EUniverse Updater Browser Hijacker Information
|| EUniverse Updater
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge.
||EUniverse is an adware program that runs at startup, generates popup ads, and performs a number of spyware related functions such as transmitting personal information and hijacking Internet Explorer.
Beside generating adware passed popup adverts, EUniverse performs the following spyware functions without the userís consent. EUniverse monitors web sites visited, so that ads may be targeted; EUniverse hijacks the hosts file and redirects Netscape searches to incredifind.com; EUniverse hijacks error pages and address bar searches to incredifind.com, which is then redirected to sirsearch.com; EUniverse adds an Internet Explorer toolbar providing a search field directed to sirsearch.com.
EUniverse Updater connects to update.thunderdownloads.com (126.96.36.199) looking for updates.
EUniverse delivers ads, software and informational messages by tracking your interests and behavior patterns based on computer usage. EUniverse selects advertisements based on a number of factors including URLs associated with web pages you visit, search terms you input into search engines, HTML content you view, your IP address, and your local zip code. Often, advertisements are from websites that are competitive to web sites that you are viewing or have recently viewed. Advertisements are delivered to your computer screen and cannot be independently removed from your computer. You are unable to control or delete Advertisements by deleting cookies or unbundling the software. ... Advertisements are delivered to your computer screen by: ∑ Pop-Up Windows ∑ Pop-Up Slider Windows ∑ Embedded Ads ∑ Desktop icons and installation files that may be placed on your computer for you to link to other products and services.
EUniverse is distributed with software originating at eUniverse sites, including thunderdownloads.com, myfreecursors.com, cursorzone.com, crazymates.com, and mycoolscreen.com. EUniverse is also installed by FavoriteMan, desktop playmates, some MP3 Players, screensavers, online games, and shopping tools. EUniverse is also bundled with the PowerSearch Toolbar. Bundled with the new MapQuest toolbar from http://mapquest.com, and bundled with the RealPlayer Search Bar.
The EUniverse.PerfectNav variant is bundled with the Free Ad Supported version of Kazaa Media Desktop 2.6. and also likely to be found in software supplied by eUniverse sites, such as thunderdownloads.com, myfreecursors.com, cursorzone.com and mycoolscreen.com.
||process: delupdat.exe: MD5 Hash: ac168b09cdba93d98ac...
process: sui.exe: MD5 Hash: b1afb0317320a145f28...
process: wupdater.exe: MD5 Hash: 273bcf5f87c39df769a...
process: tipb.exe: MD5 Hash: ...
process: updaterinstall_112.exe: MD5 Hash: 983b4529fbe28efce77...
process: searchupgrader.exe: MD5 Hash: b551ec7dbd87b173c48...
process: searchupgrader.exe: MD5 Hash: 441d14b86f145357229...
process: SearchUpgrader.exe: MD5 Hash: ...
process: searchupgrader.exe: MD5 Hash: d964700b1e20b1992b2...
process: 246765-ventura-hot.exe: MD5 Hash: b628046e1231721908b...
process: searchupgrader.exe: MD5 Hash: 87a51c6138c353c8ef8...
process: searchupgrader.exe: MD5 Hash: ab5cd7a7455ee5b1fe5...
process: searchupgrader.exe: MD5 Hash: 903911cd0bf5fdeed14..
||Browser Hijacker - Adware is generally software that displays advertisements. Some advertisers may covertly install adware on your system and generate a stream of unsolicited advertisements that can clutter your desktop and affect your productivity. The advertisements may also contain pornographic or other material that you might find inappropriate. The extra processing required to track you or to display advertisements can tax your computer and hurt your system performance.
Top Browser Hijacker Visited Pages:
SuperSpider - Alias: Network Security Guard, Melcosoft - 570 visits
Tubby - Alias: MakeMeSearch, CoolWebSearch.Tubby, Spyware.Arau, Trojan.Win32.StartPage.ih, Trojan.StartPage-FJ - 211 visits
Spyass.com - 123 visits
SecurityToolbar.DesktopScam - 122 visits
EUniverse Updater - Alias: WUpdate, eUniverse Flowgo toolbar, eUniverse SirSearch, SearchUpgrader, Search Upgrader - 120 visits
CoolWebSearch - Alias: CWS, Cool Web Serach, CoolWwwSearch - 115 visits
CrackSpider - Alias: Troj/Favadd-D - 106 visits
Trojan.StartPage - Alias: SearchCentral - 86 visits
Paytime - 84 visits
IEHijacker.Q - 80 visits
Random Browser Hijacker Pages:
ActualNames - Alias: AdvSearch, SearchPike, BrowseProxy
InstaFinder - Alias: Vista
SearchCentral - Alias: SearchCentral.cc, SearchCentral.update.js