
E2Give description:
E2Give Category:Adware,BHO,Downloader
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
BHO (Browser Helper Object) Trojan.
The BHO waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
The method of network transport used by the attacker makes this Trojan unique.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.
Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into
the data section of an ICMP ping packet." explained the company.
Trojans-downloaders downloads and installs new malware or adware on the computer.
Detection E2Give :
E2Give Files:
[%PROFILE_TEMP%]\ei.exe
[%SYSTEM%]\data.~
[%SYSTEM%]\key.~
[%SYSTEM%]\keylog.~
[%SYSTEM%]\log.~
[%WINDOWS%]\pi1_36.exe
[%PROGRAM_FILES%]\spellaroo\spellaroo\polarspellchecker.dll
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellaroo.exe
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellaroodlg.dll
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellarooh.dll
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellaroor.dll
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellhk.dll
[%SYSTEM%]\iebhos.dll
[%SYSTEM%]\prutqct.exe
[%WINDOWS%]\downloaded program files\ugo20.exe
[%WINDOWS%]\syslasp.dll
[%WINDOWS%]\system\iebhos.dll
[%PROFILE_TEMP%]\ei.exe
[%SYSTEM%]\data.~
[%SYSTEM%]\key.~
[%SYSTEM%]\keylog.~
[%SYSTEM%]\log.~
[%WINDOWS%]\pi1_36.exe
[%PROGRAM_FILES%]\spellaroo\spellaroo\polarspellchecker.dll
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellaroo.exe
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellaroodlg.dll
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellarooh.dll
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellaroor.dll
[%PROGRAM_FILES%]\spellaroo\spellaroo\spellhk.dll
[%SYSTEM%]\iebhos.dll
[%SYSTEM%]\prutqct.exe
[%WINDOWS%]\downloaded program files\ugo20.exe
[%WINDOWS%]\syslasp.dll
[%WINDOWS%]\system\iebhos.dll
E2Give Folders:
[%PROGRAM_FILES%]\e2g
[%PROGRAM_FILES%]\spellaroo\spellaroo\dictionaries
E2Give Registry Keys:
HKEY_CURRENT_USER\software\ptech
HKEY_LOCAL_MACHINE\software\classes\appid\{3b99f202-145a-4e5a-ac7b-88a36910bf5e}
HKEY_LOCAL_MACHINE\software\classes\clsid\{3643abc2-21bf-46b9-b230-f247db0c6fd6}
HKEY_LOCAL_MACHINE\software\classes\iebhos.control.1\clsid
HKEY_LOCAL_MACHINE\software\classes\iebhos.control\clsid
HKEY_LOCAL_MACHINE\software\e2g
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6}
HKEY_CLASSES_ROOT\clsid\{e9041f85-3c18-4a7e-a29d-e24f84b79bf1}
HKEY_CLASSES_ROOT\typelib\{3643abc2-21bf-46b9-b230-f247db0c6fd6}
HKEY_CLASSES_ROOT\typelib\{e9041f85-3c18-4a7e-a29d-e24f84b79bf1}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3643abc2-21bf-46b9-b230-f247db0c6fd6}
E2Give Registry Values:
HKEY_CLASSES_ROOT\clsid\{3643abc2-21bf-46b9-b230-f247db0c6fd6}
HKEY_CLASSES_ROOT\clsid\{3643abc2-21bf-46b9-b230-f247db0c6fd6}\inprocserver32
HKEY_LOCAL_MACHINE\software\classes\appid\iebhos.dll
HKEY_CLASSES_ROOT\appid\iebhos.dll
HKEY_CLASSES_ROOT\clsid\{3643abc2-21bf-46b9-b230-f247db0c6fd6}
HKEY_CLASSES_ROOT\clsid\{3643abc2-21bf-46b9-b230-f247db0c6fd6}
HKEY_CLASSES_ROOT\clsid\{3643abc2-21bf-46b9-b230-f247db0c6fd6}\inprocserver32
HKEY_CURRENT_USER\software\spellaroo\spellaroo
HKEY_CURRENT_USER\software\spellaroo\spellaroo
HKEY_CURRENT_USER\software\spellaroo\spellaroo
HKEY_CURRENT_USER\software\spellaroo\spellaroo
HKEY_CURRENT_USER\software\spellaroo\spellaroo
HKEY_CURRENT_USER\software\spellaroo\spellaroo
HKEY_CURRENT_USER\software\spellaroo\spellaroo\dictionaries\custom
HKEY_CURRENT_USER\software\spellaroo\spellaroo\dictionaries\main
HKEY_LOCAL_MACHINE\software\classes\appid\iebhos.dll
HKEY_LOCAL_MACHINE\software\microsoft\eventsystem\{26c409cc-ae86-11d1-b616-00805fc79216}\subscriptions\{2c87cff4-8f09-4d4c-8949-5231dbebd542}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\e2g plugin
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\e2g plugin
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\e2g plugin
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\e2g plugin
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\e2g plugin
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\e2g plugin
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\spellaroo!_is1
Removing E2Give:
you can run
trial version of ExterminateIt, or remove E2Give manually.
To completely manually remove E2Give malware from your computer, you need to delete the Windows registry keys and registry values, the files and folders associated with E2Give.
Read also:
TrojanDownloader.Win32.PurityScan Downloader Information
Remove Porn Adware
CrazyMouse.joke Trojan Cleaner
BookmarkExpress Adware Symptoms