Home Malware Programs Potentially Unwanted Programs (PUPs) SearchFoot

SearchFoot

Posted: April 17, 2014

Threat Metric

Ranking: 14,600
Threat Level: 2/10
Infected PCs: 4,319
First Seen: April 17, 2014
Last Seen: March 3, 2025
OS(es) Affected: Windows


SearchFoot is a potentially unwanted program (PUP) that has been made compatible with Internet Explorer, Google Chrome and Mozilla Firefox Web browsers. SearchFoot may be distributed and enter the computer system as an optional application bundled with various freeware that PC users download and install from unreliable download websites. After installation into the computer, SearchFoot may start creating and showing numerous types of intrusive advertisements, such as interstitial and full page ads, in-text ads and links, search-related ads, banner and video ads. SearchFoot may monitor the computer user's Internet surfing habits by recording software and hardware information including IP address, operating system, browser type, unique identifier number, entered search queries, websites visited, and other similar information.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\SearchFoot\bin\SearchFoot.PurBrowse64.exe File name: SearchFoot.PurBrowse64.exe
Size: 287 KB (287008 bytes)
MD5: fbc6b6639e38650e80cb1e46858e2bdc
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SearchFoot\bin
Group: Malware file
Last Updated: August 25, 2014
%PROGRAMFILES%\SearchFoot\bin\SearchFoot.PurBrowse.exe File name: SearchFoot.PurBrowse.exe
Size: 239.39 KB (239392 bytes)
MD5: 987e43eb1118fd699b439cd576595cd5
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SearchFoot\bin
Group: Malware file
Last Updated: August 25, 2014
%PROGRAMFILES%\SearchFoot\updater.exe File name: updater.exe
Size: 109.56 KB (109568 bytes)
MD5: 82d5c9176f2b0316652726df79ddeae0
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SearchFoot
Group: Malware file
Last Updated: August 25, 2014
%PROGRAMFILES%\SearchFoot\bin\SearchFoot.BrowserAdapter.exe File name: SearchFoot.BrowserAdapter.exe
Size: 96.54 KB (96544 bytes)
MD5: 7541f57eb48b534b7ad067a05c95f326
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SearchFoot\bin
Group: Malware file
Last Updated: August 25, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{0A2FAE03-A8A5-4E5F-B732-329EF221D26A}{1AB8383F-6383-4873-A031-7B06687CC83D}{e8a37c8e-4949-4e1b-ad24-2d1c141be207}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{E8A37C8E-4949-4E1B-AD24-2D1C141BE207}SOFTWARE\Microsoft\Tracing\SearchFoot_RASAPI32SOFTWARE\Microsoft\Tracing\SearchFoot_RASMANCSSOFTWARE\Microsoft\Tracing\updateSearchFoot_RASAPI32SOFTWARE\Microsoft\Tracing\updateSearchFoot_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\SearchFoot_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchFoot_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateSearchFoot_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateSearchFoot_RASMANCSSYSTEM\ControlSet001\services\eventlog\Application\Update SearchFootSYSTEM\ControlSet001\services\Update SearchFootSYSTEM\ControlSet002\services\eventlog\Application\Update SearchFootSYSTEM\ControlSet002\services\Update SearchFootSYSTEM\CurrentControlSet\services\eventlog\Application\Update SearchFootSYSTEM\CurrentControlSet\services\Update SearchFoot

Additional Information

The following directories were created:
%PROGRAMFILES%\SearchFoot%PROGRAMFILES(x86)%\SearchFoot
The following URL's were detected:
searchfoot.net
Loading...