Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:Adware/BHO.S
Date discovered:20/07/2012
Type:Adware/Spyware
In the wild:No
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low
File size:614912 Bytes
MD5 checksum:e8b6a9f0c48fd30c5cf7757af1484cb4
VDF version:7.11.36.246 - Friday, July 20, 2012
IVDF version:7.11.36.246 - Friday, July 20, 2012

 General Method of propagation:
   • No own spreading routine


Platforms / OS:
   • Windows XP
   • Windows 2003
    Windows Vista
    Windows Server 2008
    Windows 7
   • Registry modification

 Registry The following registry keys are added:

HKCR\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}\
   • (Default)="loadtbs"

HKCR\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}\InProcServer32\
   • (Default)="%HOME%
   • \Appdata\loadtbs\toolbar.dll"

HKCR\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}\InProcServer32\
   • ThreadingModel="Apartment"

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
   • {DFEFCDEE-CF1A-4FC8-88AD-129872198372}=""

Description inserted by Jan-Eric Herting on Sunday, July 22, 2012
Description updated by Jan-Eric Herting on Sunday, July 22, 2012

Back . . . .