SearchForIt Adware Profile

SearchForIt is an adware program created by Search For It, Inc.  It was first discovered on November 13 of 2004.  It can be manually downloaded from either www.searchforit.com or www.adshooter.com.

It is disguised as a toolbar add-on for your browser.  The premise is that it provides buttons that you can click to instantly link to sites you may want to visit, primarily credit cards, adult dating sites, and their affiliated shopping sites.  In all actuality, these buttons only link you to its partner and affiliate websites.

SearchForIt is also a pop-up generator.  It operates when your Internet Explorer is opened and it delivers ads for its partners and affiliates.  These ads will often include tie-ins to clickbank.net, which is known for being displayed on pop-ups.  SearchForIt seems to be related to the adware program called Adshooter.  While their functionality is different, many of the file names are the same.

If you have SearchForIt, you should remove it.  It offers no real benefit, and it can clog your browser’s performance.  It may even lead to browser crashes.  SpyZooka is consistently effective at eliminating this threat.

Also Known As:
Adware.SearchForIt, Adshooter.SearchForIt,
Trojan.Win32.StartPage.ey, Search for it,
The Search Mall, AdShooter, Searchmall

Adware Type: Toolbar

Associated Files:
syssfitb.dll,sysfit.exe,syssfitb2.dll,ca2.dll,replaceSearch.dll,sf.exe,sfita.exe,sfi2.dll

HKEY_CLASSES_ROOT\SYI.SYIObj.1
HKEY_CLASSES_ROOT\SYI.SYIObj
HKEY_CLASSES_ROOT\CLSID\{C109664B-CEB1-420B-B353-D55A561536DD}
HKEY_CLASSES_ROOT\CLSID\{832BEBED-C3DA-4534-A2C2-B2FFF220C820}
HKEY_CLASSES_ROOT\CLSID\{B5F3970B-745E-46AC-B890-E08F69777D80}
HKEY_CLASSES_ROOT\TypeLib\{F43085A3-5FBD-4954-B7BF-00A8F1A1B9FE}
HKEY_CLASSES_ROOT\TypeLib\{919F8A8D-135D-44FC-A809-B36083EEAE35}
HKEY_CLASSES_ROOT\TypeLib\{B9C1DD92-B443-4BF1-B4C0-950E41A9F9F7}
HKEY_CLASSES_ROOT\Interface\{2DB1A6DF-8120-47BD-9DCE-CFCD47B17B24}
HKEY_CLASSES_ROOT\Interface\{AB94D42B-64E9-436F-887C-CF38FE475CFC}
HKEY_CLASSES_ROOT\Interface\{337278B8-50AF-4F67-8929-E7D6B8DDD66B}
HKEY_CLASSES_ROOT\Interface\{FAAEB405-B7B0-4749-81DE-DF36B2D36531}
HKEY_LOCAL_MACHINE\SOFTWAREe\Classes\Ca.Cas
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Ca.Cas.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\drs.n
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ReplaceSearch.ReplaceSearchCtl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ReplaceSearch.ReplaceSearchCtl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{832BEBED-C3DA-4534-A2C2-B2FFF220C820}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B5F3970B-745E-46AC-B890-E08F69777D80}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{C109664B-CEB1-420B-B353-D55A561536DD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\searchforitsearchforit
HKEY_CURRENT_USER\SOFTWARE\searchforit
HKEY_CURRENT_USER\SOFTWARE\DR_S
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar “{C109664B-CEB1-420B-B353-D55A561536DD}” = “[RANDOM HEX NUMBERS]”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser “{C109664B-CEB1-420B-B353-D55A561536DD}” = “[RANDOM HEX NUMBERS]”

Download Free Scan

Leave a Reply

Your email address will not be published. Required fields are marked *

Products

Contact

css.php