Webalta.ru

By CagedTech in Browser Hijackers

Threat Scorecard

Ranking: 6,503
Threat Level: 50 % (Medium)
Infected Computers: 13,947
First Seen: September 4, 2015
Last Seen: September 27, 2023
OS(es) Affected: Windows

File System Details

Webalta.ru may create the following file(s):
# File Name MD5 Detections
1. Phoenix Browser Updater.exe 2cb69df073a7a59b3c146899b0d276a3 465
2. Phoenix Browser Updater.exe 68616de95f81b0e5e9ed5a1f57c22af6 1

Registry Details

Webalta.ru may create the following registry entry or registry entries:
CLSID
{0470D7FF-135D-3F24-B8D4-9D0FE702E9A0}
{08970B09-FF25-3A44-88FA-AC86E3801F26}
{0A128A92-CD88-3DFB-B2C9-58FC50265B20}
{0E5BE6F8-888B-30F2-B6C8-EE9D9D804FAF}
{1234BC65-3CEA-33D5-A997-1D9C0B57592E}
{182BFF93-5707-3859-B2B4-A4B1D6E00BDF}
{20873E9E-A6A3-317A-8396-EE8CF84E2BF8}
{233216C6-C0CA-34DE-BA7F-CA278546752B}
{261239AD-18F2-36E5-9951-52042D68DE99}
{27E75271-DAC5-3AE6-A7ED-58D6345C6795}
{2BD51F53-E561-3E26-B7A9-E429938754BD}
{2E27BDDD-2C1B-3669-93F7-01B551F8F265}
{320612EC-F3CC-3757-B9F7-5978FD2A96AA}
{37279556-3B33-3B42-91A9-95204738FA0A}
{39EB0175-2E75-3597-98A1-E74EB4DC2158}
{40534F3E-64C4-364F-916B-E18903B0A82E}
{4B213F8B-75DF-3BA0-AE52-9A2BE4333E3D}
{4C7933DF-30D3-3C46-8C11-1F684480BE2B}
{4D9EDF9A-DD36-39A7-B910-41236423A905}
{4FF4CA75-8FE9-36EA-87B6-356CD4B877DA}
{5079E326-36AE-3922-B41D-B77EAD941BEE}
{534ADAED-B709-3DE0-A98E-0E0998F1E58B}
{5895C4A2-A5E3-3E8E-9809-13402F2EFAF5}
{5BEF7B34-EDC3-3789-B34A-9C0113888678}
{5CE7A1C6-6C9B-3E47-84F3-39A48F3A286F}
{5CEB2741-44EA-3823-AED2-AA4173DF314F}
{5F89C642-AFB9-3825-AB5C-F1E895DDB732}
{62136DB4-1FA9-3888-AD49-9EDD2C3D799F}
{63B5001B-B6AD-34DA-81E6-46FB4CEE1365}
{6776FDC0-74A8-3152-9753-4CC33464D9ED}
{69840587-05C9-3D87-9362-5544FFD4DAC6}
{700DA8CD-91BE-3CB3-8978-FAB953D6039C}
{73F76B26-6F92-3D40-BD7B-9E6A5BA0CF3C}
{741CD0D5-BD5E-3512-95E2-3B1ECDBA4871}
{78023DF7-DE79-3012-A910-C77603A99A93}
{7D05217F-FFD5-389C-805C-37FCAD77620D}
{7E100778-5264-33FE-B32B-53B1AB3FD155}
{820DFA12-BEEA-33A2-B201-1FEA2600E148}
{928724BE-3044-3825-9F85-E290BF4E8EEE}
{972A845A-1407-3490-B742-092A30D18526}
{A1ECAAC7-AEE9-3553-915B-1067E29A441B}
{A55A0E2C-3E1E-3016-8E8D-B35731B1B271}
{AC870F3E-3964-3A34-98FE-76C8DBE324F3}
{B272BAD4-98BA-3F08-AA36-03EC0F80C2E4}
{B88C9B36-4BCE-3F7F-BB05-EDB9212E69DA}
{BE803610-98AE-3AA3-8DA8-DBFD7FE7C7DB}
{C1A1B616-9265-3A5B-A794-893FBA40B732}
{C2BD33A2-1E83-3CFE-A6C3-15AD4F6B7F03}
{C87005B2-BBBC-3430-9F57-6AF127CB6488}
{CB4F2FC1-FB1A-3A70-951E-3E1828E850DE}
{D3F57769-AE05-3FC7-9DA9-1DCAA23CA42C}
{D833B3D1-5577-3DDA-A890-3D72C6DF44E0}
{DCD347F0-451E-30DC-9909-D448A4EF6D6A}
{DD0C913B-BED9-3281-94A8-E05E00E71942}
{DDAB2CFC-56C6-31D1-8D16-C0F6EC1419F9}
{E16AB4E3-F446-30B2-A818-13777E54C97F}
{E441B25F-F9B1-39DE-8842-59BCD080B96D}
{E466B78E-16D5-32B4-AB63-216DC2CA00BC}
{E604BE0D-6185-33F0-84D1-32C31D96B1D3}
{EDCCA070-31C8-3434-9791-ABF8DF0B9C60}
{FA98442B-DD00-3776-AFF6-1B1D034CFF73}
{FD2852A0-C0DC-319E-A99D-10E7582DBE8F}
{FE704BF8-384B-44E1-8CF2-8DBEB3637A8A}
File name without path
http_new.webalta.ru_0.localstorage
http_new.webalta.ru_0.localstorage-journal
Twilight Pretty Search.lnk
Regexp file mask
%WINDIR%\System32\Tasks\Phoenix Browser Updater
SOFTWARE\Classes\nsWebAlta.WebAltaSearchBar
SOFTWARE\Classes\Record\{01AC0443-2749-375D-B447-3B4958CC90E0}
SOFTWARE\Classes\Record\{05E924A7-D321-3154-83B1-B33EE5B035E4}
SOFTWARE\Classes\Record\{0A2BBFC7-C5C3-3ABB-8594-6A3A85751CD3}
SOFTWARE\Classes\Record\{1514FB65-F250-3B1F-BCE8-E1AEB4DE74F7}
SOFTWARE\Classes\Record\{1A8D689D-67BA-371C-9BA1-8B630A0491D3}
SOFTWARE\Classes\Record\{1C6B6D75-F716-3A70-B2C2-ECE1319BDC5C}
SOFTWARE\Classes\Record\{1CF32E00-81AC-3608-9CA2-B8D15B0AEBF7}
SOFTWARE\Classes\Record\{1DC09608-80B8-39C3-BA88-773D896A997E}
SOFTWARE\Classes\Record\{21C5DD98-5B94-372E-AA18-730039587767}
SOFTWARE\Classes\Record\{2212F2F2-CADB-3F49-810E-7899895F3577}
SOFTWARE\Classes\Record\{2A09BFFB-A5D2-3B01-A1C0-48115F47ABDD}
SOFTWARE\Classes\Record\{311F5A23-ED76-313B-8EE7-3126C43EE8ED}
SOFTWARE\Classes\Record\{346BA8A1-4AB1-39B8-9E1C-0DBFBDB8E3BB}
SOFTWARE\Classes\Record\{365FD1AE-BECA-34E1-8191-6A7F21241115}
SOFTWARE\Classes\Record\{3C21CEA1-47B1-3912-AD59-17AD41ABAEA5}
SOFTWARE\Classes\Record\{3C896B19-1F93-3086-9600-C0DE9E0E51B2}
SOFTWARE\Classes\Record\{3D50D22C-ED49-3E0B-B351-1CEF0B6695C8}
SOFTWARE\Classes\Record\{3DCD5DD5-8100-32F5-BEA0-F9503BF6322C}
SOFTWARE\Classes\Record\{3DDBCD06-095E-3949-8B07-1340692EA6E7}
SOFTWARE\Classes\Record\{418E50E9-8DBC-3DE6-9D65-905C56D579B8}
SOFTWARE\Classes\Record\{442D331E-D6B7-33BB-8403-CB7BE4169E08}
SOFTWARE\Classes\Record\{455DC7A2-9CF0-3645-AE1B-A280264726D6}
SOFTWARE\Classes\Record\{51E07F38-5AC1-38DC-87A8-A93AED437C3A}
SOFTWARE\Classes\Record\{54B28B62-4536-36CA-AE14-220C25C1FB50}
SOFTWARE\Classes\Record\{563B82FC-5DB0-31F5-BF81-1B3A22A64DD9}
SOFTWARE\Classes\Record\{5C108E19-814F-3A17-BEB0-C0FDB705D8A1}
SOFTWARE\Classes\Record\{5F7CEEA5-EDB0-34FD-BA9C-1E5967B9EA27}
SOFTWARE\Classes\Record\{64DEA4BE-886D-3C28-AE28-508CCFB62745}
SOFTWARE\Classes\Record\{669F50BB-3476-3BE7-A8E8-35FB4FEC1F1C}
SOFTWARE\Classes\Record\{73AB20FC-452F-3E95-929D-7439F8CE5ABB}
SOFTWARE\Classes\Record\{744185C9-7A09-3666-8AE6-0266CBBF7FC1}
SOFTWARE\Classes\Record\{7529BD37-C1C0-3B76-B286-8AFAF4C8A588}
SOFTWARE\Classes\Record\{75AF2BA3-02FB-3D3A-A366-CBA70858DEEE}
SOFTWARE\Classes\Record\{776A1F1A-B67B-3205-A682-10C286E75F96}
SOFTWARE\Classes\Record\{7C44F6CB-6512-30DA-B445-5B29CB1307D4}
SOFTWARE\Classes\Record\{7DBF2A49-0953-32C7-8568-D760E6128D05}
SOFTWARE\Classes\Record\{7F8941DF-C627-3C7D-AFD9-7707CCF93F41}
SOFTWARE\Classes\Record\{85AC1C75-99D0-3CF2-9C25-F131EBEB44F3}
SOFTWARE\Classes\Record\{88274DA7-9AED-3DE2-930D-0C516BA46D11}
SOFTWARE\Classes\Record\{894B603E-1EA5-3CD9-817F-C2C592B5FF85}
SOFTWARE\Classes\Record\{8EA8E8FA-2E44-396B-A6F9-555A4DAAD986}
SOFTWARE\Classes\Record\{90B277E0-E21E-3AEF-9E59-A21DBD73FCAC}
SOFTWARE\Classes\Record\{93843D8F-C5AF-3BF3-BCCA-6204391CEA58}
SOFTWARE\Classes\Record\{A19497B5-93ED-357D-B543-3096DE7F202B}
SOFTWARE\Classes\Record\{A2725D98-345D-3C08-ADC5-D9BEBFCF14C0}
SOFTWARE\Classes\Record\{A90C9A59-48FA-3901-811D-AD33B98C711F}
SOFTWARE\Classes\Record\{B144CDA2-A24C-34CD-ABC1-3864315D2B85}
SOFTWARE\Classes\Record\{B859AE8C-0EAB-3804-9536-E1E973C63B1B}
SOFTWARE\Classes\Record\{BBEF582D-EA9E-3999-9B40-F1A7AA5AB160}
SOFTWARE\Classes\Record\{BE33840E-EBE5-38BF-935E-D8522C2A7AE1}
SOFTWARE\Classes\Record\{BF1D7BE1-9951-310F-91CE-AC3485F2192C}
SOFTWARE\Classes\Record\{C24F4A95-467E-32B1-8255-6C3902BC5487}
SOFTWARE\Classes\Record\{C33C3E4B-6394-3DE8-8234-968BC45FCB44}
SOFTWARE\Classes\Record\{C3597BAB-3217-3DC9-BEFC-DC3BC1D101AE}
SOFTWARE\Classes\Record\{C7E62130-89E4-3B47-A3EE-83679B588C9E}
SOFTWARE\Classes\Record\{C9257795-7ADB-3EB2-928C-CF9D8DCB4C2F}
SOFTWARE\Classes\Record\{CAE0A5E9-09DB-35EB-9ACE-12EB6FD9B69F}
SOFTWARE\Classes\Record\{CBE226DC-4F15-31E2-AAC3-7EE99B078887}
SOFTWARE\Classes\Record\{CE45E4DC-48C7-381D-AE7A-8E829176709F}
SOFTWARE\Classes\Record\{DCD1BDEB-A277-3D07-A773-3C48FB7968C8}
SOFTWARE\Classes\Record\{DDF1A36B-3E8D-3FDF-AC55-E718198513C6}
SOFTWARE\Classes\Record\{E4D46BA6-F8E8-3898-8D45-75B7DAE1DCC8}
SOFTWARE\Classes\Record\{E826A1E6-9CC0-3E96-AC4C-95B70EA7481D}
SOFTWARE\Classes\Record\{EA8CA002-F63B-30AB-907F-B599328C66A7}
SOFTWARE\Classes\Record\{ECE58F32-A667-3270-9255-4DDEA4B55856}
SOFTWARE\Classes\Record\{EDC4A2C8-9025-3914-9EE4-44F1BB90C3F4}
SOFTWARE\Classes\Record\{EE6007AA-5DE0-3A20-8710-A21EF0845EF6}
SOFTWARE\Classes\Record\{F05142A4-5EEB-3E00-8A8F-08A9554FC83D}
SOFTWARE\Classes\Record\{F12B263A-FA6C-32B5-93BB-FA219A5AC687}
SOFTWARE\Classes\Record\{F1DF3277-3713-3C71-BDD6-F4EDA0B22B9B}
SOFTWARE\Classes\Record\{F64FA539-24AB-34F9-8598-C61DAABB790E}
SOFTWARE\Classes\Record\{F7E4C398-D5B0-3C84-BF3F-90A4A346DD03}
SOFTWARE\Classes\Record\{F81B0DDE-66E4-3463-ABC0-C6ADD8469DCD}
SOFTWARE\Classes\Record\{FBA1BEBD-4B97-31D2-98A5-56AFFAC48B03}
Software\Microsoft\Internet Explorer\DOMStorage\new.webalta.ru
Software\Microsoft\Internet Explorer\DOMStorage\search.webalta.ru
Software\Microsoft\Internet Explorer\DOMStorage\webalta.ru
Software\Microsoft\Internet Explorer\SearchScopes\{61EB20A4-D4D5-4276-A2C9-DCCE8CE9F633}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Phoenix Browser Updater
Software\Webalta Toolbar

Directories

Webalta.ru may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\Webalta Toolbar
%Appdata%\WebAlta
%LOCALAPPDATA%\Pbrowserupd
%LOCALAPPDATA%\Phoenix Browser Updater
%LOCALAPPDATA%\UpdaterProBrowsers
%LOCALAPPDATA%\Webalta Toolbar
%PROGRAMFILES%\Twilight Tech\Pretty Search
%PROGRAMFILES(x86)%\Twilight Tech\Pretty Search
%USERPROFILE%\Local Settings\Application Data\Phoenix Browser Updater
%UserProfile%\Local Settings\Application Data\Pbrowserupd
%UserProfile%\Local Settings\Application Data\UpdaterProBrowsers
%UserProfile%\Local Settings\Application Data\Webalta Toolbar
%WINDIR%\assembly\GAC_MSIL\WebAltaSearch

Trending

Most Viewed

Loading...