Hijacker . SearchForIt Toolbar (Summary)
Software Name: SearchForIt Toolbar
Company Name: Acquirenic
Product Name: SearchForIt Toolbar
Classification: Hijacker
Website: http://www.searchforit.com
Brief:
Takes over browser settings and may track searching behavior or habits. Installs additional items on your computer. Displays pop-up ads when internet browsing and displays sponsored search results when using specific search engines.
IMPORTANT!
Some of the Hijacker.SearchForIt Toolbar components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of SearchForIt Toolbar
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
SearchForIt Toolbar might create following folders (and inject its files inside
the folders):
SearchForIt Toolbar might create following files (some of the files might be
loaded in memory while the software is running):
- %PROFILE%\Local Settings\Temp\DnldNCSX0002.exe
- %WINDOWS%\SYSsfitb.exe
- %WINDOWS%\Downloaded Program Files\downloader.inf
- %WINDOWS%\Downloaded Program Files\d_loader.exe
- %SYSTEM%\SYSsfitb.dll
- %PROFILE%\Local Settings\Temp\sysawqd.dat
- %PROFILE%\Local Settings\Temp\downloader.inf
- %PROFILE%\Local Settings\Temp\d_loader.exe
- %PROFILE%\Local Settings\Temp\GLF5GLF5.EXE
- %PROFILE%\Local Settings\Temp\SYSsfitb.cab
- %PROFILE%\Local Settings\Temp\ts_8_new.exe
- %WINDOWS%\SYSfit.exe
- %SYSTEM%\replaceSearch.dll
- %SYSTEM%\sfita.exe
SearchForIt Toolbar is often accompanied by the following tracking cookies:
n/a
SearchForIt Toolbar might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\CLSID\{C109664B-CEB1-420b-B353-D55A561536DD}
- HKEY_CLASSES_ROOT\drs.n
- HKEY_CLASSES_ROOT\Interface\{2DB1A6DF-8120-47BD-9DCE-CFCD47B17B24}
- HKEY_CLASSES_ROOT\Interface\{AB94D42B-64E9-436F-887C-CF38FE475CFC}
- HKEY_CLASSES_ROOT\SYI.SYIObj
- HKEY_CLASSES_ROOT\SYI.SYIObj\CLSID
- HKEY_CLASSES_ROOT\SYI.SYIObj\CurVer
- HKEY_CLASSES_ROOT\SYI.SYIObj.1
- HKEY_CLASSES_ROOT\SYI.SYIObj.1\CLSID
- HKEY_CLASSES_ROOT\TypeLib\{F43085A3-5FBD-4954-B7BF-00A8F1A1B9FE}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A27AD582-5BE5-4C2D-82F0-48B24FE02040}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/d_loader.exe*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\searchforitsearchforit
- HKEY_USERS\*\Software\DR_S
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Hot Sites
- HKEY_USERS\*\Software\searchforit
- HKEY_CLASSES_ROOT\CLSID\{832BEBED-C3DA-4534-A2C2-B2FFF220C820}
- HKEY_CLASSES_ROOT\Interface\{FAAEB405-B7B0-4749-81DE-DF36B2D36531}
- HKEY_CLASSES_ROOT\ReplaceSearch.ReplaceSearchCtl
- HKEY_CLASSES_ROOT\ReplaceSearch.ReplaceSearchCtl.1
- HKEY_CLASSES_ROOT\TypeLib\{B9C1DD92-B443-4BF1-B4C0-950E41A9F9F7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{832BEBED-C3DA-4534-A2C2-B2FFF220C820}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TSL Installer
- HKEY_CLASSES_ROOT\Ca.Cas
- HKEY_CLASSES_ROOT\Ca.Cas.1
- HKEY_CLASSES_ROOT\CLSID\{B5F3970B-745E-46AC-B890-E08F69777D80}
- HKEY_CLASSES_ROOT\Interface\{337278B8-50AF-4F67-8929-E7D6B8DDD66B}
- HKEY_CLASSES_ROOT\TypeLib\{919F8A8D-135D-44FC-A809-B36083EEAE35}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B5F3970B-745E-46AC-B890-E08F69777D80}
SearchForIt Toolbar might create following registry values:
- HKEY_CLASSES_ROOT\drs.n|uID
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{C109664B-CEB1-420b-B353-D55A561536DD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\d_loader.exe
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{C109664B-CEB1-420B-B353-D55A561536DD}
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|DR_S
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|SYSfit
SearchForIt Toolbar might create registry values with following data:
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|Start Page|http://www.searchforit.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://www.searchforit.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|*|http://www.searchforit.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://www.searchforit.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|*|http://www.searchforit.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\SearchUrl|(default)|http://www.searchforit.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\SearchUrl|*|http://www.searchforit.com*
SearchForIt Toolbar might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for SearchForIt Toolbar free of charge
|