Home Articles Spyware Research Support Scan Now Purchase F.A.Q.

Downloader/UCSearch

Alias: IE Spy2, UCSearch

Description: Such simple but effective spyware is used by hackers for getting remote access to user's computer. The principle is quite simple: a "server" secretly installs on to your machine and the hacker connects through a "client" on his computer. This is the basic function of a RAT, but it also can have several other functions, which depend on the interests of the attacker. Originated in November 2002. The author is PyroBruno.

Threat type:

Downloader - A Downloader is a software application or part of the program which is designed to retrieve (download) and install additional files from the Internet. Malware programs often include Downloaders which allow the Malware to continually update themselves, thereby eluding detection.


Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy.

Detection:
SpyNoMore detects Downloader/UCSearch: Yes

Threat risk: High Risk
SpyNoMore AntiSpyware: Remove UCSearch, UCSearch Remover
Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans.

Symptoms:

Downloader/UCSearch Signature Details: The following information includes some of the standard signatures associated with this spyware threat. Please do not attempt to manually remove these items from your computer; Removing these items incorrectly or partially can cause your computer to experience critical errors, prevent your computer from restarting or cause loss of Internet connectivity. Should you be infected with Downloader/UCSearch, you can clean your computer by downloading SpyNoMore now.

Running Process Signatures:
N/A

File Signatures:
%WINDOWS%\downloaded program files\ucsearch.ocx
%WINDOWS%\downloaded program files\ucsearch.inf

Registered Dll (Dynamic Link Library) Signatures:
N/A

Folder Signatures:
N/A

Registry Signatures:
HKCR\interface\{4c33d68d-9703-4636-b433-383d42d0847c}
HKCR\clsid\{1fdec088-a699-46fe-bf76-d5fd6dae6150}
HKLM\software\microsoft\code store database\distribution units\{1fdec088-a699-46fe-bf76-d5fd6dae6150}
HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/ucsearch.ocx
HKCR\interface\{737263fd-a882-4957-8136-c0fd923ff150}
HKCR\ucsearch.ucucsearch
HKCR\typelib\{0ff7dbe0-ce7d-43b2-b016-50f1c88551e5}

SpyNoMore Collected Residual File Signatures:
N/A


See Also:
Trojan/Backdoor/RAT/EggDrop.130
Trojan/Backdoor/RAT/EggDrop.149
RAT/XQdoor.09
Adware/Downloader/Perfiler
Adware/StatBlaster
Hacker Tool/Safecast
Adware/BHO/Toolbar/2020Search
Trojan/Adware/Backdoor/Doomob.A
Trojan/Adware/Worm/TalkStocks.a
Adware/OnSrvr

Spyware Removal Home | Support | F.A.Q. | Contact Us | Spyware Removal Database | Privacy Policy | Site Map
Copyright © 2005-2008 Illysoft LLC