Home Malware Programs Adware Zebar

Zebar

Posted: April 1, 2014

Threat Metric

Ranking: 12,371
Threat Level: 2/10
Infected PCs: 4,167
First Seen: April 1, 2014
Last Seen: October 4, 2023
OS(es) Affected: Windows


Zebar Ads is an adware program that loads additional content through your Web browser. This content often is marketed as advantageous to your online shopping experiences, although malware researchers have seen minimal actual benefits from Zebar Ads. Like any adware, Zebar Ads also holds within Zebar Ads the possibility of endangering your Web-browsing activities with a variety of low-key security issues, such as being able to update itself automatically. As a natural response to these unwanted features, removing Zebar Ads through the use of a good adware-removal utility is considered optimal for your browser's performance, security and privacy.

The Advertisements that want to Tell You Where to Shop

Zebar Ads is a Potentially Unwanted Program, which doesn't provide functions of deliberately threatening intent, but does display advertisements in a way that is unlikely to benefit you or your PC in any way. Through the injection of additional Web content, most often thumbnails and pop-ups for related product search results, Zebar Ads tries to promote its advertising partners while pretending that this helps you find savings. Sadly, this quintessential adware function has no verified savings for its users, and malware researchers sometimes find that advertisement networks from products like Zebar Ads also are compromised by persons exploiting them for easy attacks against viewers.

Since Zebar Ads modifies Web pages to display this new content automatically, Zebar Ads also may hinder your access to normal Web content. Zebar Ads's advertisements may prevent you from reading text, viewing images or accessing basic website controls. Since Zebar Ads, like many other types of adware, also reserves for itself the right to update automatically, Zebar Ads also may add other functions over time. Malware researchers rate all of these issues as potential risks to your online security and, as a rule, there's no reason to tolerate them.

Wiping Your Browser Clean from Advertisements to Zebar

Zebar Ads is not considered a threat, but malware researchers continue to recommend the removal of adware without intentionally malign functions. Web browsers modified by Zebar Ads or other adware tend to be in greater danger than usual of being exposed to phishing attacks, online misleading tactics, threat-installing files and other PC threats that are extremely common on questionable advertisement networks. Removing Zebar Ads does not pose a hindrance to your ability to find legitimate shopping bargains through safe channels, but Zebar Ads does increase your online security and, potentially, may re-stabilize a browser that's showing symptoms of unwanted modifications (such as slow loading times).

If you need to delete Zebar Ads from an already affected browser, using anti-adware or anti-malware software is recommended, as a general rule. The latter, in particular, should be considered whenever Zebar Ads is installed automatically, which sometimes is a symptom of the attacks of Trojan downloaders and other threats. On the other side, not all Zebar Ads installers necessarily are distributed by Trojans, and malware experts see no need to consider Zebar Ads's presence as equal to that of a high-level threat's attacks against the affected machine.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



system32\drivers\{9f93bd66-d3d2-427d-b37f-743603e2388d}Gt64.sys File name: {9f93bd66-d3d2-427d-b37f-743603e2388d}Gt64.sys
Size: 60.08 KB (60088 bytes)
MD5: 1f8ced295c379e6bb0819951cb9c80c9
Detection count: 31
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: July 11, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{26e67fb2-111e-417f-966e-547ac43968cf}{A2754B05-A74E-4A3B-998B-7D682F46C836}{FD434553-D1EB-4212-B3D7-8BA0938DD62B}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{26e67fb2-111e-417f-966e-547ac43968cf}SOFTWARE\Microsoft\Tracing\updateZebar_RASAPI32SOFTWARE\Microsoft\Tracing\updateZebar_RASMANCSSOFTWARE\Microsoft\Tracing\utilZebar_RASAPI32SOFTWARE\Microsoft\Tracing\utilZebar_RASMANCSSOFTWARE\Microsoft\Tracing\Zebar_RASAPI32SOFTWARE\Microsoft\Tracing\Zebar_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{26e67fb2-111e-417f-966e-547ac43968cf}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{26e67fb2-111e-417f-966e-547ac43968cf}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{26e67fb2-111e-417f-966e-547ac43968cf}SOFTWARE\Wow6432Node\Microsoft\Tracing\updateZebar_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateZebar_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilZebar_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilZebar_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\Zebar_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Zebar_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{26e67fb2-111e-417f-966e-547ac43968cf}SOFTWARE\Wow6432Node\ZebarSoftware\ZebarSYSTEM\ControlSet001\services\eventlog\Application\Update ZebarSYSTEM\ControlSet001\services\eventlog\Application\Util ZebarSYSTEM\ControlSet001\services\Update ZebarSYSTEM\ControlSet001\services\Util ZebarSYSTEM\CurrentControlSet\services\eventlog\Application\Update ZebarSYSTEM\CurrentControlSet\services\eventlog\Application\Util ZebarSYSTEM\CurrentControlSet\services\Update ZebarSYSTEM\CurrentControlSet\services\Util ZebarHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Zebar

Additional Information

The following directories were created:
%PROGRAMFILES%\Zebar%PROGRAMFILES(x86)%\Zebar

Related Posts

Loading...