1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. HTTP Searchtool Activity

HTTP Searchtool Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects Adware.Searchtool communicating and requesting information from its controlling server.

Additional Information

When the program is executed, it creates the following folder:
C:\WINDOWS\system32\SearchTool

The program then creates the following files:

* %UserProfile%\Application Data\inifile41.ini
* %UserProfile%\Application Data\internaldb1942.dat
* %UserProfile%\Application Data\internaldb4827.dat
* %UserProfile%\Application Data\internaldb5436.dat
* %UserProfile%\Desktop\FREE IPOD NANO!.lnk
* %System%\SearchTool\ns[random chars].dll
* %System%\SearchTool\SearchTool.dll
* %System%\SearchTool\uninstallSE.exe
* %Windir%\wininit.ini


The program may also periodically drop one of the following files on to the desktop:

* %UserProfile%\Desktop\FREE IPOD NANO!.lnk
* %UserProfile%\Desktop\FREE RAZR (tm) PHONE !!.lnk


Next, the program creates the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\VersionIndependentProgID\"Default" = "fis.amo"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\TypeLib\"Default" = "{B025A407-444A-483A-8A26-93E3E468AB21}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\ProgID\"Default" = "fis.amo.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\InprocServer32\"Default" = "%System%\SearchTool\nsg5.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\InprocServer32\"ThreadingModel" = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\"Default" = "amo Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\VersionIndependentProgID\"Default" = "fis.ohb"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\TypeLib\"Default" = "{B025A407-444A-483A-8A26-93E3E468AB21}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\ProgID\"Default" = "fis.ohb.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\InprocServer32\"Default" = "%System%\SearchTool\nsg5.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\InprocServer32\"ThreadingModel" = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\"Default" = "ohb Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85E0B171-04FA-11D1-B7DA-00A0C90348D7}\InprocServer32\"Default" = "%System%\SearchTool\SearchTool.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85E0B171-04FA-11D1-B7DA-00A0C90348D7}\InprocServer32\"ThreadingModel" = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85E0B171-04FA-11D1-B7DA-00A0C90348D7}\"Default" = "Search Tool"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\VersionIndependentProgID\"Default" = "fis.momo"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\TypeLib\"Default" = "{B025A407-444A-483A-8A26-93E3E468AB21}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\ProgID\"Default" = "fis.momo.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\InprocServer32\"Default" = "%System%\SearchTool\nsg5.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\InprocServer32\"ThreadingModel" = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\"Default" = "momo Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo\CurVer\"Default" = "fis.amo.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo\CLSID\"Default" = "{5015BF9D-173C-474B-9AF3-77D4D23A4135}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo\"Default" = "amo Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo.1\CLSID\"Default" = "{5015BF9D-173C-474B-9AF3-77D4D23A4135}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo.1\"Default" = "amo Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo\CurVer\"Default" = "fis.momo.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo\CLSID\"Default" = "{92C3F342-45DA-4511-853A-B3836AAFF5F5}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo\"Default" = "momo Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo.1\CLSID\"Default" = "{92C3F342-45DA-4511-853A-B3836AAFF5F5}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo.1\"Default" = "momo Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb\CurVer\"Default" = "fis.ohb.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb\CLSID\"Default" = "{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb\"Default" = "ohb Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb.1\CLSID\"Default" = "{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb.1\"Default" = "ohb Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\"Default" = "ohb"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchEnhancer\"DisplayName" = "Search Enhancer"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchEnhancer\"UninstallString" = "%System%\SearchTool\uninstallSE.exe"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\iexplore\"Type" = " 3"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\iexplore\"Count" = "1"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\iexplore\"Time" = "D7 07 03 00 04 00 16 00 0A 00 31 00 07 00 8B 02"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"d" = "wonder-context.com"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"shared-ver" = "0"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"shared" = "%UserProfile%\Application Data\internaldb1942.dat"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"global" = "439252626-cd94679a14fc7304a4ec53ea389f1b7b"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"n" = "F"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"contenttool-reg" = "FFF7EA335F8F1AE818529D33156C3703"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"data" = "%UserProfile%\Application Data\internaldb4827.dat"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"icondrops-ver" = "7DA"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"icondrops" = "%UserProfile%\Application Data\internaldb5436.dat"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"explorerbar" = "18"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"contenttool" = "15"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"last" = "0x46025E97"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"explorerbar-reg" = "47411C5782217A10262083DDD1653AE1"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7\"lastf" = "0x46025F26"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\SearchEnhancer\"DllName" = "%System%\SearchTool\nsg5.dll"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\SearchEnhancer\"RegKeyName" = "nsg5.dll"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Softwarensg5.dll\"ccat" = "1"
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Softwarensg5.dll\"ffafid" = "1111"

The program also creates the following registry subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5015BF9D-173C-474B-9AF3-77D4D23A4135}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85E0B171-04FA-11D1-B7DA-00A0C90348D7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85E0B171-04FA-11D1-B7DA-00A0C90348D7}\Implemented Categories
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85E0B171-04FA-11D1-B7DA-00A0C90348D7}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85E0B171-04FA-11D1-B7DA-00A0C90348D7}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92C3F342-45DA-4511-853A-B3836AAFF5F5}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.amo.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.momo.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fis.ohb.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchEnhancer
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5ED7D3DE-6DBE-4516-8712-01B1B64B7057}\iexplore
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\884E079B2F78C10334A79B210E9EA2B7
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software\SearchEnhancer
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Softwarensg5.dll

This program redirects browser error pages to the following location:
[http://]www.serverunavailab1e.com

It periodically drops a .lnk file on to the desktop, such as:

* FREE IPOD NANO!.lnk

[http://]GET_YOUR_FREE_IPOD_NANO_BY_CLICKING.directory.453searches.com[REMOVED]

* FREE PLATINUM CARD.lnk

[http://]APPLY_FOR_A_CREDIT_CARD_HERE.directory.453searches.com[REMOVED]

* FREE MASTERCARD.lnk

[http://]apply_for_a_credit_card_here2.directory.453searches.com[REMOVED]

* FREE POKER TOURNAMENT.lnk

[http://]ENTER_FREE_TEN_THOUSAND_DOLLAR_TOURNEY_HERE.directory.453searches.com[REMOVED]

* FREE DIGITAL CAMERA.lnk

[http://]get_a_free_sony_digital_camera_here.directory.453searches.com[REMOVED]

* FREE LAPTOP.lnk

[http://]get_your_free_hp_laptop_here.directory.453searches.com[REMOVED]

* $1 000 GIFT CARD.lnk

[http://]get_your_free_ikea_giftcard_here.directory.453searches.com[REMOVED]

* FREE RAZR (tm) PHONE !!.lnk

[http://]GET_YOUR_FREE_MOTOROLLA_RAZR_BY_CLICKING.directory.453searches.com[REMOVED]

* RATE MY BODY ;).lnk

[http://]PERSONALS_AND_DATING_SITE.directory.453searches.com[REMOVED]

* FREE RING TONE.lnk

[http://]RINGTONESFORYOURCELLPHONEFREEHERE.directory.453searches.com[REMOVED]

The program may download the following icon files to be used for the above links:

* [http://]icons.453searches.com/[REMOVED]
* [http://]icons.453searches.com/9.i[REMOVED]
* [http://]ate>http://icons.453searches.com/16.[REMOVED]
* [http://]ate>http://icons.453searches.com/12.[REMOVED]
* [http://]ate>http://icons.453searches.com/13.[REMOVED]
* [http://]ate>http://icons.453searches.com/10.[REMOVED]
* [http://]ate>http://icons.453searches.com/17.[REMOVED]
* [http://]ate>http://icons.453searches.com/[REMOVED]
* [http://]icons.453searches.com/11.[REMOVED]
* [http://]icons.453searches.com/15.[REMOVED]

Affected

  • Windows 2000
  • Windows 95
  • Windows 98
  • Windows Me
  • Windows NT
  • Windows Server 2003
  • Windows XP

Response

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan.
4. Delete any values added to the registry.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube