1. Symantec/
  2. Security Response/
  3. Adware.Exactbar

Adware.Exactbar

Updated:
February 7, 2007 1:53:02 PM
Type:
Adware
Version:
1.0
Publisher:
mail.com
Risk Impact:
Low
Systems Affected:
Windows
When the program is executed, it creates the following files:

  • %ProgramFiles%\eXact\INSTALL.LOG
  • %ProgramFiles%\eXact\mg03025.bmp
  • %ProgramFiles%\eXact\mg03025.xml
  • %ProgramFiles%\eXact\mg03025a.rar
  • %ProgramFiles%\eXact\mg03026.bmp
  • %ProgramFiles%\eXact\mg03026.xml
  • %ProgramFiles%\eXact\mg03026a.rar
  • %ProgramFiles%\eXact\mg03027.bmp
  • %ProgramFiles%\eXact\mg03027.xml
  • %ProgramFiles%\eXact\mg03027a.rar
  • %ProgramFiles%\eXact\mg03028.bmp
  • %ProgramFiles%\eXact\mg03028.xml
  • %ProgramFiles%\eXact\mg03028a.rar
  • %ProgramFiles%\eXact\mg03030.bmp
  • %ProgramFiles%\eXact\mg03030.xml
  • %ProgramFiles%\eXact\mg03030a.rar
  • %ProgramFiles%\eXact\mg03031.bmp
  • %ProgramFiles%\eXact\mg03031.xml
  • %ProgramFiles%\eXact\mg03031a.rar
  • %ProgramFiles%\eXact\mg03032.bmp
  • %ProgramFiles%\eXact\mg03032.xml
  • %ProgramFiles%\eXact\mg03032a.rar
  • %ProgramFiles%\eXact\mg03033.bmp
  • %ProgramFiles%\eXact\mg03033.xml
  • %ProgramFiles%\eXact\mg03033a.rar
  • %ProgramFiles%\eXact\mg03034.bmp
  • %ProgramFiles%\eXact\mg03034.xml
  • %ProgramFiles%\eXact\mg03034a.rar
  • %ProgramFiles%\eXact\mg10000.bmp
  • %ProgramFiles%\eXact\mg10000.xml
  • %ProgramFiles%\eXact\mg10000a.rar
  • %ProgramFiles%\eXact\msg_log.txt
  • %ProgramFiles%\eXact\popularlinks.reg
  • %ProgramFiles%\eXact\exactToolbar.dll
  • %ProgramFiles%\eXact\buttons.xml
  • %ProgramFiles%\eXact\exactupdateguid.txt

Next, the program creates the following registry subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\exact
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eXact Search Bar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{F9765480-72D1-11D4-A75A-004F-49045A87}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9765480-72D1-11D4-A75A-004F-49045A87}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{224530A0-4AEE-9C0F-54AC1B533211}
HKEY_USERS\.DEFAULT\Software\eXact

The program also creates the following registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\"224530A0-4AEE-9C0F-54AC1B533211" = "eXact Toolbar"

The program may connect to the following site for updates:
[http://]www.exactsearchbar.com[REMOVED]

These updates are downloaded to the following location:
%ProgramFiles%\eXact
Summary| Technical Details| Removal

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube