<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>im-infected.com &#187; Adware</title>
	<atom:link href="http://www.im-infected.com/category/adware/feed" rel="self" type="application/rss+xml" />
	<link>http://www.im-infected.com</link>
	<description></description>
	<lastBuildDate>Mon, 06 Sep 2010 01:16:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Widgi Toolbar</title>
		<link>http://www.im-infected.com/adware/widgi-toolbar.html</link>
		<comments>http://www.im-infected.com/adware/widgi-toolbar.html#comments</comments>
		<pubDate>Sun, 09 May 2010 12:34:04 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[How to remove Widgi Toolbar]]></category>
		<category><![CDATA[IWidgi Toolbar Removal]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2667</guid>
		<description><![CDATA[Widgi Toolbar is a potentially unwanted application that will register itself as a toolbar for Internet Explorer. Widgi Toolbar will alter registry entries to make itself run automatically and install as an IE component.



Type
Adware


Sub-Type
Downloader


Aliases
 


OS Affected
Windows


Detected By
Sophos



What are the Symptoms of Widgi Toolbar Infection?
It will modify Windows Registry and add the following entries:

HKEY_CLASSES_ROOT\Interface\{2DC9C611-D7C2-42A3-9312-BFF512812022}
&#8220;(Default)&#8221; = &#8220;IWidgiToolbarHost&#8221;
KEY_CLASSES_ROOT\Interface\{C3ABD5A3-E699-4B9F-97FF-25B121A41276 &#8220;(Default)&#8221; = [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/adware/widgi-toolbar.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AntiToolbar</title>
		<link>http://www.im-infected.com/adware/antitoolbar.html</link>
		<comments>http://www.im-infected.com/adware/antitoolbar.html#comments</comments>
		<pubDate>Sat, 02 Jan 2010 03:41:01 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[AntiToolbar Trojan]]></category>
		<category><![CDATA[AntiToolbar Virus]]></category>
		<category><![CDATA[Remove AntiToolbar]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2169</guid>
		<description><![CDATA[AntiToolbar is a misleading security application that displays falsified security reports on the infected computer. Upon execution, AntiToolbar will dropped malicious files and modifies registry entries to run  itself when Windows is started.



Type
Adware


Sub-Type
Downloader


Aliases
 


OS Affected
Windows


Detected By
Symantec



What are the Symptoms of AntiToolbar Infection?

It will modify Windows Registry and add the following entries:

KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Uninstall\{11A6DB90-161E-4E1C-9516-75ED6A67033D}_is1
HKEY_CURRENT_USER\S-1-5-21-1172441840-534431857-1906119351-500

AntiToolbar threat will drop the following malicious files:

C:\Documents [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/adware/antitoolbar.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Adware.Zwunzi</title>
		<link>http://www.im-infected.com/adware/adware-zwunzi.html</link>
		<comments>http://www.im-infected.com/adware/adware-zwunzi.html#comments</comments>
		<pubDate>Sat, 05 Dec 2009 03:15:12 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[Adware.Zwunzi]]></category>
		<category><![CDATA[Zwunzi Adware]]></category>
		<category><![CDATA[Zwunzi Search]]></category>
		<category><![CDATA[Zwunzi Toolbar]]></category>
		<category><![CDATA[Zwunzi Virus]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=2042</guid>
		<description><![CDATA[Adware.Zwunzi is an considered an adware program because the way it installs on computer is by means of another program. Adware.Zwunzi will install itself separately and without users consent as a Browser Search Plugin for Internet Explorer and Mozilla Firefox.



Type
Adware


Sub-Type
Toolbar


Aliases
 


OS Affected
Windows


Detected By
Symantec



How to Remove Adware.Zwunzi Manually
1. Disable System Restore
- On Desktop, right click on &#8220;My Computer&#8221; then [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/adware/adware-zwunzi.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>mindsparksearch.com</title>
		<link>http://www.im-infected.com/adware/mindsparksearch-com.html</link>
		<comments>http://www.im-infected.com/adware/mindsparksearch-com.html#comments</comments>
		<pubDate>Mon, 12 Oct 2009 03:13:13 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[mindspark search page]]></category>
		<category><![CDATA[mindsparksearch virus]]></category>
		<category><![CDATA[mindsparksearch.com]]></category>
		<category><![CDATA[mindsparksearch.com redirect]]></category>
		<category><![CDATA[mindsparksearch.com removal]]></category>
		<category><![CDATA[remove mindsparksearch.com]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=1628</guid>
		<description><![CDATA[mindsparksearch.com or MindSpark Search Page virus is an adware program that will set itself as part of Internet browser and configured as the default search tool. mindsparksearch.com can be acquired by downloading malicious program from file-sharing networks and unfamiliar websites.



Type
Adware


Sub-Type
Hijacker


Aliases
 -


OS Affected
Windows


Detected By
-



How to Remove mindsparksearch.com Manually
1. Restart your computer in SafeMode
- After Power-On the computer, just [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/adware/mindsparksearch-com.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Z-Connect</title>
		<link>http://www.im-infected.com/adware/z-connect.html</link>
		<comments>http://www.im-infected.com/adware/z-connect.html#comments</comments>
		<pubDate>Mon, 12 Oct 2009 02:42:51 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[how to remove z-connect]]></category>
		<category><![CDATA[z-connect]]></category>
		<category><![CDATA[z-connect dialer]]></category>
		<category><![CDATA[z-connect ISP]]></category>
		<category><![CDATA[z-connect removal tool]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=1621</guid>
		<description><![CDATA[Z-Connect is an adware program that will create its own shortcut on desktop computer as dialer for Internet connection. Z-Connect will also modify system and Internet settings to configure this connection as the service provider when compromised user tries to connect to Internet.



Type
Adware


Sub-Type
Dialer


Aliases
 -


OS Affected
Windows


Detected By
-



What are the Symptoms of Z-Connect Infection?
It will modify Windows Registry and [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/adware/z-connect.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adware.DoubleD (Desktop Smiley Toolbar)</title>
		<link>http://www.im-infected.com/adware/adware-doubled-desktop-smiley-toolbar.html</link>
		<comments>http://www.im-infected.com/adware/adware-doubled-desktop-smiley-toolbar.html#comments</comments>
		<pubDate>Thu, 20 Aug 2009 01:33:51 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Adware]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=982</guid>
		<description><![CDATA[Adware.DoubleD is a potentially unwanted application or adware program that displays out-of-context advertisements on the affected computers. It will also add a Desktop Smiley Toolbar on the computer.



Type
Adware


Sub-Type
Downloader


Aliases
Desktop Smiley Toolbar


OS Affected
Windows


Detected By
Sophos




What Adware.DoubleD Does?
It will modify Windows Registry and add the following entries:

HKEY_CURRENT_USER\Software\DoubleD
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&#38;Funband Serach
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Ext\Stats\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Settings\User Agent
HKEY_CURRENT_USER\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
HKEY_CLASSES_ROOT\AIMActiveXDLL.AIMHelper.1
HKEY_CLASSES_ROOT\AIMActiveXDLL.AIMHelper
HKEY_CLASSES_ROOT\AppID\AIMActiveXDLL.DLL
HKEY_CLASSES_ROOT\AppID\AxGifAnimator.DLL
HKEY_CLASSES_ROOT\AppID\{57ABA38E-6535-48F3-99FD-EFDC62137C78}
HKEY_CLASSES_ROOT\AppID\{E97BE7A8-7FBA-49FA-A742-BCFB5DAA0ED5}
HKEY_CLASSES_ROOT\AxGifAnimator.GifAnimator.1
HKEY_CLASSES_ROOT\AxGifAnimator.GifAnimator
HKEY_CLASSES_ROOT\CLSID\{27FF1EE8-8CCC-49E1-B801-F212E3744E80}
HKEY_CLASSES_ROOT\CLSID\{2E8E2100-98CB-4AAC-9480-63A281ACAFF5}
HKEY_CLASSES_ROOT\CLSID\{3FB17508-0BF4-4FDE-845A-323A1052957C}
HKEY_CLASSES_ROOT\CLSID\{51B67A88-02D0-43CB-8D12-5CA3E2D4CF49}
HKEY_CLASSES_ROOT\CLSID\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
HKEY_CLASSES_ROOT\CLSID\{D44CC2FB-77B8-48A5-A5DC-F961F2D258FB}
HKEY_CLASSES_ROOT\Installer\Features\7AD2B90A400825245BC229FFAEC2D5DB
HKEY_CLASSES_ROOT\Installer\Products\7AD2B90A400825245BC229FFAEC2D5DB
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\2E6AF0CA64E1D164E8A1442284D2E132
HKEY_CLASSES_ROOT\Interface\{3FB17508-0BF4-4FDE-845A-323A1052957C}
HKEY_CLASSES_ROOT\Interface\{42C23154-00FA-4A93-9DE9-3EB523CFFFF6}
HKEY_CLASSES_ROOT\Interface\{803E73FE-CB73-4D49-8AFF-653FD6F44171}
HKEY_CLASSES_ROOT\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}
HKEY_CLASSES_ROOT\Interface\{EDB1A56E-2224-4C79-A4BD-42A39C6E4608}
HKEY_CLASSES_ROOT\OEActiveXDLL.DesktopButtonHandler.1
HKEY_CLASSES_ROOT\OEActiveXDLL.DesktopButtonHandler
HKEY_CLASSES_ROOT\OEActiveXDLL.DesktopOEAddin1.1
HKEY_CLASSES_ROOT\OEActiveXDLL.DesktopOEAddin1
HKEY_CLASSES_ROOT\TypeLib\{0514C9B0-E4C6-4D6B-A3A6-B38BC280B115}
HKEY_CLASSES_ROOT\TypeLib\{22C12739-C111-44C6-9BB7-F335C2A9BE2A}
HKEY_CLASSES_ROOT\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945}
HKEY_CLASSES_ROOT\TypeLib\{D335D84D-61D8-4B5F-9C4E-067DC8B27ED5}
HKEY_LOCAL_MACHINE\SOFTWARE\DoubleD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Uninstall\Desktop Smiley Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Uninstall\{A09B2DA7-8004-4252-B52C-92FFEA2C5DBD}
HKEY_LOCAL_MACHINE\SOFTWARE\MimarSinan\InstallAware\Ident.Cache\{A09B2DA7-8004-4252-B52C-92FFEA2C5DBD}
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox
HKEY_LOCAL_MACHINE\SOFTWARE\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}

The threat will drop [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/adware/adware-doubled-desktop-smiley-toolbar.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adware:Win32/Zhongsou</title>
		<link>http://www.im-infected.com/adware/adwarewin32zhongsou.html</link>
		<comments>http://www.im-infected.com/adware/adwarewin32zhongsou.html#comments</comments>
		<pubDate>Wed, 05 Aug 2009 01:54:44 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Adware]]></category>

		<guid isPermaLink="false">http://www.im-infected.com/?p=840</guid>
		<description><![CDATA[Adware:Win32/Zhongsou is a potentially unwanted application that will monitor web browsing habits of users on the infected computer. Adware:Win32/Zhongsou will generate pop-up advertisements based on the observed behaviour. 



Type
Adware


Sub-Type
Downloader


Aliases
Win32/Adware.Zhongsou,
GRAY_Sml.8Z0034


OS Affected
Windows


Detected By
MMPC




What Adware:Win32/Zhongsou Does?
It will modify Windows Registry and add the following entries:

HKLM\SOFTWARE\IETimber
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IETimber
HKLM\SOFTWARE\Classes\Toolbar_bho.IeToolbar.1
HKLM\SOFTWARE\Classes\Toolbar_bho.IeToolbar
HKLM\SOFTWARE\Classes\CLSID\{489873CE-F3E1-44A3-8E89-04BE26BE4446}
HKLM\SOFTWARE\Classes\TypeLib\{065683C4-C71A-47F1-830B-7D9309D3913D}\1.0
HKLM\SOFTWARE\Classes\Interface\{8FF78EFD-0213-4A73-AC23-6A489190DBFB}
HKLM\SOFTWARE\Classes\Toolbar_bho.IeToolbar.1 = &#8220;ietimber&#8221;
HKLM\SOFTWARE\Classes\Toolbar_bho.IeToolbar.1\CLSID = &#8220;{489873ce-f3e1-44a3-8e89-04be26be4446}&#8221;
HKLM\SOFTWARE\Classes\Toolbar_bho.IeToolbar = &#8220;ietimber&#8221;
HKLM\SOFTWARE\Classes\Toolbar_bho.IeToolbar\CurVer = &#8220;toolbar_bho.ietoolbar.1&#8243;
HKLM\SOFTWARE\Classes\CLSID\{489873CE-F3E1-44A3-8E89-04BE26BE4446} = &#8220;ietimber&#8221;
HKLM\SOFTWARE\Classes\CLSID\{489873CE-F3E1-44A3-8E89-04BE26BE4446}\VersionIndependentProgID = &#8220;toolbar_bho.ietoolbar&#8221;
HKLM\SOFTWARE\Classes\CLSID\{489873CE-F3E1-44A3-8E89-04BE26BE4446}\InprocServer32 = &#8220;%ProgramFiles%\internet explorer\ietimber\ietimber.dll&#8221;
HKLM\SOFTWARE\Classes\CLSID\{489873CE-F3E1-44A3-8E89-04BE26BE4446}\TypeLib = &#8220;{065683c4-c71a-47f1-830b-7d9309d3913d}&#8221;
HKLM\SOFTWARE\Classes\TypeLib\{065683C4-C71A-47F1-830B-7D9309D3913D}\1.0 [...]]]></description>
		<wfw:commentRss>http://www.im-infected.com/adware/adwarewin32zhongsou.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
