Hijacker . CWS.HereToFind (Summary)
Software Name: CWS.HereToFind
Company Name: Unknown
Product Name: HeretoFind
Classification: Hijacker
Website: http://www.heretofind.com
Brief:
Exploits Windows Help system using a false help file to hijack users homepage and search settings to heretofind.com, an adult web portal.
IMPORTANT!
Some of the Hijacker.CWS.HereToFind components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of CWS.HereToFind
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
CWS.HereToFind might create following folders (and inject its files inside
the folders):
CWS.HereToFind might create following files (some of the files might be
loaded in memory while the software is running):
- %PROFILE%\Local Settings\Temp\ajkl.dat
- %PROFILE%\Local Settings\Temp\dkef.dat
- %PROFILE%\Local Settings\Temp\jpmi.dat
- %SYSTEMDRIVE%\spe\start.chm
- %SYSTEM%\iframeworks.exe
- %SYSTEM%\remove_me.dll
CWS.HereToFind is often accompanied by the following tracking cookies:
n/a
CWS.HereToFind might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\CLSID\{237AA178-C3BC-4f67-A8BB-D8BC14BA0B89}
- HKEY_CLASSES_ROOT\CLSID\{A080D497-BB7C-48AC-B533-8592C649B863}
- HKEY_CLASSES_ROOT\CLSID\{e449f20a-e449f20a-e449f20a-e449f20a-e449f20a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{237AA178-C3BC-4f67-A8BB-D8BC14BA0B89}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{A080D497-BB7C-48AC-B533-8592C649B863}
- HKEY_LOCAL_MACHINE\SOFTWARE\MiniBridge
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Extensions\{237AA178-C3BC-4f67-A8BB-D8BC14BA0B89}
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Extensions\{A080D497-BB7C-48AC-B533-8592C649B863}
CWS.HereToFind might create following registry values:
- HKEY_USERS\*\Software\WinRAR SFX|c%%spe
CWS.HereToFind might create registry values with following data:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|mk:@MSITStore*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|mk:@MSITStore*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://www.heretofind.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix|(default)|http://www.heretofind.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes|*|http://www.heretofind.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://www.heretofind.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix|*|http://www.heretofind.com*
CWS.HereToFind might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for CWS.HereToFind free of charge
|