2020Search is a browser hijacker spyware program created by Visicom Media.  Despite the claims that Visicom makes about their products not having spyware, 2020Search has all the behaviors associated with a browser hijacker program.  It targets Internet Explorer and replaces its search pane with a searching page located at pop.popuptoast.com/9908/search/search.html, and downloads the Spyware.Shopnav program.  It redirects searches to its own pages.  It also searches for certain files on the computer and uploads them to a remote IP address.  These are all clearly behaviors of a spyware program.

Visicom gives away the fact that they use spyware in their privacy policy.  To quote:  “We also use cookies to collect demographic and profile data for purposes of delivering content specific to your interests,” and “IP addresses are automatically collected by our web server as part of demographic and profile data known as ‘traffic data’ so that data (such as the Web pages you request) can be sent to you.”  What this means in so many words is that they admit to collecting data to send targeted advertisements to you by use of their products.  In other words, it’s spyware.

ZookaWare PC Cleaner can quickly and thoroughly remove 2020Search and ShopNav.

Associated Files:
[%WINDOWS%]\2020search2.dll, [%WINDOWS%]\mssvr.exe, [%SYSTEM%]\2020search.dll, [%SYSTEM%]\2020search2.dll, [%WINDOWS%]\2020install.exe, [%WINDOWS%]\downloaded program files\2020search.dll, [%WINDOWS%]\downloaded program files\2020search.inf, [%WINDOWS%]\system\2020search.dll, [%WINDOWS%]\system\2020search2.dll

HKEY_CLASSES_ROOT\CLSID\ {FC3A74E5-F281-4F10-AE1E-733078684F3C}
HKEY_CLASSES_ROOT\Interface\ {7B9A715E-9D87-4C21-BF9E-F914F2FA953F}
HKEY_CLASSES_ROOT\Interface\ {EAF2CCEE-21A1-4203-9F36-4929FD104D43}
HKEY_CLASSES_ROOT\Interface\ {02CB16D1-4CA7-47FF-8546-C5E925DF33D6}
HKEY_CLASSES_ROOT\TypeLib\ {6D3F5DE4-E980-4407-A10F-9AC771ABAAE6}
HKEY_CLASSES_ROOT\TypeLib\ {E306B3C1-3C68-4EFA-9EBC-0B99C6A918C2}
HKEY_CLASSES_ROOT\ Downloader.Downloader
HKEY_CLASSES_ROOT\ Downloader.Downloader.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ 2020Search2020Search
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ &RSDN Search
HKEY_CURRENT_USER\Software\ 2020Search

Adds value:
“Srng”=”C:\Program Files\Srng\Srng.exe” to registry subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run so that the Spyware.Shopnav executable program runs when you start Windows.

Adds value:
“[default]” = “{4E1075F4-EEC4-4a86-ADD7-CD5F52858C31}” to registry subkeys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser

