Home Malware Programs Adware PodoWeb

PodoWeb

Posted: July 30, 2014

Threat Metric

Ranking: 19,615
Threat Level: 2/10
Infected PCs: 4,991
First Seen: July 30, 2014
Last Seen: February 27, 2025
OS(es) Affected: Windows


PodoWeb is an adware application that may conduct various actions to display several ads across your screen. For the most part, the PodoWeb ads are aggravating and do not prove to be that useful for the type of products or services the ads offer. Use of the PodoWeb ads is known to redirect your web browser to random sites or pages that have unwanted or questionable content. The PodoWeb ads may come in various formats, such as banners, pop-ups and pop-unders. In some rare instances the PodoWeb ads may cause your web browser to perform slowly. Stopping the random PodoWeb pop-ups and ads from displaying may take finding all related components or browser extensions and removing each of them. Automatically removing PodoWeb and its related components may take use of an antispyware tool.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\PodoWeb\PodoWeb.FirstRun.exe File name: PodoWeb.FirstRun.exe
Size: 1.12 MB (1123608 bytes)
MD5: bc7c12d89097b5ab092216c43f9c6882
Detection count: 51
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\PodoWeb
Group: Malware file
Last Updated: August 18, 2014
%PROGRAMFILES(x86)%\PodoWeb\bin\PodoWeb.BrowserAdapter.exe File name: PodoWeb.BrowserAdapter.exe
Size: 108.23 KB (108232 bytes)
MD5: 84619d5f34d97331f0fe69ddb51dbb7b
Detection count: 18
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PodoWeb\bin
Group: Malware file
Last Updated: December 18, 2015
%PROGRAMFILES(x86)%\PodoWeb\bin\PodoWeb.PurBrowse64.exe File name: PodoWeb.PurBrowse64.exe
Size: 353.48 KB (353480 bytes)
MD5: fd8984accca4d188749baad9e3d32240
Detection count: 17
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PodoWeb\bin
Group: Malware file
Last Updated: December 18, 2015
%PROGRAMFILES(x86)%\PodoWeb\bin\PodoWeb.expext.exe File name: PodoWeb.expext.exe
Size: 115.4 KB (115400 bytes)
MD5: 7a454625fe40ce45879a06be88f0f5f1
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PodoWeb\bin
Group: Malware file
Last Updated: December 18, 2015
%PROGRAMFILES(x86)%\PodoWeb\bin\utilPodoWeb.exe File name: utilPodoWeb.exe
Size: 653 KB (653000 bytes)
MD5: d594b4d0dc63d3270c559550ea34eeb8
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\PodoWeb\bin
Group: Malware file
Last Updated: December 18, 2015

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{06CDA919-B001-49D5-A555-ADD1AE1BC38E}{13f75e5b-d92b-4ad2-8c9a-860a287be74c}{5401490B-25E8-4E30-8AA8-D76E51C2AE99}{AEDAB5B0-022B-465C-A88B-1E8C2FAAA5A2}{B3D6B511-4D77-44DB-A459-938D9E6995F7}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{980B8A8F-EA0B-4C24-A2E9-70635E2502E9}SOFTWARE\Microsoft\Tracing\PodoWeb_RASAPI32SOFTWARE\Microsoft\Tracing\PodoWeb_RASMANCSSOFTWARE\Microsoft\Tracing\updatePodoWeb_RASAPI32SOFTWARE\Microsoft\Tracing\updatePodoWeb_RASMANCSSOFTWARE\Microsoft\Tracing\utilPodoWeb_RASAPI32SOFTWARE\Microsoft\Tracing\utilPodoWeb_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{980B8A8F-EA0B-4C24-A2E9-70635E2502E9}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{980B8A8F-EA0B-4C24-A2E9-70635E2502E9}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{980B8A8F-EA0B-4C24-A2E9-70635E2502E9}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{980b8a8f-ea0b-4c24-a2e9-70635e2502e9}SOFTWARE\PodoWebSOFTWARE\Wow6432Node\Microsoft\Tracing\PodoWeb_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\PodoWeb_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updatePodoWeb_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatePodoWeb_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilPodoWeb_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilPodoWeb_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{13f75e5b-d92b-4ad2-8c9a-860a287be74c}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{980B8A8F-EA0B-4C24-A2E9-70635E2502E9}SOFTWARE\Wow6432Node\PodoWebSYSTEM\ControlSet001\services\eventlog\Application\Update PodoWebSYSTEM\ControlSet001\services\eventlog\Application\Util PodoWebSYSTEM\ControlSet001\services\Update PodoWebSYSTEM\ControlSet001\services\Util PodoWebSYSTEM\ControlSet002\services\eventlog\Application\Update PodoWebSYSTEM\ControlSet002\services\eventlog\Application\Util PodoWebSYSTEM\ControlSet002\services\Update PodoWebSYSTEM\ControlSet002\services\Util PodoWebSYSTEM\CurrentControlSet\services\eventlog\Application\Update PodoWebSYSTEM\CurrentControlSet\services\Update PodoWebHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}PodoWeb

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\01e58235-010d-43b1-8340-277d43a75321%ALLUSERSPROFILE%\Application Data\01e58235-010d-43b1-8340-277d43a75321%PROGRAMFILES%\PodoWeb%PROGRAMFILES(x86)%\PodoWeb%Temp%\PodoWeb
Loading...