Hijacker . Starware Toolbar (Summary)
Software Name: Starware Toolbar
Company Name: Comet Systems
Product Name: Starware Toolbar
Classification: Hijacker
Website: http://www.starware.com
Brief:
Changes browsers search settings which re-directs address bar keyword searches to search.cometsystems.com. Installs a browser search toolbar and when performing a google.com search, will create a new window of search results from cometsystems.com.
IMPORTANT!
Some of the Hijacker.Starware Toolbar components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of Starware Toolbar
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
Starware Toolbar might create following folders (and inject its files inside
the folders):
- %PROFILE%\Local Settings\Temp\nsi3.tmp
- %PROGRAM_FILES%\Comet Systems
- %COMMON_APPDATA%\Starware
- %APPDATA%\Starware
- %PROGRAM_FILES%\Starware
Starware Toolbar might create following files (some of the files might be
loaded in memory while the software is running):
- %WINDOWS%\Downloaded Program Files\dm.inf
- %PROGRAM_FILES%\Starware\StarwareUninstall.exe
- %PROGRAM_FILES%\Starware\bin\Starware.dll
Starware Toolbar is often accompanied by the following tracking cookies:
Starware Toolbar might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\AppID\DMServer.EXE
- HKEY_CLASSES_ROOT\AppID\{BAC984C9-78C8-4105-9E97-1675A4052686}
- HKEY_CLASSES_ROOT\CLSID\{16BC6464-196A-4BAB-A14B-F69F8A0A60F7}
- HKEY_CLASSES_ROOT\CLSID\{188D171F-A126-4A3B-B1DC-ED698FDFCADA}
- HKEY_CLASSES_ROOT\CLSID\{197AB1D7-A7DD-4C86-A938-1FCC0DB21B85}
- HKEY_CLASSES_ROOT\CLSID\{23B55C84-2467-41AC-B9BC-708DE79B2C6C}
- HKEY_CLASSES_ROOT\CLSID\{5A10A2F4-5F95-4424-8776-3D2D25166410}
- HKEY_CLASSES_ROOT\CLSID\{AAB5BAAC-A08D-4B98-8ACD-85D8968C1F04}
- HKEY_CLASSES_ROOT\CLSID\{D8EB7F70-C1F4-471F-A9DA-325B5ADCEF74}
- HKEY_CLASSES_ROOT\CLSID\{F59C663D-E891-492C-86E3-0758C71885C2}
- HKEY_CLASSES_ROOT\CLSID\{F7CCE501-24AC-4133-9D62-9AB0921E2B62}
- HKEY_CLASSES_ROOT\CSSecurity.HTMLSecurity
- HKEY_CLASSES_ROOT\CSSecurity.HTMLSecurity.1
- HKEY_CLASSES_ROOT\DMProxy.DMProxyCtl
- HKEY_CLASSES_ROOT\DMProxy.DMProxyCtl.1
- HKEY_CLASSES_ROOT\DMServer.DMNotify
- HKEY_CLASSES_ROOT\DMServer.DMNotify.1
- HKEY_CLASSES_ROOT\HistoryZapper.CacheCleaner
- HKEY_CLASSES_ROOT\HistoryZapper.CacheCleaner.1
- HKEY_CLASSES_ROOT\HistoryZapper.CookieCleaner
- HKEY_CLASSES_ROOT\HistoryZapper.CookieCleaner.1
- HKEY_CLASSES_ROOT\HistoryZapper.FormCleaner
- HKEY_CLASSES_ROOT\HistoryZapper.FormCleaner.1
- HKEY_CLASSES_ROOT\HistoryZapper.HistoryEntries
- HKEY_CLASSES_ROOT\HistoryZapper.HistoryEntries.1
- HKEY_CLASSES_ROOT\HistoryZapper.HZMgr
- HKEY_CLASSES_ROOT\HistoryZapper.HZMgr.1
- HKEY_CLASSES_ROOT\HistoryZapper.TypedURLs
- HKEY_CLASSES_ROOT\HistoryZapper.TypedURLs.1
- HKEY_CLASSES_ROOT\Interface\{04D7391C-AB32-4921-84F3-B63FC0EEDF43}
- HKEY_CLASSES_ROOT\Interface\{09F19D39-3084-47B0-B1CE-26581074BC36}
- HKEY_CLASSES_ROOT\Interface\{2CEC1D83-1F31-41A7-B2BC-A2FE25E3BF34}
- HKEY_CLASSES_ROOT\Interface\{41943AC1-46DC-41EF-A365-713C14C50A06}
- HKEY_CLASSES_ROOT\Interface\{439508F6-E48B-4095-B000-ADC7A02AB29E}
- HKEY_CLASSES_ROOT\Interface\{4A0F42B7-A61B-4131-BF41-BF05A2635BFD}
- HKEY_CLASSES_ROOT\Interface\{4E86A93F-4E89-45FD-866B-80D25B0F21A6}
- HKEY_CLASSES_ROOT\Interface\{9DBDD71C-0A7F-48AC-9FFA-E102B3750B9D}
- HKEY_CLASSES_ROOT\Interface\{C2E56E18-2F04-4AB9-9333-B2DB3C350956}
- HKEY_CLASSES_ROOT\Interface\{C7E7863D-2EF7-46F9-A2C2-DD08B2B3C0A5}
- HKEY_CLASSES_ROOT\Interface\{CA74A032-869B-4752-927E-D0DA5677DC23}
- HKEY_CLASSES_ROOT\Interface\{E9CBBEED-20B6-456C-8589-CF364D9D2370}
- HKEY_CLASSES_ROOT\Interface\{F8C5EA77-7D72-405C-B90A-093655B0F544}
- HKEY_CLASSES_ROOT\TypeLib\{32BA13AF-001C-456E-8825-8D53077460AC}
- HKEY_CLASSES_ROOT\TypeLib\{844C39EC-7EA4-4F11-BCE6-28404FD768E3}
- HKEY_CLASSES_ROOT\TypeLib\{8FCD3B3F-6F3E-4BB2-9C37-B03B27F71857}
- HKEY_CLASSES_ROOT\TypeLib\{BA3EFF3D-B557-45DC-A59D-2CF8AA4A4036}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{197AB1D7-A7DD-4C86-A938-1FCC0DB21B85}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SWAR
- HKEY_USERS\*\Software\Comet Systems
- HKEY_CLASSES_ROOT\CLSID\{2D51D869-C36B-42bd-AE68-0A81BC771FA5}
- HKEY_CLASSES_ROOT\CLSID\{7BED0340-176B-44bc-915E-C21C1DD6F617}
- HKEY_CLASSES_ROOT\CLSID\{CA356D79-679B-4b4c-8E49-5AF97014F4C1}
- HKEY_CLASSES_ROOT\CLSID\{D49E9D35-254C-4c6a-9D17-95018D228FF5}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CA356D79-679B-4B4C-8E49-5AF97014F4C1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA356D79-679B-4b4c-8E49-5AF97014F4C1}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Starware
- HKEY_USERS\*\Software\Starware
Starware Toolbar might create following registry values:
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main\ErrorThresholds|404
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main\ErrorThresholds|500
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|DM_Server
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{D49E9D35-254C-4c6a-9D17-95018D228FF5}
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D49E9D35-254C-4C6A-9D17-95018D228FF5}
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{2D51D869-C36B-42BD-AE68-0A81BC771FA5}
Starware Toolbar might create registry values with following data:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|*|http://search.cometsystems.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|*|*\dmserver.exe*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search|SearchAssistant|*starware.com*
- HKEY_USERS\*\Software\Starware\SearchAssistant|SearchAssistant|*starware.com*
Starware Toolbar might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for Starware Toolbar free of charge
|