Crawler Toolbar

Threat Scorecard

Popularity Rank: 561
Threat Level: 50 % (Medium)
Infected Computers: 22,578
First Seen: August 31, 2010
Last Seen: January 13, 2026
OS(es) Affected: Windows

Crawler Toolbar is a toolbar that can be used to help you search the internet when intentionally installed. Crawler Toolbar has a loose privacy policy or end user license agreement (EULA) and is often installed by malware or other malicious programs. When inside a machine, Crawler Toolbar will display annoying adware and possibly install other spyware or malware. Crawler Toolbar will also deteriorate a systems performance while gathering internet related information which it later sends to a remote third-party. In not intentionally installed, have Crawler Toolbar removed from your system as soon as possible.

Aliases

7 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Prevx1 Heuristic: Suspicious Self Modifying File
Symantec Suspicious.Insight
F-Prot W32/HotBar.A.gen!Eldorado
McAfee+Artemis Suspect-29!878E643FA7BA
Panda Suspicious file
McAfee+Artemis Suspect-29!C12B6F467570
Authentium W32/Podnuha.B.gen!Eldorado

SpyHunter Detects & Remove Crawler Toolbar

File System Details

Crawler Toolbar may create the following file(s):
# File Name MD5 Detections
1. PCRxTray.exe 2cfd05bae80678ca16a0bb0f2c1f1e43 119
2. PCRx.exe b05742ed2c53fb76e81c9a17401aa1b0 107
More files

Registry Details

Crawler Toolbar may create the following registry entry or registry entries:
CLSID
{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
{22C1406C-6350-4D3B-9F62-2A3F370AD9A7}
{2DC4F899-9C79-4462-863D-4EC61F3EFA52}
{38CF96AD-0ACC-49DF-91B7-5D7F640BF1B7}
{4545C96B-15D0-4E22-8DDE-6F2CAF531281}
{694AB2B2-6141-4567-9B66-B60FD06AD30F}
{7CC6C266-6155-4676-AE77-85164EAE29D9}
{9234F5E0-56CC-4F0B-AAE4-0D4BD5032180}
{BAA73D86-AFBD-4F73-8243-E7D193FA6C8B}
{C4D78C72-08DB-4A3F-9175-B265157283F3}
{EDDAFD4A-10D1-406A-8796-D13B54DB5E04}
{FA66632B-E294-4249-B007-64C07C7E0147}
File name without path
www.crawler[1].xml
SOFTWARE\Classes\Crawler.AppServer
SOFTWARE\Classes\Crawler.CRT404
SOFTWARE\Classes\Crawler.JSServer
SOFTWARE\Classes\Crawler.Toolbar
Software\Crawler Toolbar
Software\Microsoft\Internet Explorer\Approved Extensions\{9234F5E0-56CC-4F0B-AAE4-0D4BD5032180}
Software\Microsoft\Internet Explorer\Approved Extensions\{C4D78C72-08DB-4A3F-9175-B265157283F3}
Software\Microsoft\Internet Explorer\DOMStorage\crawler.com
Software\Microsoft\Internet Explorer\DOMStorage\www.crawler.com
SOFTWARE\Microsoft\Internet Explorer\MenuExt\Crawler Search
Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9234F5E0-56CC-4F0B-AAE4-0D4BD5032180}
Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9234F5E0-56CC-4F0B-AAE4-0D4BD5032180}
Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4D78C72-08DB-4A3F-9175-B265157283F3}
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{22C1406C-6350-4D3B-9F62-2A3F370AD9A7}
SOFTWARE\Wow6432Node\Crawler Toolbar
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAA73D86-AFBD-4F73-8243-E7D193FA6C8B}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4D78C72-08DB-4A3F-9175-B265157283F3}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9234F5E0-56CC-4F0B-AAE4-0D4BD5032180}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4D78C72-08DB-4A3F-9175-B265157283F3}

Directories

Crawler Toolbar may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Crawler Toolbar
%PROGRAMFILES%\Crawler Toolbar
%PROGRAMFILES%\Crawler\Toolbar
%PROGRAMFILES(x86)%\Crawler Toolbar
%PROGRAMFILES(x86)%\Crawler\Toolbar
%USERPROFILE%\AppData\LocalLow\Crawler Toolbar

URLs

Crawler Toolbar may call the following URLs:

crawler.com

Analysis Report

General information

Family Name: Crawler Toolbar
Signature status: Root Not Trusted

Known Samples

MD5: 68c9b7fdafcaa1e1664dcf3fca1d3e3e
SHA1: da6b9d8bd453a74f489d0c78df663ce15df0a574
SHA256: A99952D823173EAA1A403F0737DD3DC87AB5F1859525AFA9EA806F6625298ABE
File Size: 8.60 MB, 8604456 bytes
MD5: fd31c306bd8ec037753f32c5a34ca41b
SHA1: 6827ba65e0765ed8b83817f89b435508f0e30e75
SHA256: ACBD6FAC46D4E823E7D5E2ADE13EAD2DED6BAA32DE7976ACB960DBDD5FEF9A0B
File Size: 4.98 MB, 4979152 bytes
MD5: 20a9ef8a59603e8b4db1f1b10a516555
SHA1: 22367dbafabb0397cdb7ac925c1a8471a8628d8d
SHA256: 6DE730E732D91A94FC0C6A193EC2035E6B2E755753F9D8FFDC2A0A371A6D3BCE
File Size: 1.21 MB, 1211344 bytes
MD5: d659818120de412a8b66d9e22c944d76
SHA1: a6a27bd50d7f4c98a40aeac6a1349b988bb909bf
SHA256: 5FCE15F1D0ADA6064D7199A966EDF2ED52586D5FEC6C2BA450077906DD59DD97
File Size: 1.74 MB, 1741464 bytes
MD5: f04a816f3969f75f99cec8849b083610
SHA1: 44cce897d7207df337352ed91230e5803f73a302
SHA256: 973C681F216F65C6F5696E71D651C918C4AEC4FD833C151E849BD092AC08ED6A
File Size: 6.50 MB, 6499480 bytes
Show More
MD5: 9bec9bd815f344c4a8e38ee4ec5261ca
SHA1: 5855ce5f3d09acc35f73b8a39aa82fcadd8320b1
SHA256: DAF681014CE4668AF610D561F6457B0DDA789577107B53E593A11C8E73ADB56E
File Size: 4.81 MB, 4806672 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • SpywareTerminator PORTABLE
  • This installation was built with Inno Setup.
Company Name
  • Crawler, LLC
  • Crawler.com
  • Crawler.com
  • Crawler Inc.
  • tugashare.net
File Description
  • 24x7Help
  • Crawler Toolbar Browser Object
  • Spyware Terminator 2012 Setup
  • SpywareTerminator PORTABLE
  • Spyware Terminator Setup
File Version
  • 5.1.0.177
  • 3.0.0.74
  • 3.0.0.69
  • 3, 0, 0, 54
  • 2.2.0.355
  • 2.1.0.19
Internal Name SpywareTerminator PORTABLE
Legal Copyright
  • copyright Crawler
  • Copyright © 2006-2012 tugashare.net
  • copyright © Crawler.com
  • © Crawler, LLC
  • © Crawler.com
Original Filename
  • App24x7Help.exe
  • ctbr.dll
  • SpywareTerminator.exe
Product Name
  • 24x7Help
  • Crawler Toolbar
  • Spyware Terminator 2012
  • SpywareTerminator PORTABLE
Product Version
  • 5.1.0.177
  • 3.0.0.0
  • 3, 0, 0, 54
  • 2.1.0.0

Digital Signatures

Signer Root Status
Crawler, LLC VeriSign Class 3 Code Signing 2004 CA Root Not Trusted
Crawler, LLC VeriSign Class 3 Public Primary Certification Authority - G5 Root Not Trusted

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-22glm.tmp\6827ba65e0765ed8b83817f89b435508f0e30e75_0004979152.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-h39n5.tmp\da6b9d8bd453a74f489d0c78df663ce15df0a574_0008604456.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-h7i8f.tmp\_isetup\_regdll.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-h7i8f.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-h7i8f.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7_uploaderdark01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7_uploaderdark01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7_uploaderdark01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_left.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_left.png Generic Write,Read Attributes
Show More
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_left.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_right.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_right.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_right.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_x00.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_x00.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_x00.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_x01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_x01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_x01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_x02.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_x02.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7bubble_x02.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark001_settingsactive.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark001_settingsactive.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark001_settingsactive.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark001_settingsback.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark001_settingsback.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark001_settingsback.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark001_settingshover.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark001_settingshover.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark001_settingshover.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark_notabs_back00.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark_notabs_back00.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark_notabs_back00.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark_notabs_phoneicon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark_notabs_phoneicon.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7dark_notabs_phoneicon.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7logonew_dark01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7logonew_dark01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7logonew_dark01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7man_dark01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\24x7man_dark01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\24x7man_dark01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\arrowsmall.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\arrowsmall.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\arrowsmall.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\arrowsmallhot.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\arrowsmallhot.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\arrowsmallhot.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\bubble.xml Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\bubble.xml Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\bubble.xml Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\hardware_icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\hardware_icon.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\hardware_icon.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\hotinactivetableft.bmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\hotinactivetableft.bmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\hotinactivetableft.bmp Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\hotinactivetabright.bmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\hotinactivetabright.bmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\hotinactivetabright.bmp Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\mainimg_settingsdark01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\mainimg_settingsdark01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\mainimg_settingsdark01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\navigation_homeicon00_dark01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\navigation_homeicon00_dark01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\navigation_homeicon00_dark01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\navigation_homeicon01_dark01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\navigation_homeicon01_dark01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\navigation_homeicon01_dark01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\navigation_settingsicon00_dark01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\navigation_settingsicon00_dark01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\navigation_settingsicon00_dark01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\navigation_settingsicon01_dark01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\navigation_settingsicon01_dark01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\navigation_settingsicon01_dark01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\ok_icongreen01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\ok_icongreen01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\ok_icongreen01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\phones_icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\phones_icon.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\phones_icon.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\pushedinactivetableft.bmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\pushedinactivetableft.bmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\pushedinactivetableft.bmp Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\pushedinactivetabright.bmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\pushedinactivetabright.bmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\pushedinactivetabright.bmp Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\security_icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\security_icon.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\security_icon.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\skin.xml Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\skin.xml Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\skin.xml Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\software_icon.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\software_icon.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\software_icon.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\supportcheck01_arrow00.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\supportcheck01_arrow00.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\supportcheck01_arrow00.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\supportcheck01_arrow01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\supportcheck01_arrow01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\supportcheck01_arrow01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\warning_icon01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\warning_icon01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\warning_icon01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\warning_iconorange01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\warning_iconorange01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\warning_iconorange01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\warning_iconred01.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\warning_iconred01.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\warning_iconred01.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\whitetableft.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\whitetableft.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\whitetableft.png Synchronize,Write Attributes
c:\users\user\appdata\roaming\24x7 help\skin\whitetabright.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\24x7 help\skin\whitetabright.png Generic Write,Read Attributes
c:\users\user\appdata\roaming\24x7 help\skin\whitetabright.png Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\ctoolbar::afa_done 0 RegNtPreCreateKey
HKCU\software\24x7help::lang_id en RegNtPreCreateKey
HKCU\software\24x7help::techsupport_text Click here for instant access to technical support from the 24x7 Help RegNtPreCreateKey
HKCU\software\24x7help::representative_icon 1 RegNtPreCreateKey
HKLM\software\wow6432node\24x7help::last_senddata 46003.328733044 RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • SetWindowsHookEx
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
Network Winhttp
  • WinHttpOpen

Shell Command Execution

"C:\Users\Wojvgvpc\AppData\Local\Temp\is-H39N5.tmp\da6b9d8bd453a74f489d0c78df663ce15df0a574_0008604456.tmp" /SL5="$5020E,8103461,66048,c:\users\user\downloads\da6b9d8bd453a74f489d0c78df663ce15df0a574_0008604456"
"C:\Users\Ldojtqam\AppData\Local\Temp\is-22GLM.tmp\6827ba65e0765ed8b83817f89b435508f0e30e75_0004979152.tmp" /SL5="$8034A,4298571,161792,c:\users\user\downloads\6827ba65e0765ed8b83817f89b435508f0e30e75_0004979152"
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\22367dbafabb0397cdb7ac925c1a8471a8628d8d_0001211344.,LiQMAxHB

2 Comments

If only there were more clever people like you!

wendy c benton Reply

I would like to know how to remove crawler toolbar from my computer

Related Posts

Trending

Most Viewed

Loading...