Win32.Trojan.Falsesign.Pdmp also known as Win32.Troj.Undef.(kcloud), MyWebSearch.J (v) (not malicious), Adware/WebSearch.
Malware Analysis of Win32.Trojan.Falsesign.Pdmp – NPV4STUB.DLL
Created files:
%Program Files%\DictionaryBoss\bar\1.bin\installKeys.js
%Program Files%\DictionaryBoss\bar\1.bin\LOGO.BMP
%Program Files%\DictionaryBoss\bar\1.bin\NPv4Stub.dll
%Program Files%\DictionaryBoss\bar\1.bin\T8EPMSUP.DLL
%Program Files%\DictionaryBoss\bar\1.bin\T8EXTEX.DLL
Autostart registry keys:
HKLM\Software\Classes\CLSID\{032416f0-0007-481b-9df8-9bcd1bf357f0}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4feedmg.dll”
HKLM\Software\Classes\CLSID\{23f28f6b-50a2-4327-9450-7d3d2f33daae}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4httpct.dll”
HKLM\Software\Classes\CLSID\{272143f8-3dbe-424c-949f-20acd11e5a6d}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4skin.dll”
HKLM\Software\Classes\CLSID\{3042df7a-e900-4389-9b94-923df0daa57e}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4bar.dll”
HKLM\Software\Classes\CLSID\{488c2712-1482-42ad-bc4d-681e5832f0c2}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4datact.dll”
HKLM\Software\Classes\CLSID\{58376892-60e7-4f63-aca0-0f686af554d6}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4SrcAs.dll”
HKLM\Software\Classes\CLSID\{5b610696-32b6-416c-bf5c-ca4f60a345dd}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4skin.dll”
HKLM\Software\Classes\CLSID\{6eb534fb-2001-45c4-b860-bc904865a379}\InprocServer32\: “C:\PROGRA~1\DICTIO~1\bar\1.bin\v4bar.dll”
HKLM\Software\Classes\CLSID\{715321aa-a1fc-4058-8ffa-668d687b6e32}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4radio.dll”
HKLM\Software\Classes\CLSID\{73a7cce6-ff3a-4c7f-9a3e-db9bd92be292}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4skin.dll”
HKLM\Software\Classes\CLSID\{82481cff-738f-4410-bffb-77595d5d9faa}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4radio.dll”
HKLM\Software\Classes\CLSID\{8eb0aaa0-2ffe-4326-8331-efe2d5d15ec7}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4bar.dll”
HKLM\Software\Classes\CLSID\{afed4702-7932-4426-aea4-9b248189c7a3}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4script.dll”
HKLM\Software\Classes\CLSID\{b160a11e-8cde-47dd-bc20-2d67921fe5c6}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4bprtct.dll”
HKLM\Software\Classes\CLSID\{b4ea8204-ee81-4f73-a240-ec4aeb8ad3de}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4mlbtn.dll”
HKLM\Software\Classes\CLSID\{da08805b-ba32-426b-ad14-ecac8235a8aa}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4dlghk.dll”
HKLM\Software\Classes\CLSID\{e001b32e-5acb-4cce-9910-2d379ce0a6d6}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4tpinst.dll”
HKLM\Software\Classes\CLSID\{eb2049f6-9dfa-4e51-b2a1-fc5a6e596c80}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\T8HTML.DLL”
HKLM\Software\Classes\CLSID\{F9A402FD-82C8-4743-991E-BC77E62DA0E5}\InprocServer32\: “%Program Files%\DictionaryBoss\bar\1.bin\v4htmlmu.dll”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\DictionaryBoss Home Page Guard 32 bit: “”C:\PROGRA~1\DICTIO~1\bar\1.bin\AppIntegrator.exe””
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\DictionaryBoss Search Scope Monitor: “”C:\PROGRA~1\DICTIO~1\bar\1.bin\v4srchmn.exe” /m=2 /w /h”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\DictionaryBoss Browser Plugin Loader: “C:\PROGRA~1\DICTIO~1\bar\1.bin\v4brmon.exe”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DictionaryBossbar Uninstall Firefox\UninstallString: “rundll32 “%Program Files%\DictionaryBoss\bar\1.bin\v4Bar.dll”,O mindsparktoolbarkey=”DictionaryBoss” uninstalltype=FF”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DictionaryBossbar Uninstall Internet Explorer\DisplayName: “DictionaryBoss Internet Explorer Toolbar”
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DictionaryBossbar Uninstall Internet Explorer\UninstallString: “rundll32 “%Program Files%\DictionaryBoss\bar\1.bin\v4Bar.dll”,O mindsparktoolbarkey=”DictionaryBoss” uninstalltype=IE”
HKLM\Software\DictionaryBoss\bar\UninstallString: “”%Program Files%\DictionaryBoss\bar\1.bin\v4highin.exe” v4bar.dll,O uninstalltype=IE”
HKLM\System\CurrentControlSet\Services\DictionaryBossService\ImagePath: “C:\PROGRA~1\DICTIO~1\bar\1.bin\v4barsvc.exe”
HKLM\System\CurrentControlSet\Services\DictionaryBossService\DisplayName: “DictionaryBossService”
Detected by UnHackMe:
NPV4STUB.DLL
Default location: %PROGRAM FILES%\DICTIONARYBOSS\BAR\1.BIN\NPV4STUB.DLL
Dropper hash(md5): b2c431a4712964fce0448fbe40121e48