Home Malware Programs Browser Hijackers Findwhatever

Findwhatever

Posted: March 28, 2006

Findwhatever is a browser hijacker that periodically changes Internet Explorer default home page to many advertising web sites. Findwhatever doesn't have any harmful payload. It can silently get into the computer while visiting certain web pages. The spyware runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 autolfn.exe
    2 csrss.exe
    3 dpvsetup.exe
    4 dsndup.exe
    5 label.exe
    6 lasss.exe
    7 mdm.exe
    8 mmc.exe
    9 mshelp.exe
    10 mshta.exe
    11 mssetup.exe
    12 msswchx.exe
    13 mstask.exe
    14 netdde.exe
    15 ntvdm.exe
    16 osk.exe
    17 spoolsv.exe
    18 sptsupd.exe
    19 subst.exe
    20 svchost.exe
    21 ups.exe
    22 w32tm.exe
    23 xcopy.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunClockHKEY_CURRENT_USERSoftwareMicrosoftClockHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddress]
Loading...