1. /
  2. Security Response/
  3. Adware.CSearch

Adware.CSearch

Updated:
February 13, 2007 11:43:13 AM
Type:
Adware
Version:
1.0.0.6
Publisher:
I.S. Technologies
Risk Impact:
Medium
File Names:
CSearch.dll
Systems Affected:
Windows 2000, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003, Windows XP

When Adware.CSearch is installed, it performs the following actions:
  1. Creates the following registry keys:

    HKEY_CLASSES_ROOT\CLSID\{064CB07A-9ECD-46FD-8E10-1D3C5FF218CA}
    HKEY_CLASSES_ROOT\CLSID\{D8FA0364-7866-40A7-B340-A6069265AD9F}
    HKEY_CLASSES_ROOT\Interface\{09C33C5E-2B76-47FE-B97B-9788235A3876}
    HKEY_CLASSES_ROOT\Interface\{F250A919-FB4B-4120-9F2E-E5FE03FB8202}
    HKEY_CLASSES_ROOT\TypeLib\{DEB0BC8B-7405-4B97-9489-89D72C27678A}
    HKEY_CLASSES_ROOT\Csearch.Band
    HKEY_CLASSES_ROOT\Csearch.Band.1
    HKEY_CLASSES_ROOT\Csearch.Redirect
    HKEY_CLASSES_ROOT\Csearch.Redirect.1
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D8FA0364-7866-40A7-B340-A6069265AD9F}
    %HKEY_ALL_USERS%\Software\ISTechnologies

    Note: %HKEY_ALL_USERS% refers to all user entries in HKEY_USERS.

  2. Adds the value:

    {D8FA0364-7866-40A7-B340-A6069265AD9F}

    to the following registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar

  3. Adds the value:

    "(default)" = "http:/ /www.searchmain.com/searching/?d=%s"

    to the registry subkey:

    HKEY_ALL_USERS\Software\Microsoft\Internet Explorer\SearchUrl

  4. Sets the value:

    "Search Page" = "http:/ /www.searchmain.com/"

    in the registry subkeys:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
    HKEY_ALL_USERS\Software\Microsoft\Internet Explorer\Main

  5. Set the value:

    "CustomizeSearch" = "
    http:/ /www.searchmain.com/"

    in the registry subkey:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search

  6. Sets the value:

    "DefaultSearchURL" = "
    http:/ /www.searchmain.com/searching/?d=%s"

    in the registry subkey:

    HKEY_ALL_USERS\Software\Microsoft\Search Assistant


Summary| Technical Details| Removal

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report
Symantec DeepSight Screensaver