Help - Search - Members - Calendar
Full Version: Anonymous Surf Toolbar & Spyware Remover 1.0
Malwarebytes Forum > Research Center > Newest Rogue Threats
fredvries
Anonymous Surf Toolbar & Spyware Remover 1.0

Downloadable here.

Virustotal results:
AntiVir - - DR/Softomate.J.22
Avast - - Win32:Adware-gen
BitDefender - - Adware.Softomate.DS
Ewido - - Adware.Softomate
Fortinet - - Adware/Softomate
F-Prot - - W32/Adware.QPF
NOD32v2 - - probably a variant of Win32/Adware.Toolbar.Eztracks
Sophos - - SearchIt
TheHacker - - Adware/ToolBar.ISearch.c
VBA32 - - AdWare.Win32.Softomate.j
Webwasher-Gateway - - Trojan.Softomate.J.22
MysteryFCM
Thats one heck of a hostname!

Homepage for this toolbar is actually;

snipeomatic.com

DD URL:
http://www.snipeomatic.com/tp/MMIP.exe
MysteryFCM
Interesting tidbits from the XML file inside the download.

CODE
        <WEBJUMP name="tbscmd_tbs_combo_007786" href="http://www.astrodownload.com/%combo&amp;.html" encoding="1252" parse_events="0"/>
        <WEBJUMP name="tbscmd_tbs_button_005588" href="http://www.astrodownload.com/%combo&amp;.html" encoding="1252" parse_events="0"/>


CODE
            <ITEM id="tbs_item_016597" caption="Snipeomatic.com homepage" visibility="1" command="redirect" href="http://www.snipeomatic.com" hint="Check for updates !"/>
            <ITEM id="tbs_item_023404" caption="Astrodownload.com Homepage" visibility="1" command="redirect" href="http://www.astrodownload.com"/>


Files:

QUOTE
*****************************************************
This file has been generated by QFScript v1.0 Revision 2
Date: 08-03-2006
Author: Steven Burn - Ur I.T. Mate Group owner
Homepage: www.it-mate.co.uk

File index for: snipeomatic_com
*****************************************************
DATE/TIME - MD5 - FILE/FOLDER
22/11/2007 10:36:40 7c6cf0b7c7d28aeca7ce575cf467a8b0 E:\Misc\Malware\snipeomatic_com
22/11/2007 10:37:34 873e402caaba6bacbbb2145d52aba357 E:\Misc\Malware\snipeomatic_com\MMIP.exe
22/11/2007 10:37:54 e4c237e5b43d303ab4604fa3b90badc6 E:\Misc\Malware\snipeomatic_com\MMIP
22/11/2007 10:37:54 1f19593f2d2bffe4ca63b3e7bda7989a E:\Misc\Malware\snipeomatic_com\MMIP\_€
22/11/2007 10:37:54 c9ae6e71a2f8680f8d375028e8e73aff E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006
31/10/2005 17:07:34 9d1d6e90b1c0c887a1ea9b47d6dd2029 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\snipetoolfull.dll
23/11/2006 14:54:16 9d4744de6dec798d794b4ec0778db39b E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\basis.xml
23/11/2006 14:48:52 6fea427519a3efaa86e227e5f6b3d389 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\version.txt
29/03/2005 14:56:00 8735350f659c1e332a002a267c170397 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\autofill.cfg
06/05/2005 16:57:00 f6065d57aa4d63dbe900483ceb64f2ee E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\autofill_plugin.dll
27/10/2005 14:52:06 6c3efe4e3111bcecf7b2a94ce4315f09 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\tracertsettings.html
07/12/1999 09:00:00 00a316d4d5e3e1b2a93b94262086770f E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\tracert.exe
02/11/2005 14:02:36 bace1e3da7f2738afdd6b462384da119 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\custombuttons_menulist.html
02/11/2005 14:02:36 6ba27da4a0a4462251f2c4ef93a8959c E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\custombuttons_list.html
18/03/2005 11:07:58 4c2c6eef48f23be4d38199624e805307 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\custombuttons_imageviewer.html
04/04/2005 12:07:14 fcbeb9863348deaa15c133302096a08d E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\custombuttons_additem.html
22/07/2002 11:05:04 fe259c38880f055e0c2b61a2d7fa6cd0 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\msvcrt.dll
28/08/2000 23:00:00 9cfd92c059157dae9628cc988cb81180 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\msvcp60.dll
02/11/2005 11:58:04 e78c2db5405c65a2e7b4927a9da539a3 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\MMIP.bmp
19/01/2005 14:39:20 420ca0b05b1b624e5dd2329deb4501b1 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\icons.bmp
16/08/2005 11:44:00 eb3847c1553168951692a920c2c65bc0 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\regdb.bin
16/08/2005 11:44:00 2ebf6126055fc199e461417cc7585385 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\fdb.bin
16/08/2005 11:44:00 5a2c4dfb2da736267a76d63e67f64383 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\descdb.bin
16/08/2005 11:44:00 8c4375eb2e94a3435f31cf28323615cc E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\spyrem.exe
23/11/2006 14:54:16 2bed6d316333beed5ea5b2d575130213 E:\Misc\Malware\snipeomatic_com\MMIP\_€\tbu05006\snipetoolfull.crc
*****************************************************
3 folders, 21 files
*****************************************************
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.