Adware.STIEBar

Printer Friendly Page

Updated: February 13, 2007 11:44:55 AM
Type: Adware
Version: 1.0
Publisher: 0Cat Yellow Pages
Risk Impact: Low
File Names: STIEBar2.dll
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP


When Adware.STIEBar is installed, it performs the following actions:

  1. Creates the following files:

    • C:\Program Files\0CAT YellowPages\stiea.dat
    • C:\Program Files\0CAT YellowPages\STIEBar2.dll
    • C:\Program Files\0CAT YellowPages\sties.dat
    • C:\Program Files\0CAT YellowPages\tlbtn.ico
    • C:\Program Files\0CAT YellowPages\tlbtnhot.ico
    • C:\Program Files\0CAT YellowPages\uninst.exe

      Note: %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.

  2. Creates the following registry keys:

    HKEY_CLASSES_ROOT\CLSID\{13B5C450-C43E-4531-B12E-97779B346B5F}
    HKEY_CLASSES_ROOT\CLSID\{679695BC-A811-4A9D-8CDF-BA8C795F261A}
    HKEY_CLASSES_ROOT\CLSID\{D797AD6C-6447-4DB4-91D0-090344408E72}
    HKEY_CLASSES_ROOT\Interface\{38493F7F-2922-4C6C-9A9A-8DA2C940D0EE}
    HKEY_CLASSES_ROOT\Interface\{AC50DF8B-B632-42C0-857C-2A9B7C509BFB}
    HKEY_CLASSES_ROOT\Interface\{D008677D-5759-403B-B09B-724B46C22E76}
    HKEY_CLASSES_ROOT\STIEbar.STIEbarBand
    HKEY_CLASSES_ROOT\STIEbar.STIEbarBand.1
    HKEY_CLASSES_ROOT\STIEbar.STIEbarBHO
    HKEY_CLASSES_ROOT\STIEbar.STIEbarBHO.1
    HKEY_CLASSES_ROOT\STIEbar.STIEbarButton
    HKEY_CLASSES_ROOT\STIEbar.STIEbarButton.1
    HKEY_CLASSES_ROOT\TypeLib\{3277CD27-4001-4EF8-9D96-C6CA745AC2F9}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{47FE5D70-9AA2-40F1-9C6B-12A255F085EA}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D797AD6C-6447-4DB4-91D0-090344408E72}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\0CAT YellowPages
    HKEY_LOCAL_MACHINE\SOFTWARE\STIEBar


  3. Adds the toolbar to Internet Explorer

  4. Connects to [http://]69.50.160.98/[REMOVED].

Search by name
Example: W32.Beagle.AG@mm
Limited Time Offers! Save up to 50%
Windows Vista Security