Hijacker . NWS Search (Summary)
Software Name: NWS Search
Company Name:
Product Name: NWS Search
Classification: Hijacker
Website: http://0ml.net
Brief:
Homepage and search hijacker disguised as a Windows Help file. Directs homepage and searches to http://0ml.net. Downloads additional software and adds adult links to IE favorites.
IMPORTANT!
Some of the Hijacker.NWS Search components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of NWS Search
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
NWS Search might create following folders (and inject its files inside
the folders):
n/a
NWS Search might create following files (some of the files might be
loaded in memory while the software is running):
- %WINDOWS%\defcolors.txt
- %WINDOWS%\_hp.html
- %WINDOWS%\_sp.html
- %SYSTEM%\checking.exe
- %SYSTEM%\aqyxbf4r1n.dll
- %SYSTEM%\f98er24s8u.dll
- %SYSTEM%\svcpck.dat
- %FAVORITES%\!SEX SEARCH ENGINE.URL
- %FAVORITES%\-= FREE SEX THUMBNAILED GALLERIES =-.URL
- %FAVORITES%st! XXX-TV.US - FREE XXX THUMBS DAILY!.URL
- %FAVORITES%\FREE PORN PICS.URL
- %FAVORITES%\Uncensored Sex Pics and Live Cams.URL
- %FAVORITES%\~ Porn Movies ~.URL
- %PROFILE%\Local Settings\Temp\delself.bat
NWS Search is often accompanied by the following tracking cookies:
n/a
NWS Search might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10020}
- HKEY_CLASSES_ROOT\IEHlprObj.IEHlprObj
- HKEY_CLASSES_ROOT\IEHlprObj.IEHlprObj.1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CE7C3CF0-4B15-11D1-ABED-709549C10020}
NWS Search might create following registry values:
n/a
NWS Search might create registry values with following data:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://0ml.net*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|(default)|http://0ml.net*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|*|http://0ml.net*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL|(default)http://0ml.net*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://0ml.net*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|(default)|http://0ml.net*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|*|http://0ml.net*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\SearchUrl|(default)|http://0ml.net*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Styles|User Stylesheet|*\defcolors.txt
NWS Search might insert following entries in the HOSTS file:
- 3466709097 auto.search.msn.com
- 3466709097 sea.search.msn.com
- 3466709097 search.msn.com
- 3466709097 sitefinder.verisign.com
- 3466709097 sitefinder-idn.verisign.com
- 3466709097 www.your.com your.com
- 3466709097 com.org
- 3466690378 ad.doubleclick.net
- 3466690378 view.atdmt.com
- 3466690378 click.atdmt.com
- 3466690378 leader.linkexchange.com
Click
here to scan your computer for NWS Search free of charge
|