Hijacker . IncrediFind (Summary)
Software Name: IncrediFind
Company Name:
Product Name: IncrediFind
Classification: Hijacker
Website: http://www.incredifind.com
Brief:
Silently installed BHO that hijacks browser search settings to point to its controlling servers incredifind.com. Re-directs on 404 page errors and also auto-updates in the background.
IMPORTANT!
Some of the Hijacker.IncrediFind components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of IncrediFind
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
IncrediFind might create following folders (and inject its files inside
the folders):
- %PROGRAM_FILES_COMMON%\updater
- %PROGRAM_FILES%\IncrediFind
IncrediFind might create following files (some of the files might be
loaded in memory while the software is running):
- %PROFILE%\Local Settings\Temp\IncrediFindBHOLog.tmp
- %SYSTEM%\drivers\etc\hosts.bho
- %SYSTEM%\incfindbho.dll
- %SYSTEM%\incredifind.dll
IncrediFind is often accompanied by the following tracking cookies:
n/a
IncrediFind might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\BHO.IncrediFindBHO
- HKEY_CLASSES_ROOT\BHO.IncrediFindBHO.1
- HKEY_CLASSES_ROOT\CLSID\{5D60FF48-95BE-4956-B4C6-6BB168A70310}
- HKEY_CLASSES_ROOT\Interface\{8B8F6968-2F24-41E3-B653-E9613226F14D}
- HKEY_CLASSES_ROOT\TypeLib\{DE289BFA-737B-4ABB-A4EC-F8753551B875}
- HKEY_LOCAL_MACHINE\SOFTWARE\IncrediFind
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5D60FF48-95BE-4956-B4C6-6BB168A70310}
- HKEY_LOCAL_MACHINE\SOFTWARE\updater
- HKEY_LOCAL_MACHINE\SOFTWARE\updater\{8D15A72D-62E0-4733-B057-0A81B4FFEB3D}
IncrediFind might create following registry values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|updater
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\URLSearchHooks|{5D60FF48-95BE-4956-B4C6-6BB168A70310}
IncrediFind might create registry values with following data:
n/a
IncrediFind might insert following entries in the HOSTS file:
- 12.129.205.209 search.netscape.com12.129.205.209
- 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
Click
here to scan your computer for IncrediFind free of charge
|