2Search Spyware Profile

2Search is a spyware program that intercepts searches in Google and puts its affiliate sites at the top of the search results page.  It also monitors browsing history and search engine queries in order to deliver pop-up ads based on them.  It usually comes bundled with other software, or may be manually installed individually.  It is set to run every time Windows starts up, so it can be difficult for many antispyware programs to remove.

ZookaWare PC Cleaner can remove 2Search and all its components completely.

Associated Files:
%ProgramFiles%\2search\2search.dll,
%ProgramFiles%\2Search\date.dat,
%ProgramFiles%\2Search\defaultne.txt,
%ProgramFiles%\2search\get.exe,
%ProgramFiles%\2Search\getst.exe,
%ProgramFiles%\2Search\main.exe,
%ProgramFiles%\2Search\plugin.dll,
%ProgramFiles%\2Search\svchost.exe,
%ProgramFiles%\2Search\uninstall.exe,
%ProgramFiles%\The Guard\the007guard.ocx,
%ProgramFiles%\The Guard\the007installer.exe,
%System%\007guard.exe,
%System%\2searchinstaller.exe,
%System%\feeds\1.dat,
%System%\feeds\2.dat,
%System%\feeds\3.dat,
%System%\feeds\4.dat,
%System%\feeds\feed.dst,
%ProgramFiles%\IM Names\IM-svr.exe,
%ProgramFiles%\IM Names\IMNames.exe,
%ProgramFiles%\IM Names\1.exe,
%ProgramFiles%\IM Names\main.exe,
%UserProfile%\Application Data\IM-Names\exclusion_AOL.ini,
%UserProfile%\Application Data\IM-Names\exclusion_MSN.ini,
%UserProfile%\Application Data\IM-Names\exclusion_Yahoo.ini

Registry:
HKEY_CLASSES_ROOT\Interface\{03BE31FE-6526-4D9C-B197-4A3E5DCFF696}
HKEY_CLASSES_ROOT\Interface\{8395562C-205D-434B-BE19-3C4E07E6D415}
HKEY_CLASSES_ROOT\Interface\{9C33138E-0581-4C28-A943-BC238A68208C}
HKEY_CLASSES_ROOT\Interface\{F79A1360-2754-43F3-8297-8A39408BE2BF}
HKEY_CLASSES_ROOT\TypeLib\{68E774CB-72D1-4A52-B55B-C0B1011E013B}
HKEY_CLASSES_ROOT\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F}
HKEY_CLASSES_ROOT\IEsearch.clsIESpy
HKEY_CLASSES_ROOT\GoogleCatch.clsIESpy
HKEY_CLASSES_ROOT\Interface\{0EB61AF8-0B15-48B6-A971-1F206F2E3D5E}
HKEY_CLASSES_ROOT\Component Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKEY_CLASSES_ROOT\TypeLib\{20048BB0-DB68-11CF-9CAF-00AA006CB425}
HKEY_CLASSES_ROOT\TypeLib\{20048BB0-DB68-11CF-9CAF-00AA006CB425}
HKEY_CLASSES_ROOT\TypeLib\{4508E20A-ACAD-11D2-9FC0-00550076E06F}
HKEY_CLASSES_ROOT\The007Guard.The007GuardCtrl.1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4508E20C-ACAD-11D2-9FC0-00550076E06F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4508E20C-ACAD-11D2-9FC0-00550076E06F}
HKEY_CURRENT_USER\Software\IMAdvertiser\AOL
HKEY_CURRENT_USER\Software\IMAdvertiser\MSN
HKEY_CURRENT_USER\Software\IMAdvertiser\Yahoo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4508E20C-ACAD-11D2-9FC0-00550076E06F}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\2search
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\2search
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\the guard
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\the guard
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR SFX\C:\%Program Files%The Guard
HKEY_CURRENT_USER\WinRAR SFX\C:\%Program Files%The Guard
HKEY_CURRENT_USER\SOFTWARE\WinRAR SFX\C:\%Program Files%2search
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR SFX\C:\%Program Files%2search
Can add value:  “IMprocess” = “%ProgramFiles%\IM Names\IM-svr.EXE””[NAME]” = “[VALUE]” to the registry subkey:  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to make it run every time Windows boots up.
Can add the entry *.hottestgames.net to the registry subkey:  HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow
Can add the values “C:\%Program Files%IM Names” = “%ProgramFiles%\IM Names” and “C:\%Program Files%2search”: “%ProgramFiles%\2search” to the registry subkey:  HKEY_CURRENT_USER\Software\WinRAR SFX

Also Known As:
Adware.2Search (Symantec),
clsIESpy, GoogleCatch,
007guard, 007Installer,
The007Guard, msnnames,
msn names, IM Names,
IMNames

Download Free Scan
ZookaWare runs on Windows Vista, 7, 8 and 10. It has no ads, popups or bundled software and fully uninstalls by clicking Start > All Programs > select ZookaWare and click Uninstall.

Leave a Reply

Your email address will not be published. Required fields are marked *

css.php