The following is a detail page of Virtual Grub Street's Adware & Malware Indentifier Index:
The information in the Adware & Malware Indentifier Index is the result of thousands of web searches. It can not, however, possibly be complete. The subject is vast and constantly changing. Moreover, vendor uninstall tools and other removal tools do not necessarily remove all of an infection from your computer. Vendor uninstall tools, for instance, may silently leave cookies or other tracking software installed. It is suggestible to follow up a removal with one or more adware scans and/or to do an inspection using a HijackThis log. The information on the page is not guaranteed correct and any use you may choose to make of it is entirely at your own risk.
ISearchTech.SideFind
- Associated Worms/Trojans: Downloader.Dyfica.3.L; Troj/LowZone-AL [a.k.a. Downloader-QG; QLowZones-26; Trojan.WinREG.LowZones.f ]; Troj/SideFind-A; TR/Spy.Shutcom; TrojanDownloader:Win32/IstBar.EO; W32/Istbar.O@dl.
- Executable Files: sfexd001.exe; sidefind.exe; sidefind[1].exe; istrecover[1].exe; sskc.exe; ISTsvc.exe.
- Dynamic Link Libraries: sfbho.dll; sidefind.dll.
- Directory/Search Page: http://www.sidefind.com/ist/softwares/sidefind/; http://www.sidefind.com/ist/softwares/sidefind/v1.3/.
- Uninstall page URL: ISearchTech claims that it provides a removal tool for "IST toolbar" (A generic designation for all ISearchTech toolbars? Just a YSB family?) at this location: http://www.ysbweb.com/uninstall.html. It provides two tools each of which requires you to install new software the nature of which is not described.
- Related Articles: Fighting Malware with Standard Windows Tools (February 25, 2007). You may have more in your bag of tricks than you realize. How to Remove the ISearchTech Family; ISearchTech.SideFind Update (08-27-05); How to Remove YourSiteBar; How to Remove Trojan.winreg.LowZones.f; Important Removal Tool Note.
- Notes: Click this link for instructions on >>> How to remove generic / stand-alone versions of Trojan.winREG.LowZones.f.
- Variations on this infection are also known as Troj/SideFind-A [Sophos], ADW_SideFind-A [B, C][TrendMicro] and ADW_sideFind-C [TrendMicro]. This group of trojan downloaded side bars may be identified by the following value being detected in the HKEY_USERS section of the registry: {8CBA1B49-8144-4721-A7B1-64C578C9EED7}.
- According to Sophos, Troj/SideFind-A versions of this infection 'can be uninstalled via the Add or Remove Programs dialog in the Windows Control Panel (Start -> Settings -> Control Panel -> Add/Remove Programs) by selecting "SideFind".' According to the YourSiteBar uninstall page, all versions of this software (i.e. SideFind) can be removed from the standard Windows Add/Remove Programs utility.
- Most versions of this infection can now be removed by using Spybot S&D.
Also See:
- Man-Boy Love Advocate Accused of Using Wikipedia to Troll for Interested Parties (March 4, 2007). Rookie Revolyob, Clayboy, Zanthalon, et al: Why is Wikpedia a Pedophile Haven?
No comments:
Post a Comment