A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #15678  by erikloman
 Wed Sep 19, 2012 8:18 am
Looking for the following Adware:

1. A dropper that is installing adware that is using BrowserSeekIEHelper.DNSGuard component. Also known as Clkads.com adware.
2. Searchqu dropper

Also interested in other adwares installing browser toolbars.
 #15685  by CloneRanger
 Thu Sep 20, 2012 7:20 am
@ erikloman

Hi, here's the Searchqu dropper you wanted.

Searchqu - iLivid/Bandoo Media Inc = Free Download Manager -http://www.ilivid.com

Destination IP 80.150.193.192:80 Destination DNS download.cdn.ilivid.com

PW = infected

I chose Custom & i did NOT change my search page !
iliv.gif
iliv.gif (13.83 KiB) Viewed 201 times
Regards
Attachments
(603.24 KiB) Downloaded 72 times