Adware . WhenUSearch (Summary)
Software Name: WhenUSearch
Company Name: WhenU.com Inc
Product Name: WhenUSearch
Classification: Adware
Website: http://www.whenusearch.com
Brief:
WhenUsearch has 3 versions; a desktop toolbar, a browser toolbar and a browser sidebar. When visiting various websites WhenUsearch will display popup advertising for discounts or coupons. Usually installed by drive-by Active-X installer.
IMPORTANT!
Some of the Adware.WhenUSearch components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of WhenUSearch
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
WhenUSearch might create following folders (and inject its files inside
the folders):
- %PROGRAMS%\WhenUSearch
- %PROGRAM_FILES%\WhenUSearch
- %PROGRAM_FILES%\Save
- %PROGRAMS%\WhenU
WhenUSearch might create following files (some of the files might be
loaded in memory while the software is running):
- %PROFILE%\Local Settings\Temp\whenu.exe
- %WINDOWS%\Downloaded Program Files\SearchInst.inf
- %WINDOWS%\Downloaded Program Files\SNDbMark.dll
- %PROFILE%\Local Settings\Temp\wuinstsecs.cab
- %WINDOWS%\wuinst.dll
- %WINDOWS%\wuinst.inf
- %SYSTEM%\wuinst.dll
- %SYSTEM%\wuinst.inf
- %WINDOWS%\system\wuinst.dll
- %WINDOWS%\system\wuinst.inf
- %COMMON_DESKTOPDIRECTORY%\Toolbar.lnk
- %PROGRAM_FILES%\WhenUSearch\search.dll
- %PROGRAM_FILES%\WhenUSearch\Search.exe
- %PROGRAM_FILES%\WhenUSearch\Uninst.exe
- %PROGRAM_FILES%\WhenUSearch\whse.exe
- %PROFILE%\Local Settings\Temp\GLF9.exe
- %PROFILE%\Local Settings\Temp\SaveNowInst.exe
- %PROGRAM_FILES%\Save\Save.exe
- %WINDOWS%\Downloaded Program Files\WUInst.dll
- %WINDOWS%\Downloaded Program Files\WUInst.inf
WhenUSearch is often accompanied by the following tracking cookies:
n/a
WhenUSearch might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\CLSID\{FC327B3F-377B-4CB7-8B61-27CD69816BC3}
- HKEY_CLASSES_ROOT\WUSE.1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FC327B3F-377B-4CB7-8B61-27CD69816BC3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhenUSearch
- HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSearch
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/SNDbmark.dll*
- HKEY_CLASSES_ROOT\CLSID\{45E5DADB-DFDF-4FC3-A46C-DD34B6CDDB38}
- HKEY_CLASSES_ROOT\CLSID\{715839CD-ABEC-45D8-A83C-1275F2D837CD}
- HKEY_CLASSES_ROOT\CLSID\{763BD795-24AE-44d7-82D8-F9A1EE799729}
- HKEY_CLASSES_ROOT\CLSID\{BA2325ED-F9EB-4830-8FCE-0BC35B16969B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{737830B7-F1F9-4bae-A8FC-1433C71BEDFF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA2325ED-F9EB-4830-8FCE-0BC35B16969B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhenUSearchB
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhenUSearchF
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Explorer Bars\{715839CD-ABEC-45D8-A83C-1275F2D837CD}
- HKEY_CLASSES_ROOT\CLSID\{E2F2B9D0-96B9-4B25-B90C-636ECB207D18}
- HKEY_CLASSES_ROOT\WUSN.1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2F2B9D0-96B9-4B25-B90C-636ECB207D18}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/WUInst.dll*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SaveNow
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhenUSaveMsg
- HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave
- HKEY_USERS\*\Software\WhenU
WhenUSearch might create following registry values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WhenUSearch
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\SNDbMark.dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{45E5DADB-DFDF-4FC3-A46C-DD34B6CDDB38}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WhenUSearchWHSE
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{45E5DADB-DFDF-4FC3-A46C-DD34B6CDDB38}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WhenUSave
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\WUInst.dll
WhenUSearch might create registry values with following data:
n/a
WhenUSearch might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for WhenUSearch free of charge
|