Threat Database Adware Adware.Softomate.A

Adware.Softomate.A

By CagedTech in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 80
First Seen: January 11, 2013
Last Seen: March 20, 2026
OS(es) Affected: Windows

The detection of Adware.Softomate.A on your system indicates that your computer has been compromised by a potentially unwanted program. This type of software is designed to display unwanted advertisements, collect user data, and potentially redirect users to malicious websites. It is essential to take immediate action to remove Adware.Softomate.A from your system to prevent further damage and protect your personal information.

What Is Adware.Softomate.A?

Adware.Softomate.A is a type of adware program that is designed to generate revenue for its creators by displaying unwanted advertisements on infected systems. It may be bundled with other software, downloaded from the internet, or installed through exploits in vulnerable applications. Once installed, Adware.Softomate.A can collect user data, such as browsing history and search queries, and use this information to display targeted advertisements.

How Adware.Softomate.A Operates

Adware.Softomate.A operates by installing itself on a system and then connecting to a remote server to download advertisements and other malicious content. It may also modify system settings, such as changing the default search engine or homepage, to further facilitate the display of unwanted advertisements. In some cases, Adware.Softomate.A may also install additional malware or potentially unwanted programs on the infected system.

Adware.Softomate.A may use various tactics to evade detection, such as disguising itself as a legitimate program or using code obfuscation techniques to hide its malicious activities. However, its primary goal is to generate revenue for its creators by displaying unwanted advertisements and collecting user data.

Symptoms of Infection

Systems infected with Adware.Softomate.A may exhibit a range of symptoms, including the display of unwanted advertisements, slowed system performance, and changes to system settings. Users may also notice that their search results are being redirected to unfamiliar websites or that their browsing history is being collected and used to display targeted advertisements.

  • Unwanted advertisements appearing on the system or in web browsers
  • Slowed system performance or increased CPU usage
  • Changes to system settings, such as the default search engine or homepage
  • Redirected search results or unfamiliar websites appearing in the browser

How to Remove Adware.Softomate.A

  1. Boot your system in Safe Mode with Networking to prevent Adware.Softomate.A from loading and to allow for easier removal
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove Adware.Softomate.A and any other malware or potentially unwanted programs
  3. Uninstall any suspicious programs or applications that may be related to Adware.Softomate.A
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by Adware.Softomate.A
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that Adware.Softomate.A has been completely removed

Conclusion

Removing Adware.Softomate.A from your system is essential to prevent further damage and protect your personal information. By following the steps outlined above, you can effectively remove this unwanted program and restore your system to a safe and secure state. It is also important to take steps to prevent future infections, such as keeping your operating system and software up to date, using reputable anti-malware tools, and being cautious when downloading software or clicking on links from unknown sources.

Analysis Report

General information

Family Name: Adware.Softomate.A
Signature status: No Signature

Known Samples

MD5: 23e9ecd8920b36ebb85e1f5c918edbb1
SHA1: f368de89b34dcd01c637f1398888b8009fc2f4d3
SHA256: BBBF3F3774F16D38CF899719C3A4C223781AABACAC2DA0D4FB2FD8C0D9768ADA
File Size: 2.56 MB, 2564039 bytes
MD5: c921bed3b4e16ad98f164c13c59e8aae
SHA1: 4043f9477ebc6e56698b4958375da85940746d6b
SHA256: 09CC126F3B97F54EDB072D7E7D5FF3CC5BE78B533D307D079BDFEEA2B67FED94
File Size: 864.32 KB, 864317 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Description IE Toolbar Engine
File Version
  • 4, 1, 0, 33
  • 3, 0, 1, 51
Internal Name tbcore3
Legal Copyright
  • Copyright © 2001-2006. All rights reserved.
  • Copyright © 2001-2008. All rights reserved.
Original Filename tbcore3.dll
Product Name IE Toolbar
Product Version
  • 4, 1, 0, 33
  • 3.0.1.0

File Traits

  • big overlay
  • dll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 5,592
Potentially Malicious Blocks: 950
Whitelisted Blocks: 4,638
Unknown Blocks: 4

Visual Map

0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x x 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 x x x x x x x x 0 x x x 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x x 0 x x x x x x x 0 x x x 0 x x 0 x 0 x x 0 x 0 x x x x 0 x x x x x x 0 x 0 x x x x 0 x x x x 0 x 0 x 0 x x x x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 x 0 x 0 0 0 0 x 0 x 0 x 0 0 0 x 0 x x x x 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x x x x 0 x 0 0 x x x x x x x x x 0 x x x x x x x x x x x x x 0 x x x x x x x x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 x 0 0 x 0 0 0 0 0 x 0 x x x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x 0 0 0 x 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x x 0 0 x x 0 0 0 x x 0 0 0 x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 x 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Softomate.A

Files Modified

File Attributes
c:\program files\common files\system\symsrv.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows nt\currentversion\windows::appinit_dlls C:\PROGRA~1\COMMON~1\System\symsrv.dll RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows nt\currentversion\windows::loadappinit_dlls  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows nt\currentversion\windows::requiresignedappinit_dlls RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f368de89b34dcd01c637f1398888b8009fc2f4d3_0002564039.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4043f9477ebc6e56698b4958375da85940746d6b_0000864317.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...