Home
Articles
Spyware Research
Support
Scan Now
Purchase
F.A.Q.
Top 25 Spyware:
Glossary Latest Detections ![]() |
Hijacker/SmartFinderAlias: Shopping Wizard, SmartFinder
Description: 123search is the Browser helper Object. Threat type: Hijacker - A Hijacker is a software application that takes control of your browser's settings. Usually it changes your home page and redirects it to some unknown site or modifies your search settings. It prevents you from changing back your browser's settings. An infected browser usually operates much slower. Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy. Detection: SpyNoMore detects Hijacker/SmartFinder: Yes Threat risk: High Risk Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans. Symptoms: Running Process Signatures: N/A File Signatures: %FAVORITES%\search the web.url %FAVORITES%\only sex website.url %FAVORITES%\seven days of free porn.url Registered Dll (Dynamic Link Library) Signatures: N/A Folder Signatures: N/A Registry Signatures: HKLM\system\currentcontrolset\services\ 6q'8 HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{14913c42-fa8e-dbbc-21ea-6eb6ca2408bd} HKLM\software\adverts HKCR\clsid\{4a7621f7-51a8-8816-226b-81ee72e669cf} HKCR\clsid\{9331bd47-3ca2-b77d-8df9-1e8a3da4557f} HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{202b0efd-2cb9-039b-2b11-a3579d6d56a3} HKLM\software\microsoft\windows\currentversion\uninstall\sw HKCR\clsid\{14913c42-fa8e-dbbc-21ea-6eb6ca2408bd} HKLM\software\microsoft\windows\currentversion\uninstall\se HKLM\software\microsoft\windows\currentversion\uninstall\hsa HKCR\clsid\{6769fc6b-5e56-dfce-14a8-3a23227f30d6} HKCU\software\sno2 HKCR\clsid\{8f5f3fdd-ca3c-1e88-3714-ee2cc672a96f} HKCR\clsid\{4a8dadd4-5a25-4d41-8599-cb7458766220} HKLM\system\currentcontrolset\enum\root\legacy_*008f__6q*00d4*00f5*0013'*00aa*00b4*00c6*00d08 SpyNoMore Collected Residual File Signatures: N/A
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||