level: 2/10
Infected PCs: 24,449
First Seen: May 4, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{1A69D6AE-AFBE-4660-8CE6-BF529E8C075C}{20983e68-68e3-49d5-bebe-9905a0ff6dca}{2E92EEC0-62C4-4BDF-9D24-6439FC1842D2}{38c9d1d5-1cb7-4a79-b724-79ad0a5f3bee}{3ea2f517-f861-4808-ac97-df37a984e665}{402a6a30-cf41-491b-94f2-bf5c132ac303}{46850749-0877-48c0-ba00-b09bb3894ba2}{4A8525F7-F10B-4AA3-A609-B99D81FB2DC4}{6779cbd1-3260-4e8e-a6c8-30e16a667941}{683384F4-8600-464B-B62A-9B74ED390D4A}{73B59465-2AE5-4873-8F4A-82DE64D7FD5E}{73D04B4A-E292-4077-8061-5928BD56CAF0}{787ae9bb-0318-49de-b3e4-ee99d863ee9e}{91B34B1D-0E4C-477D-91E8-8E5FDEBEEEE4}{99a56a24-3a9c-4760-bb2e-7eb2e02cf02e}{AA171016-901C-4A02-884E-7E7675951D11}{abe604d1-9241-4ca4-83eb-9fec12839e14}{B504670F-4883-4340-A808-526720C77658}{b6fba4e3-33e9-4aef-9e77-e4e2a0d4e36e}{b7ca0785-797d-43ed-b945-9e6537e41130}{BB7CC0A9-74A8-47CB-88BA-288687BFF826}{bc563929-7de7-4cda-a9bf-086ed062bc54}{c2f15c29-9d64-4d29-af82-3bcc899c7834}{c8774b1a-7325-46cb-b3e1-b20adf147fc7}{D20DDE9B-9311-412A-89E0-80BA645D1D00}{db2e8d44-3996-439c-8302-06908a33c52a}{e05670b0-1e3f-4ad4-9878-512ee04a159a}{f51a32a7-b554-4296-b001-3a9242f3c393}File name without pathdownshotfree.dl.tb.ask[1].xmlDownShotFree.lnkhttp_DownShotFree.dl.tb.ask.com_0.localstoragehttp_DownShotFree.dl.tb.ask.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}SOFTWARE\AppDataLow\Software\DownShotFree_e0Software\DownShotFree_e0Software\Microsoft\Internet Explorer\Approved Extensions\{B7CA0785-797D-43ED-B945-9E6537E41130}Software\Microsoft\Internet Explorer\Approved Extensions\{C2F15C29-9D64-4D29-AF82-3BCC899C7834}SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\downshotfree.dl.tb.ask.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\downspeedtest.dl.tb.ask.comSOFTWARE\Microsoft\Internet Explorer\Toolbar\{c2f15c29-9d64-4d29-af82-3bcc899c7834}SOFTWARE\Microsoft\Tracing\DownShotFree_RASAPI32SOFTWARE\Microsoft\Tracing\DownShotFree_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3ea2f517-f861-4808-ac97-df37a984e665}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{b7ca0785-797d-43ed-b945-9e6537e41130}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DownShotFree AppIntegrator 32-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\DownShotFree AppIntegrator 64-bitSOFTWARE\Microsoft\Windows\CurrentVersion\Run\DownShotFree EPM SupportSOFTWARE\Microsoft\Windows\CurrentVersion\Run\DownShotFree Search Scope MonitorSOFTWARE\Wow6432Node\DownShotFree_e0SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{c2f15c29-9d64-4d29-af82-3bcc899c7834}SOFTWARE\Wow6432Node\Microsoft\Tracing\DownShotFree_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\DownShotFree_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3ea2f517-f861-4808-ac97-df37a984e665}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{b7ca0785-797d-43ed-b945-9e6537e41130}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\DownShotFree AppIntegrator 32-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\DownShotFree AppIntegrator 64-bitSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\DownShotFree EPM SupportSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\DownShotFree Search Scope MonitorSYSTEM\ControlSet001\services\DownShotFree_e0ServiceSYSTEM\ControlSet002\services\DownShotFree_e0ServiceSYSTEM\CurrentControlSet\services\DownShotFree_e0ServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}DownShotFree_e0bar Uninstall Internet ExplorerMindspark DownShotFree

Additional Information

The following directories were created:
%PROGRAMFILES(x86)%\DownShotFree_e0EI%USERPROFILE%\AppData\LocalLow\DownShotFree_e0
Loading...