DotCom Toolbar details

  • Description

    From the doc :"Dotcomtoolbar is a program that hooks URLs, sends them to a predetermined Web site, and then redirects the URL to the correct location. The Web site can log a user's IP address and visited URLs."

  • Alias

    Spyware.DotcomtoolbarSpyware/DCToolbar [Panda]Trojan Horse [Panda]TrojanClicker.Win32.DotComToolBar.b [Kaspersky]TrojanClicker.Win32.DotComToolBar.c [Kaspersky]TrojanClicker.Win32.DotComToolBar.d [Kaspersky]

  • Exe

    redirect2.exeredirect4.exeredirect5.exeWindowsedirect7.exe

  • Dll

    Windowssystemdata.dllWindowssystem32data.dll

  • Registry

    HKEY_LOCAL_MACHINEsoftwareclassesclsid{29dd1ea6-1fda-44a4-b083-c9900547bc48}HKEY_LOCAL_MACHINEsoftwareclassesclsid{fc2493d6-a673-49fe-a2ee-efe03e95c27c}HKEY_LOCAL_MACHINEsoftwareclassesgorsdn.contextitemHKEY_LOCAL_MACHINEsoftwareclassesgorsdn.contextitem.1HKEY_LOCAL_MACHINEsoftwareclassesgorsdn.contextitemclsidHKEY_LOCAL_MACHINEsoftwareclassesgorsdn.contextitemcurverHKEY_LOCAL_MACHINEsoftwareclassesinterface{7c479d09-1280-41d2-945f-2377736b8cf7}HKEY_LOCAL_MACHINEsoftwareclassesinterface{eaf2ccee-21a1-4203-9f36-4929fd104d43}HKEY_LOCAL_MACHINEsoftwareclassespugi.pugiobjHKEY_LOCAL_MACHINEsoftwareclassespugi.pugiobj.1HKEY_LOCAL_MACHINEsoftwareclassespugi.pugiobjclsidHKEY_LOCAL_MACHINEsoftwareclassespugi.pugiobjcurverHKEY_LOCAL_MACHINEsoftwareclasses oolband.hitsHKEY_LOCAL_MACHINEsoftwareclasses oolband.hits.1HKEY_LOCAL_MACHINEsoftwareclasses oolband.hitsclsidHKEY_LOCAL_MACHINEsoftwareclasses oolband.hitscurverHKEY_LOCAL_MACHINEsoftwaremicrosoftcode store databasedistribution units{5f1abcdb-a875-46c1-8345-b72a4567e483}HKEY_LOCAL_MACHINEsoftwaremicrosoftcode store databasedistribution units{5f1abcdb-a875-46c1-8345-b72a4567e483}installerHKEY_LOCAL_MACHINEsoftwaremicrosoftcode store databasedistribution units{5f1abcdb-a875-46c1-8345-b72a4567e483}systemcomponentHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionapp managementarpcachedotcomtoolbardotcomtoolbarchangedHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionapp managementarpcachedotcomtoolbardotcomtoolbarslowinfocacheHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionmoduleusagec:/windows/downloaded program files/conflict.1/toolbar_nieuw14.dll.ownerHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionmoduleusagec:/windows/downloaded program files/conflict.1/toolbar_nieuw14.dll{5f1abcdb-a875-46c1-8345-b72a4567e483}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionmoduleusagec:/windows/downloaded program files/toolbar_nieuw14.dll.ownerHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionmoduleusagec:/windows/downloaded program files/toolbar_nieuw14.dll{5f1abcdb-a875-46c1-8345-b72a4567e483}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstalldotcomtoolbardotcomtoolbardisplaynameHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstalldotcomtoolbardotcomtoolbaruninstallstring