Home Malware Programs Adware ScanTack

ScanTack

Posted: February 27, 2014

Threat Metric

Ranking: 13,316
Threat Level: 2/10
Infected PCs: 5,986
First Seen: February 27, 2014
Last Seen: February 19, 2025
OS(es) Affected: Windows


ScanTack is an adware program that may display several questionable coupon deals and other online savings offers through pop-ups. These advertisements may redirect your system to several unwanted sites upon clicking on them. The ScanTack ads may also generate banners and other forms of pop-up ads when randomly surfing the internet on several popular shopping websites. Eliminating the ScanTack ads may require finding all files related to the adware and removing each of them from your system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\ScanTack\bin\utilScanTack.exe File name: utilScanTack.exe
Size: 317.72 KB (317728 bytes)
MD5: 7d3797d6a2efc9299a6e0d556006364e
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ScanTack\bin
Group: Malware file
Last Updated: May 30, 2014
%PROGRAMFILES%\ScanTack\ScanTackbho.dll File name: ScanTackbho.dll
Size: 249.63 KB (249632 bytes)
MD5: 81846b0e7d2a519cb9bd6ab27c8aa329
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\ScanTack
Group: Malware file
Last Updated: May 30, 2014
%PROGRAMFILES%\ScanTack\bin\ScanTack.BrowserAdapter.exe File name: ScanTack.BrowserAdapter.exe
Size: 96.54 KB (96544 bytes)
MD5: fd34685e59102c216c034111fd11d1f4
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ScanTack\bin
Group: Malware file
Last Updated: May 30, 2014
%PROGRAMFILES%\ScanTack\ScanTackuninstall.exe File name: ScanTackuninstall.exe
Size: 240.11 KB (240117 bytes)
MD5: aac011ba5b9b862386735116f90bd628
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ScanTack
Group: Malware file
Last Updated: May 30, 2014
%PROGRAMFILES(x86)%\ScanTack\ScanTack.FirstRun.exe File name: ScanTack.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 1fba676afea83b10705880f6a8809358
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ScanTack
Group: Malware file
Last Updated: May 30, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{96EE63E6-6942-46F3-A1A0-2250E4E93D23}{AD836A49-1150-48E7-8841-BD466E20B0B0}Regexp file mask%WINDIR%\system32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64.sys%WINDIR%\system32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sysHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{a1bcc327-7c56-4d0c-a1b7-fd4c30da8a09}Software\Microsoft\Internet Explorer\Approved Extensions\{D332CFF8-358E-4C9E-8AF3-A08872EF22C1}SOFTWARE\Microsoft\Tracing\ScanTack_RASAPI32SOFTWARE\Microsoft\Tracing\ScanTack_RASMANCSSOFTWARE\Microsoft\Tracing\updateScanTack_RASAPI32SOFTWARE\Microsoft\Tracing\updateScanTack_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{D332CFF8-358E-4C9E-8AF3-A08872EF22C1}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D332CFF8-358E-4C9E-8AF3-A08872EF22C1}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D332CFF8-358E-4C9E-8AF3-A08872EF22C1}SOFTWARE\ScanTackSOFTWARE\Wow6432Node\Microsoft\Tracing\ScanTack_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\ScanTack_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateScanTack_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateScanTack_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{a1bcc327-7c56-4d0c-a1b7-fd4c30da8a09}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{D332CFF8-358E-4C9E-8AF3-A08872EF22C1}SOFTWARE\Wow6432Node\ScanTackSYSTEM\ControlSet001\services\eventlog\Application\Update ScanTackSYSTEM\ControlSet001\services\eventlog\Application\Util ScanTackSYSTEM\ControlSet001\services\Update ScanTackSYSTEM\ControlSet001\services\Util ScanTackSYSTEM\ControlSet001\Services\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64SYSTEM\ControlSet001\Services\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64SYSTEM\ControlSet002\services\eventlog\Application\Util ScanTackSYSTEM\ControlSet002\services\Util ScanTackSYSTEM\ControlSet002\Services\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64SYSTEM\ControlSet002\Services\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64SYSTEM\CurrentControlSet\services\eventlog\Application\Update ScanTackSYSTEM\CurrentControlSet\services\eventlog\Application\Util ScanTackSYSTEM\CurrentControlSet\services\Update ScanTackSYSTEM\CurrentControlSet\services\Util ScanTackSYSTEM\CurrentControlSet\Services\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64SYSTEM\CurrentControlSet\Services\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ScanTack

Additional Information

The following directories were created:
%PROGRAMFILES%\ScanTack%PROGRAMFILES(x86)%\ScanTack%TEMP%\ScanTack
The following URL's were detected:
ScanTack

One Comment

  • Carl A. Helsing says:

    removed all but one ite--(dll remains)--used file assassin---really sticky--obtained full permission's--still stick's-interesting--
    need jack-hammer-

Loading...