Emsisoft Malware-Info

Name: Adware.Win32.Halloween Moon

Risklevel: High Risk

Company: sitevip.net - http://www.sitevip.net/

Description:

Halloween Moon is an adware bundler that installs adware NDotNet (New.net) with itself.Adware.NDotNet is an adware program that associates non-existent domain names with sponsored content. When an end-user enters a keyword into a browser address bar or attempts to resolve a mistaken or non-existent URL, the adware redirects the user to a sponsored page.

Removal instructions for Adware Halloween Moon:

To delete this malware infection, buy Emsisoft Anti-Malware.
Guaranteed removal of Adware Halloween Moon.

Run a full scan on all drives and move all detected items to the quarantine.

More details about this danger:

Characteristics:

  • It installs adware NDotNet (New.net) with itself.
  • Adware.NDotNet is an adware program that associates non-existent domain names with sponsored content. When an end-user enters a keyword into a browser address bar or attempts to resolve a mistaken or non-existent URL, the adware redirects the user to a sponsored page.

Installation: Installed through EXE

Process: Halloween Moon.scr

Screenshots:

Halloween MoonHalloween MoonHalloween MoonHalloween MoonHalloween MoonHalloween MoonHalloween MoonHalloween MoonHalloween Moon

Used folders:

  • C:\Program Files\QuickSearch
  • C:\Program Files\PhotoOp
  • C:\Program Files\PhotoOp\Halloween Moon
  • C:\Program Files\PhotoOp\Halloween Moon\Images
  • C:\Program Files\PhotoOp\Halloween Moon\Sounds
  • C:\Program Files\NewDotNet
  • C:\Program Files\filesubmit
  • C:\Program Files\filesubmit\halloweenmoon.exe
  • C:\Program Files\IncrediFind\BHO
  • C:\WINDOWS\iNetPal
  • C:\Documents and Settings\[USER]\Start Menu\Programs\Halloween Moon
  • C:\Program Files\Common Files\updater
  • C:\Program Files\IncrediFind

Used files:

  • C:\Program Files\PhotoOp\Halloween Moon\Sounds\halowee_.mid
    [29383 Bytes] MIDI Sequence
  • C:\WINDOWS\iNetPal\m3tsp8.exe
    [304640 Bytes] Application
  • C:\Program Files\PhotoOp\Halloween Moon\Sounds\badm.mid
    [34549 Bytes] MIDI Sequence
  • C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
    [241664 Bytes] Application Extension
  • C:\Program Files\NewDotNet\newdotnet3_88.dll
    [167936 Bytes] Application Extension
  • C:\Program Files\NewDotNet\readme.txt
    [3522 Bytes] Text Document
  • C:\Program Files\NewDotNet\uninstall3_88.exe
    [36864 Bytes] Application
  • C:\Program Files\filesubmit\halloweenmoon.exe\fsi_install.ico
    [766 Bytes] Icon
  • C:\Program Files\filesubmit\halloweenmoon.exe\fsi_uninstall.ico
    [766 Bytes] Icon
  • C:\Program Files\filesubmit\halloweenmoon.exe\INSTALL.LOG
    [1904 Bytes] Text Document
  • C:\Program Files\filesubmit\halloweenmoon.exe\NNEZTA388.exe
    [208896 Bytes] Application
  • C:\Program Files\filesubmit\halloweenmoon.exe\TBEZA127Q.exe
    [294912 Bytes] Application
  • C:\Program Files\filesubmit\halloweenmoon.exe\UNWISE.INI
    [29 Bytes] Configuration Settings
  • C:\Program Files\IncrediFind\BHO\date.txt
    [17 Bytes] Text Document
  • C:\Program Files\IncrediFind\BHO\IncFindBHO.dll
    [40960 Bytes] Application Extension
  • C:\Program Files\filesubmit\halloweenmoon.exe\halloweenmoon.exe
    [1395159 Bytes] Application
  • C:\Program Files\PhotoOp\Halloween Moon\Halloween Moon.ico
    [766 Bytes] Icon
  • C:\Program Files\PhotoOp\Halloween Moon\Setup.ini
    [66 Bytes] Configuration Settings
  • C:\Program Files\PhotoOp\Halloween Moon\Images\06.jpg
    [45505 Bytes] JPEG Image
  • C:\Program Files\PhotoOp\Halloween Moon\Images\05.jpg
    [55423 Bytes] JPEG Image
  • C:\Program Files\PhotoOp\Halloween Moon\Images\04.jpg
    [58470 Bytes] JPEG Image
  • C:\Program Files\PhotoOp\Halloween Moon\Images\03.jpg
    [15565 Bytes] JPEG Image
  • C:\Program Files\PhotoOp\Halloween Moon\Images\02.jpg
    [52499 Bytes] JPEG Image
  • C:\Program Files\PhotoOp\Halloween Moon\Images\01.jpg
    [43319 Bytes] JPEG Image
  • C:\Program Files\PhotoOp\Halloween Moon\Images\07.jpg
    [69408 Bytes] JPEG Image
  • C:\Program Files\PhotoOp\Halloween Moon\Setup.inf
    [7553 Bytes] Setup Information
  • C:\Program Files\PhotoOp\Halloween Moon\Setup.in_
    [46 Bytes] IN_ File
  • C:\Program Files\PhotoOp\Halloween Moon\Setup.exe
    [16896 Bytes] Application
  • C:\Program Files\PhotoOp\Halloween Moon\PhotoOp.inx
    [2092 Bytes] INX File
  • C:\Program Files\PhotoOp\Halloween Moon\mn_witch2.jpg
    [71787 Bytes] JPEG Image
  • C:\Program Files\PhotoOp\Halloween Moon\_Setup.hl_
    [2888 Bytes] HL_ File
  • C:\Program Files\PhotoOp\Halloween Moon\_Setup.ex_
    [243969 Bytes] EX_ File
  • C:\Program Files\PhotoOp\Halloween Moon\Images\ar_logo.gif
    [5766 Bytes] GIF Image
  • C:\Program Files\PhotoOp\Halloween Moon\Images\bat_sm_ani.gif
    [3838 Bytes] GIF Image
  • C:\Program Files\PhotoOp\Halloween Moon\PhotoOp.ini
    [2773 Bytes] Configuration Settings
  • C:\WINDOWS\Thk3216.dll
    [27648 Bytes] Application Extension
  • C:\Program Files\Common Files\updater\wupdater.exe
    [61440 Bytes] Application
  • C:\Program Files\Common Files\updater\sui.exe
    [86073 Bytes] Application
  • C:\Program Files\Common Files\updater\delupdat.exe
    [24576 Bytes] Application
  • C:\Program Files\Common Files\updater\data2.dat
    [311 Bytes] DAT File
  • C:\Program Files\Common Files\updater\data1.dat
    [49 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Start Menu\Programs\Halloween Moon\Uninstall Halloween Moon.lnk
    [1697 Bytes] Shortcut
  • C:\Documents and Settings\[USER]\Start Menu\Programs\Halloween Moon\Halloween Moon.lnk
    [1469 Bytes] Shortcut
  • C:\Program Files\PhotoOp\Halloween Moon\Images\08.jpg
    [38698 Bytes] JPEG Image
  • C:\WINDOWS\Timer16.dll
    [8704 Bytes] Application Extension
  • C:\WINDOWS\Halloween Moon.scr
    [1026560 Bytes] Screen Saver
  • C:\WINDOWS\Halloween Moon.hlp
    [7761 Bytes] Help File
  • C:\WINDOWS\system32\setup_incred_3.exe
    [139335 Bytes] Application
  • C:\WINDOWS\system32\sahagent1020.exe
    [55216 Bytes] Application
  • C:\WINDOWS\system32\ATPartners.dll
    [96256 Bytes] Application Extension

Additional information might be found here:

Search at Google for Adware Halloween Moon Search at Google for Adware Halloween Moon
Search at Bing for Adware Halloween Moon Search at Bing for Adware Halloween Moon
Search at Yahoo for Adware Halloween Moon Search at Yahoo for Adware Halloween Moon

How can I protect myself from Adware Halloween Moon?

Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers. This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.

Take your chance and buy the multiple awarded protection software Emsisoft Anti-Malware today!

Only $40 for the security of your computer.

Buy Emsisoft Anti-Malware online:

Buy Emsisoft Anti-Malware now

Trust only on the best protection software!

Spring Offer!

Don't miss this: To your bought 1-year license of Emsisoft Anti-Malware or Emsisoft Internet Security Pack or higher you can now get a free license of the CyberGhost Anonymizer for free.
Your advantage: Surf anonymously and visit websites that are restricted in your country.

Only a few days left! Order here

Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - Q1-Q3 2011
More independent reviews of anti-malware software