Home Rogue Websites Find-TwoSite.com

Find-TwoSite.com

Posted: November 17, 2008

Find-TwoSite.com is a rogue site that the malicious Security Toolbar 7.1 may redirect your homepage to. The Find-TwoSite.com will monitor your web activity, bombard you with pop up ads, and disable you from visiting other websites and download malware onto your computer. If you find yourself redirected to this site remove the infection IMMEDIATELY. Use a reliable anti-spyware software program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 afzdbl.dll
    2 bgwttyl.dll
    3 cfqbw.dll
    4 cqsfk.dll
    5 dxovx.dll
    6 dyrwls.dll
    7 fdpzgi.dll
    8 gtawclv.dll
    9 gusur.dll
    10 iesplugin.dll
    11 iesuninst.exe
    12 isaddon.dll
    13 isamini.exe
    14 isamonitor.exe
    15 khtbpdl.dll
    16 lrnjnzf.dll
    17 Online Security Guide.lnk
    18 Online Security Test.url
    19 pmmon.exe
    20 pmsngr.exe
    21 pmuninst.exe
    22 psndz.dll
    23 Security Troubleshooting.lnk
    24 tinyproxy.exe
    25 tkrsw.dll
    26 ugofuq.dll
    27 vgibz.dll
    28 Video ActiveX Access
    29 vjxwnn.dll
    30 wzhtjqo.dll
    31 zpuwriz.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5574E139-F59C-4bee-9A61-150B0D3A16C7}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6DEEE498-08CC-43F0-BCA0-DBB5A25C9501}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper objects\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IExplorer Security Plug-inInternet Explorer Secure BarMessenger Service
Loading...