Home Malware Programs Adware FindWide

FindWide

Posted: April 8, 2013

Threat Metric

Ranking: 1,599
Threat Level: 5/10
Infected PCs: 193,036
First Seen: April 8, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

FindWide Screenshot 1FindWide is a browser hijacker that, once installed on the infected computer, adds a browser add-on on the compromised Internet browser. FindWide installs itself on the targeted PC together with numerous shareware or freeware applications. Usually, the option to install a toolbar of FindWide is pre-checked and even invisible during the common installation process. FindWide hijacks search results in any legal search engine and redirect victims to its own website called search.findwide.com. Search.findwide.com is supported by FindWide, which displays pop-up ads from Microsoft and is probably using Bing results.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\TNT2\2.0.0.1928\TNT2User.exe.vir File name: TNT2User.exe.vir
Size: 687.87 KB (687872 bytes)
MD5: e9c6ffc49b1a60794d1d9f39b86c0cf3
Detection count: 1,867
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\TNT2\2.0.0.1928\TNT2User.exe.vir
Group: Malware file
Last Updated: November 20, 2022
C:\Users\<username>\AppData\Local\TNT2\2.0.0.1976\TNT2User.exe File name: TNT2User.exe
Size: 693.5 KB (693504 bytes)
MD5: 15569b3f607a3a0f7229e5b051f430b7
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\TNT2\2.0.0.1976\TNT2User.exe
Group: Malware file
Last Updated: November 16, 2023
%TEMP%\nsyc016.tmp\2\searchus-tb10295.exe File name: searchus-tb10295.exe
Size: 1.32 MB (1320896 bytes)
MD5: 173291b9f7f1d76406d7565f0e5dc57c
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\nsyc016.tmp\2
Group: Malware file
Last Updated: September 25, 2024

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{02F878DF-E2BE-4B85-8CB4-A0D2D4E2ED7F}{0FEB2313-F89B-4AC6-8153-84025604A06A}{2AF343DD-3102-4F9D-AC95-DCA4C95382C7}{3137BC14-D8D7-4B67-8FFA-2E0B2E9D541B}{4CA2AC92-971B-47B1-ACB6-357B552155AC}{52C5395B-1FCD-47FA-A834-FD830701C2D5}{554EBE31-AEC1-4E34-BCE3-606467760D88}{5D3DCC39-9233-4330-94E9-DA92BE49CA1A}{615FACDF-DADB-440D-AC91-8AAB0AE9E3AD}{655847A1-FA36-46ED-923B-A5CD523696EA}{762D463B-C45A-456D-A80D-8689C297C91E}{7A6BE473-7960-44D0-BD54-D23DA76353DF}{803F550E-BAAE-42BB-8917-64BA0006AB17}{8D5BC51D-C9D3-43B9-B728-B30677B7C7E8}{991C9D8D-A789-4DB9-BDFC-5F33398B04BF}{A5ACC874-D943-483F-A2D1-14598D51F872}{ABB8A8A5-FF98-40F6-B573-5841B063EA37}{B0474212-0D9D-4361-90B3-B89D1A44275D}{BFDE183A-C6FE-41D2-80F9-586C29210AC2}{CE5A6611-5000-43C6-BBF7-014127FE985A}{DD260902-9420-4055-A956-9152EB4F3E6A}{EB1F9F3C-5526-4DAE-BD4B-3EAA7715DA9F}{EBBC143E-44AC-4B9C-BCCE-9A0E42921F2A}{F68DC16C-9C2B-455B-8853-7E4D34BAA3F4}{FBA8498F-B3A0-4942-A2BF-E0CB7BC7E000}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{0922CDBD-C8AD-43B7-AD06-1FAD706914C9}Software\Microsoft\Internet Explorer\Approved Extensions\{0A7103A2-E174-4687-A4A2-781EEAA1000A}Software\Microsoft\Internet Explorer\Approved Extensions\{11EAECED-3676-47E9-A76B-F1150C81DCB1}Software\Microsoft\Internet Explorer\Approved Extensions\{20969DCF-2975-4425-8F58-9292A3F5D3C7}Software\Microsoft\Internet Explorer\Approved Extensions\{2760BEE6-E922-4533-ADD0-5655AD0E9B51}Software\Microsoft\Internet Explorer\Approved Extensions\{2D724534-4C06-4C7B-8855-FC382FF10B4E}Software\Microsoft\Internet Explorer\Approved Extensions\{302891CB-2F47-46D8-8406-FC774074730C}Software\Microsoft\Internet Explorer\Approved Extensions\{320CC2FF-86D7-4D68-AD89-2F2681B14BF0}Software\Microsoft\Internet Explorer\Approved Extensions\{432BC798-4561-4D0A-8B04-AF188AC640D9}Software\Microsoft\Internet Explorer\Approved Extensions\{44FBFC65-6311-40E3-9800-A2D9D6610262}Software\Microsoft\Internet Explorer\Approved Extensions\{52668555-7190-4E6A-97E9-88C1149E60B5}SOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{529C8693-4DFA-4B7F-9116-2F2B38A2B5C2}Software\Microsoft\Internet Explorer\Approved Extensions\{5511D068-2A76-43F8-A2F0-1FE40645002E}Software\Microsoft\Internet Explorer\Approved Extensions\{5A196D79-D3DF-41F4-93CD-488B9543CF2A}Software\Microsoft\Internet Explorer\Approved Extensions\{63B2B812-A562-4380-AF55-AFEFFC1FA2A1}Software\Microsoft\Internet Explorer\Approved Extensions\{6F2F247A-473C-41FF-AF0D-1D0485CD0EC3}Software\Microsoft\Internet Explorer\Approved Extensions\{756EC993-7543-4A3C-8629-84D64D0CC95F}Software\Microsoft\Internet Explorer\Approved Extensions\{79AA1605-B844-4AE3-B3C0-14DC7E61F4B8}Software\Microsoft\Internet Explorer\Approved Extensions\{7F4039FB-5565-4E55-ADDD-CB0C3536D6E0}SOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{895D47DF-47EB-406E-A715-160E87DE1CCB}Software\Microsoft\Internet Explorer\Approved Extensions\{8EC1EB3E-7348-49F8-A6D8-92FAC4CFC478}Software\Microsoft\Internet Explorer\Approved Extensions\{AF62EAA6-D30B-499E-8192-71BC89CC10AC}Software\Microsoft\Internet Explorer\Approved Extensions\{BF6B2F46-72D8-4A0D-B7C1-A9177E752F18}Software\Microsoft\Internet Explorer\Approved Extensions\{C3F82EA0-79C0-46EA-9F89-5A16809558C6}Software\Microsoft\Internet Explorer\Approved Extensions\{C6B99C69-F157-425B-84E7-E634FFEDBD2E}Software\Microsoft\Internet Explorer\Approved Extensions\{D9392729-08A6-4A11-B5A2-E098A9C7084D}Software\Microsoft\Internet Explorer\Approved Extensions\{EDF97228-AF6A-4249-B05F-9DA9F0884F43}Software\Microsoft\Internet Explorer\Approved Extensions\{F2C1F911-8F74-4364-82FB-A9BA17DB0C87}Software\Microsoft\Internet Explorer\Approved Extensions\{F592552D-5E0E-4F1C-ACDA-52B0453EE138}Software\Microsoft\Internet Explorer\DOMStorage\findwide.comSoftware\Microsoft\Internet Explorer\DOMStorage\search.findwide.comSoftware\Microsoft\Internet Explorer\Low Rights\DragDrop\{70BC1CDB-0744-4172-BDA0-B5A487D00C3A}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{72A6AB0F-2FA8-4C73-9FCB-1E62A608F001}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{06A0ADB2-E26C-499F-8BF8-0572E9DAB3B5}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0A7103A2-E174-4687-A4A2-781EEAA1000A}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2760BEE6-E922-4533-ADD0-5655AD0E9B51}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{63B2B812-A562-4380-AF55-AFEFFC1FA2A1}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{6F2F247A-473C-41FF-AF0D-1D0485CD0EC3}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{756EC993-7543-4A3C-8629-84D64D0CC95F}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{79AA1605-B844-4AE3-B3C0-14DC7E61F4B8}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7F4039FB-5565-4E55-ADDD-CB0C3536D6E0}SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{895D47DF-47EB-406E-A715-160E87DE1CCB}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{BF6B2F46-72D8-4A0D-B7C1-A9177E752F18}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{C6B99C69-F157-425B-84E7-E634FFEDBD2E}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D9392729-08A6-4A11-B5A2-E098A9C7084D}Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{EDF97228-AF6A-4249-B05F-9DA9F0884F43}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{06A0ADB2-E26C-499F-8BF8-0572E9DAB3B5}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0922CDBD-C8AD-43B7-AD06-1FAD706914C9}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{11EAECED-3676-47E9-A76B-F1150C81DCB1}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{2760BEE6-E922-4533-ADD0-5655AD0E9B51}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{2D724534-4C06-4C7B-8855-FC382FF10B4E}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{302891CB-2F47-46D8-8406-FC774074730C}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{312290C7-C68C-4E99-A847-59E7738EB72F}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{320CC2FF-86D7-4D68-AD89-2F2681B14BF0}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{432BC798-4561-4D0A-8B04-AF188AC640D9}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{44FBFC65-6311-40E3-9800-A2D9D6610262}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{52668555-7190-4E6A-97E9-88C1149E60B5}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{529C8693-4DFA-4B7F-9116-2F2B38A2B5C2}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{5511D068-2A76-43F8-A2F0-1FE40645002E}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{5A196D79-D3DF-41F4-93CD-488B9543CF2A}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{63B2B812-A562-4380-AF55-AFEFFC1FA2A1}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{64E96A96-5776-48C4-9B5A-B503436D6401}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6F2F247A-473C-41FF-AF0D-1D0485CD0EC3}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{756EC993-7543-4A3C-8629-84D64D0CC95F}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{7F4039FB-5565-4E55-ADDD-CB0C3536D6E0}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{895D47DF-47EB-406E-A715-160E87DE1CCB}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8EC1EB3E-7348-49F8-A6D8-92FAC4CFC478}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{9BA84DA9-4A1D-4A59-A63A-D998F9DA738E}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{AF62EAA6-D30B-499E-8192-71BC89CC10AC}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B6396EF3-294A-45A2-A3F9-23B584AD8042}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{BF6B2F46-72D8-4A0D-B7C1-A9177E752F18}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{C3F82EA0-79C0-46EA-9F89-5A16809558C6}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{C6B99C69-F157-425B-84E7-E634FFEDBD2E}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{D026C6CC-5CF4-4DC7-926F-F076F490C9FE}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{D9392729-08A6-4A11-B5A2-E098A9C7084D}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{EDF97228-AF6A-4249-B05F-9DA9F0884F43}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{F592552D-5E0E-4F1C-ACDA-52B0453EE138}Software\MozillaPlugins\@tnt2ghost.com/PluginSoftware\MozillaPlugins\@tnt2npapi.com/PluginSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\DragDrop\{70BC1CDB-0744-4172-BDA0-B5A487D00C3A}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{72A6AB0F-2FA8-4C73-9FCB-1E62A608F001}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{06A0ADB2-E26C-499F-8BF8-0572E9DAB3B5}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{0922CDBD-C8AD-43B7-AD06-1FAD706914C9}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{0A7103A2-E174-4687-A4A2-781EEAA1000A}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{11EAECED-3676-47E9-A76B-F1150C81DCB1}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{2760BEE6-E922-4533-ADD0-5655AD0E9B51}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{2D724534-4C06-4C7B-8855-FC382FF10B4E}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{302891CB-2F47-46D8-8406-FC774074730C}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{312290C7-C68C-4E99-A847-59E7738EB72F}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{320CC2FF-86D7-4D68-AD89-2F2681B14BF0}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{432BC798-4561-4D0A-8B04-AF188AC640D9}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{44FBFC65-6311-40E3-9800-A2D9D6610262}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{52668555-7190-4E6A-97E9-88C1149E60B5}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{529C8693-4DFA-4B7F-9116-2F2B38A2B5C2}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{5511D068-2A76-43F8-A2F0-1FE40645002E}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{5A196D79-D3DF-41F4-93CD-488B9543CF2A}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{63B2B812-A562-4380-AF55-AFEFFC1FA2A1}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{6F2F247A-473C-41FF-AF0D-1D0485CD0EC3}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{756EC993-7543-4A3C-8629-84D64D0CC95F}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{79AA1605-B844-4AE3-B3C0-14DC7E61F4B8}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{7F4039FB-5565-4E55-ADDD-CB0C3536D6E0}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8386E749-3934-493D-91AF-252929E84847}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{895D47DF-47EB-406E-A715-160E87DE1CCB}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{9BA84DA9-4A1D-4A59-A63A-D998F9DA738E}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{AF62EAA6-D30B-499E-8192-71BC89CC10AC}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{B6396EF3-294A-45A2-A3F9-23B584AD8042}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{BF6B2F46-72D8-4A0D-B7C1-A9177E752F18}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{C3F82EA0-79C0-46EA-9F89-5A16809558C6}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{C6B99C69-F157-425B-84E7-E634FFEDBD2E}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{D026C6CC-5CF4-4DC7-926F-F076F490C9FE}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{D9392729-08A6-4A11-B5A2-E098A9C7084D}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{EDF97228-AF6A-4249-B05F-9DA9F0884F43}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{F592552D-5E0E-4F1C-ACDA-52B0453EE138}SOFTWARE\Wow6432Node\Microsoft\Tracing\TNT2User_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\TNT2User_RASMANCS

Additional Information

The following directories were created:
%LOCALAPPDATA%\TNT2%PROGRAMFILES%\TNT2%UserProfile%\Local Settings\Application Data\TNT2
The following URL's were detected:
FindWide Toolbarfindwide.comsearch.findwide.com

Related Posts

Loading...