Threat Database Adware AdWare.Win32.EzSearch.e

AdWare.Win32.EzSearch.e

By ESGI Advisor in Adware

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 3
First Seen: September 20, 2011
Last Seen: October 31, 2020
OS(es) Affected: Windows

AdWare.Win32.EzSearch.e is a dangerous adware generated by attackers to create and spread numerous disturbing pop-up advertisements to the infected PC system. AdWare.Win32.EzSearch.e circulates via spam email attachments and shared files, or can be installed by other malware infections. AdWare.Win32.EzSearch.e can modify the registry and download and install other malware threats onto the infected machine. AdWare.Win32.EzSearch.e can disguise itself from anti-virus program to secretly control a PC, program or network. You should delete AdWare.Win32.EzSearch.e immediately upon detection.

File System Details

AdWare.Win32.EzSearch.e may create the following file(s):
# File Name Detections
1. %AppData%\Microsoft\Windows Ez2pop\Ez2popDll.exe
2. c:\DelUS.bat
3. %AppData%\Microsoft\Windows Ez2pop\Ez2pop.exe
4. %AppData%\Microsoft\Windows Ez2pop\Ez2pop.dll
5. %AppData%\Microsoft\Windows Ez2pop\Ez2popUDF.exe
6. %Temp%\nsg2.tmp\SelfDelete.dll
7. %AppData%\Microsoft\Windows Ez2pop\Ez2popurl.dat
8. %AppData%\Microsoft\Windows Ez2pop\Ez2popurl2.dat
9. %AppData%\Microsoft\Windows Ez2pop\Ez2popkey.dat
10. %AppData%\Microsoft\Windows Ez2pop\Ez2popurl1.dat

Registry Details

AdWare.Win32.EzSearch.e may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76E789D4-F839-4203-8DBD-7A74B1FC7A29}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76E789D4-F839-4203-8DBD-7A74B1FC7A29}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76E789D4-F839-4203-8DBD-7A74B1FC7A29}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D04D4A4-27FB-46BA-BF6A-D5CA22762A1E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D04D4A4-27FB-46BA-BF6A-D5CA22762A1E}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76E789D4-F839-4203-8DBD-7A74B1FC7A29}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D04D4A4-27FB-46BA-BF6A-D5CA22762A1E}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EF6F70A-B4F1-46E2-8198-A15E3B176F68}\Programmable

Trending

Most Viewed

Loading...