Hijacker . CWS.About_Blank (Summary)
Software Name: CWS.About_Blank
Company Name: Search-About.net
Product Name: About_Blank
Classification: Hijacker
Website: http://looking-for.cc
Brief:
Hijacks browser homepage and search settings to a search portal. Can silently download and execute files.
IMPORTANT!
Some of the Hijacker.CWS.About_Blank components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of CWS.About_Blank
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
CWS.About_Blank might create following folders (and inject its files inside
the folders):
- %COMMON_APPDATA%\iefeatsl
- %APPDATA%\iefeatsl
- %FAVORITES%\Sites about
CWS.About_Blank might create following files (some of the files might be
loaded in memory while the software is running):
- %WINDOWS%\application data\iefeatsl\msiesh.dll
- %SYSTEM%\iefeatsl.dll
- %WINDOWS%\system\iefeatsl.dll
- %SYSTEM%\s.bat
- %FAVORITES%\Only sex website.url
- %FAVORITES%\Search the web.url
- %FAVORITES%\Seven days of free porn.url
- %FAVORITES%\Sites about\Ab scissor.url
- %FAVORITES%\Sites about\Broadband comparison.url
- %FAVORITES%\Sites about\Credit counseling.url
- %FAVORITES%\Sites about\Credit report.url
- %FAVORITES%\Sites about\Crm software.url
- %WINDOWS%\msopt.dll
- %SYSTEMDRIVE%\iefeatslinstaller.log
- %PROFILE%\Local Settings\Temp\system.exe
- %WINDOWS%\gtztq.txt
- %WINDOWS%\mfczt.exe
- %WINDOWS%\n_pufgmy.dat
- %WINDOWS%\sysgw32.dll
- %WINDOWS%\syszj32.exe
- %WINDOWS%\tztqu.dll
- %SYSTEM%\heuho.dll
- %SYSTEM%\javagn.dll
- %SYSTEM%\jheuh.log
- %SYSTEMDRIVE%\msinfo.exe
- %DESKTOP%\Cool Web Search.url
- %DESKTOP%\HistoryKill - The N1 Windows Privacy Tool.url
- %FAVORITES%\Cool Web Search.url
- %FAVORITES%\HistoryKill - The N1 Windows Privacy Tool.url
- %FAVORITES%\NEVER TO SHAVE AGAIN!!!.url
- %FAVORITES%\SEX Post Portal ( NEW GALLERIES EVERY DAY ).url
- %FAVORITES%\Want Bigger - Solution for you!.url
- %SYSTEM%\pbkg.dll
- %PROFILE%\Local Settings\Temp\sp.html
- %FAVORITES%\Sites about\Debt credit card.url
- %FAVORITES%\Sites about\Escorts.url
- %FAVORITES%\Sites about\Fha.url
- %FAVORITES%\Sites about\Health insurance.url
- %FAVORITES%\Sites about\Help desk software.url
- %FAVORITES%\Sites about\Insurance home.url
- %FAVORITES%\Sites about\Loan for debt consolidation.url
- %FAVORITES%\Sites about\Loan for people with bad credit.url
- %FAVORITES%\Sites about\Marketing email.url
- %FAVORITES%\Sites about\Mortgage insurance.url
- %FAVORITES%\Sites about\Mortgage life insurance.url
- %FAVORITES%\Sites about\Nevada corporations.url
- %FAVORITES%\Sites about\Online Betting Site.url
- %FAVORITES%\Sites about\Online gambling casino.url
- %FAVORITES%\Sites about\Online instant loan.url
- %FAVORITES%\Sites about\Order phentermine.url
- %FAVORITES%\Sites about\Payroll advance.url
- %FAVORITES%\Sites about\Personal loans online.url
- %FAVORITES%\Sites about\Personal loans with bad credit.url
- %FAVORITES%\Sites about\Prescription Drugs Rx Online.url
- %FAVORITES%\Sites about\Refinancing my mortgage.url
- %FAVORITES%\Sites about\Tahoe vacation rental.url
- %FAVORITES%\Sites about\Unsecured bad credit loans.url
- %FAVORITES%\Sites about\Videos.url
- %FAVORITES%\Sites about\What is hydrocodone.url
- %PROFILE%\Local Settings\Temp\se.dll
- %SYSTEM%\fimi.dll
- %SYSTEMDRIVE%\f2install.log
- %SYSTEM%\crun.dll
- %SYSTEM%\ipey32.dll
- %SYSTEM%\jgvwk.dll
- %SYSTEM%\kmfhc.dll
- %SYSTEM%\mskn32.exe
- %SYSTEM%\ouqoe.dat
- %SYSTEM%\mfcoj.exe
- %WINDOWS%\Temp\se.dll
- C:\WINDOWS\system32\egip.dll
- %SYSTEM%\atlzd32.exe
- %WINDOWS%\crny32.exe
- %WINDOWS%\addqk.dll
- %WINDOWS%\netjg.exe
- %SYSTEM%\javahe.exe
- %SYSTEM%\mistg.dll
- %SYSTEM%\apilt32.exe
- %SYSTEM%\javagy.exe
CWS.About_Blank is often accompanied by the following tracking cookies:
n/a
CWS.About_Blank might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\icoo
- HKEY_CLASSES_ROOT\PROTOCOLS\Handler\icoo
- HKEY_USERS\*\Software\Adverts
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{10003000-1000-0000-1000-000000000000}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAssistant Uninstall
- HKEY_CLASSES_ROOT\CLSID\{519417B8-BAED-4DC6-9138-D666149A7FE9}
- HKEY_CLASSES_ROOT\CLSID\{F411F98C-B6AC-4DA8-A14A-2845DB2563BA}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F411F98C-B6AC-4DA8-A14A-2845DB2563BA}
- HKEY_CLASSES_ROOT\CLSID\{B375AEC5-21DB-994F-7C6C-EC0E8EE97152}
- HKEY_CLASSES_ROOT\CLSID\{21C97877-54C4-44BF-A076-6E7834CD31C4}
- HKEY_CLASSES_ROOT\CLSID\{527D520A-B0ED-4CAE-93E8-37BB0A98FFC1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21C97877-54C4-44BF-A076-6E7834CD31C4}
- HKEY_CLASSES_ROOT\CLSID\{5AA490BA-EF24-4701-8CBF-58FBA84CD68E}
- HKEY_CLASSES_ROOT\CLSID\{7F362C5A-1D2B-4225-91E1-A188BA3BD528}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5AA490BA-EF24-4701-8CBF-58FBA84CD68E}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ 11Fßä#·ºÄÖ`I
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ 11Fßä#·ºÄÖ`I
- HKEY_CLASSES_ROOT\CLSID\{2292BD18-3B6B-01F7-6D6E-CA1A2CB8FE64}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{04E4BBE3-27B1-4DA7-B874-DDD97403D3C2}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{11212111-2121-1311-1141-115611111222}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0286A0B7-10A5-ED81-DAA1-D347AC3BBBC8}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0A5B4A8F-A91D-601F-5D8F-5341B9B56791}
- HKEY_CLASSES_ROOT\CLSID\{0A5B4A8F-A91D-601F-5D8F-5341B9B56791}
- HKEY_CLASSES_ROOT\CLSID\{0286A0B7-10A5-ED81-DAA1-D347AC3BBBC8}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{656B383F-AC64-DA20-92C9-BD8C2E2B596F}
- HKEY_CLASSES_ROOT\CLSID\{7D452CFD-9ADF-94EE-79E0-1430DBA2D535}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7D452CFD-9ADF-94EE-79E0-1430DBA2D535}
- HKEY_CLASSES_ROOT\CLSID\{1F5650BA-2C95-0E8C-5C3F-D482646BF979}
- HKEY_CLASSES_ROOT\CLSID\{9AA3D1DC-D550-95AC-9011-339941DD6100}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9AA3D1DC-D550-95AC-9011-339941DD6100}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7897E57C-2EB1-E8C5-4D9C-C227B55C1142}
- HKEY_CLASSES_ROOT\CLSID\{7897E57C-2EB1-E8C5-4D9C-C227B55C1142}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9011BFD4-E203-0899-94F9-1C6851794380}
- HKEY_CLASSES_ROOT\CLSID\{9011BFD4-E203-0899-94F9-1C6851794380}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EC37D9B3-9A1E-E706-8A80-9B7C13DF2373}
- HKEY_CLASSES_ROOT\CLSID\{EC37D9B3-9A1E-E706-8A80-9B7C13DF2373}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9AE87A0-844A-04E0-82FC-ABA9A8BCBB07}
- HKEY_CLASSES_ROOT\CLSID\{F9AE87A0-844A-04E0-82FC-ABA9A8BCBB07}
- HKEY_CLASSES_ROOT\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5}
- HKEY_CLASSES_ROOT\CLSID\{766E0CFB-DBEE-535F-853A-ADC9AC3BBE13}
- HKEY_CLASSES_ROOT\CLSID\{F9ABE119-352C-F1BB-5DD5-681EF19595DD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{766E0CFB-DBEE-535F-853A-ADC9AC3BBE13}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9ABE119-352C-F1BB-5DD5-681EF19595DD}
- HKEY_CLASSES_ROOT\CLSID\{B95DC66C-C0E4-74CA-83B9-6EE41D0D49FF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B95DC66C-C0E4-74CA-83B9-6EE41D0D49FF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D6F824E-4876-24B2-D11B-49F9A8DF9F1B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D6F824E-4876-24B2-D11B-49F9A8DF9F1B}
CWS.About_Blank might create following registry values:
- HKEY_CLASSES_ROOT\icoo|URL Protocol
- HKEY_CLASSES_ROOT\PROTOCOLS\Handler\icoo|CLSID
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\windupdates.com|*|*2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|HOMEOldSP
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|HOMEOldSP
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|iepx.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|mskn32.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|sdkgf.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|sp
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|javahe.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|apilt32.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{B95DC66C-C0E4-74CA-83B9-6EE41D0D49FF}
CWS.About_Blank might create registry values with following data:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domainsp.com|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\my-internet.info|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\scoobidoo.com|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\xxxtoolbar.com|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1|*|206.161.125.149
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domainsp.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\my-internet.info|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\scoobidoo.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\xxxtoolbar.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1|*|206.161.125.149
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\WinTrust\trust provider\software publishing\trust database{RD_DISPLAY}|*|Integrated Search Technologies
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\WinTrust\trust provider\software publishing\trust database{RD_DISPLAY}|*|MediaTickets
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\WinTrust\trust provider\software publishing\trust database{RD_DISPLAY}|*|CTD inc.
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1|*|2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crazywinnings.com|*|*2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\skoobidoo.com|*|*2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\topconverting.com|*|*2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\windupdates.com|*|*2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crazywinnings.com|*|2
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\topconverting.com|*|*2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|file://*\sp.html*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|*|file://*\sp.html*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|file://*\sp.html*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|CustomizeSearch|http://www.findin.org*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|*|file://*\sp.html*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|about:NavigationFailure
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|*|about:NavigationFailure
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|about:NavigationFailure
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|*|about:NavigationFailure
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://looking-for.cc*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://www.looking-for.cc*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://looking-for.cc*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://www.looking-for.cc*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|*|http://looking-for.cc*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|*|http://www.looking-for.cc*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|*|http://looking-for.cc*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|*|http://www.looking-for.cc*
- HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/html|CLSID|{519417B8-BAED-4DC6-9138-D666149A7FE9}
- HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain|CLSID|{519417B8-BAED-4DC6-9138-D666149A7FE9}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|*|res://%63%3a%5c%77%69%6e%64%6f%77%73%5c%73%79%73%74%65%6d%33%32%5c%73%66%63%6d%61%6e%33%32%2e%64%6c%6c/%73%70%2e%68%74%6d%6c
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|*|res://%63%3a%5c%77%69%6e%64%6f%77%73%5c%73%79%73%74%65%6d%33%32%5c%73%66%63%6d%61%6e%33%32%2e%64%6c%6c/%73%70%2e%68%74%6d%6c
- HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/html|CLSID|{527D520A-B0ED-4CAE-93E8-37BB0A98FFC1}
- HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain|CLSID|{527D520A-B0ED-4CAE-93E8-37BB0A98FFC1}
- HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/html|CLSID|{7F362C5A-1D2B-4225-91E1-A188BA3BD528}
- HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain|CLSID|{7F362C5A-1D2B-4225-91E1-A188BA3BD528}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|SearchAssistant|*/sp.html*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|*\sp.html
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|file://*\sp.html*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|*|*\sp.html
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|*|*\sp.html
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|file://*\sp.html*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|*\sp.html
CWS.About_Blank might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for CWS.About_Blank free of charge
|