FavoriteMan Spyware Profile

FavoriteMan is an extremely dangerous spyware program.  It was first discovered on January 4 in 2005.  It was created by Mindset Interactive.

FavoriteMan has Browser Hijacking capabilities.  It can monitor your browsing activity, upload the information to a remote server, and redirect your browsing to its affiliate sites.  It will also add its affiliate sites to your Favorites list.

The worst part about FavoriteMan is its Trojan Downloader capabilities.  It can download more than 30 different adware and spyware programs.  This can spell disaster for your computer’s performance and your security.

If you have a FavoriteMan infection, you have to remove it with an antispyware program.  Because it downloads other adware and spyware programs, the infection would be just too pervasive to even consider a manual removal.  ZookaWare PC Cleaner is your best bet for removing FavoriteMan.

Also Known As:
AdWare.F1Organizer,
Adware/NetPals,
ofrg (the name of the DLL program file),
TrojanDownloader.Win32.BHO,
TrojanDownloader.Win32.Rameh,
Windows Help 4 Smrt Browsing

Associated Files:
adware.txt, aess2.dll, atpartners.dll, atpart~1.dll, in10b6s.dll, pdfzzy.dll.
emesx.dll, f1.dll, favboot.dll, favman.dll, favorite.dll, fone.dll, gr02.dll, im64.dll, lwz.dll, mbr32.dll, mpz300.dll, n3tpa1p.dll, ofrg.dll, otw0i.dll, ss32.dll, sysldr.dll in Windowssystem32
emesx.dll, f1.dll, favboot.dll, favman.dll, favorite.dll, fone.dll, im64.dll, lwz.dll, n3tpa1p.dll, ofrg.dll, ss32.dll, sysldr.dll in Windowssystem
HKEY_CLASSES_ROOTclsid{000000f1-34e3-4633-87c6-1aa7a44296da}
HKEY_CLASSES_ROOTclsid{00000ef1-0786-4633-87c6-1aa7a44296da}
HKEY_CLASSES_ROOTclsid{00000ef1-34e3-4633-87c6-1aa7a44296da}
HKEY_CLASSES_ROOTclsid{139d88e5-c372-469d-b4c5-1fe00852ab9b}
HKEY_CLASSES_ROOTclsid{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}
HKEY_CLASSES_ROOTf1.organizer
HKEY_CLASSES_ROOTf1.organizercurver f1.organizer.1
HKEY_CLASSES_ROOTfone.organizer
HKEY_CLASSES_ROOTsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{000000da-0786-4633-87c6-1aa7a4429ef1}
HKEY_CLASSES_ROOTsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{000000f1-34e3-4633-87c6-1aa7a44296da}
HKEY_CLASSES_ROOTsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{00000ef1-0786-4633-87c6-1aa7a44296da}
HKEY_CLASSES_ROOTsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{00000ef1-34e3-4633-87c6-1aa7a44296da}
HKEY_CLASSES_ROOTsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{139d88e5-c372-469d-b4c5-1fe00852ab9b}
HKEY_CLASSES_ROOTsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}
HKEY_CLASSES_ROOTtypelib{00000ef1-34e3-4633-87c6-1aa7a44296da}
HKEY_CLASSES_ROOTtypelib{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}
HKEY_CLASSES_ROOTtypelib{ef100007-f409-426a-9e7c-cb211f2a9030}
HKEY_CLASSES_ROOTtypelib{ef100607-f409-426a-9e7c-cb211f2a9030}
HKEY_CURRENT_USERobjectobject
HKEY_CURRENT_USERsoftwaremicrosoftwindowscounter
HKEY_CURRENT_USERsoftwaremicrosoftwindowsserver
HKEY_LOCAL_MACHINEsoftwareclassesclsid{000000da-0786-4633-87c6-1aa7a4429ef1}
HKEY_LOCAL_MACHINEsoftwareclassesclsid{000000f1-34e3-4633-87c6-1aa7a44296da}
HKEY_LOCAL_MACHINEsoftwareclassesclsid{00000ef1-0786-4633-87c6-1aa7a44296da}
HKEY_LOCAL_MACHINEsoftwareclassesclsid{00000ef1-34e3-4633-87c6-1aa7a44296da}
HKEY_LOCAL_MACHINEsoftwareclassesclsid{139d88e5-c372-469d-b4c5-1fe00852ab9b}
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{000000f1-34e3-4633-87c6-1aa7a44296da}
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{00000ef1-0786-4633-87c6-1aa7a44296da}
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{00000ef1-34e3-4633-87c6-1aa7a44296da}
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{139d88e5-c372-469d-b4c5-1fe00852ab9b}
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{b549456d-f5d0-4641-bced-8648a0c13d83}
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorerbrowser helper objects{ebbd88e5-c372-469d-b4c5-1fe00352ab9b}
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallf1

Download Free Scan
ZookaWare runs on Windows Vista, 7, 8 and 10. It has no ads, popups or bundled software and fully uninstalls by clicking Start > All Programs > select ZookaWare and click Uninstall.

2 Responses

  1. Cristopher King says:

    I used Spyware Doctor and it said I have FavoriteMan. I pressed fix to delete and 10 minutes later it says its there AGAIN! On my desktop it says Warning Spyware Threat has been detected on your PC Your computer has several fatal errors due to this activity. Then it says click here to scan your pc for spyware. When I click it came up with a page that sells spyware products! I was freaking out if it wasn’t my brother who told my that I should try SpyZooka. It worked like a miracle! I’m so happy now! Thank you!

  2. Megan Allan says:

    After many painful hours, and doing system restores, that I thought had worked, the FavoriteMan kept returning. I finally just installed SpyZooka and that did the trick!
    Save yourself some trouble, download the software. Its worth it!!!

Leave a Reply

Your email address will not be published. Required fields are marked *

css.php