Functionality=Redirects IE standard search pages to the AllCyberSearch search page. Same Family as EzCyberSearch and GoCyberSearch (which is also listed as AllCyberSearch). Includes also TinyBar which seems to be the same page.
Privacy=Couldn't find a privacy statement
Description=There is no privavy statement on their website, so nobody knows what they data they collect and what they use it for.
EditDate=20021020
SalisburyID=26
[GoCyberSearch]
Company=Unknown
Product=GoCyberSearch
Threat=Browser hijacker
CompanyURL=http://www.gocybersearch.com/
CompanyProductURL=
CompanyPrivacyURL=
Functionality=
Privacy=Couldn't find a privacy statement
Description=There is no privavy statement on their website, so nobody knows what they data they collect and what they use it for. The list of keywords is unprotected at http://www.gocybersearch.com/searchbar/log-clicks-bar.csv . The same directory also contains some scripts giving statistics to everyone who wants to look at them.
EditDate=20021020
SalisburyID=27
[Cool-XXX]
Company=
Product=Cool-XXX
Threat=Browser hijacker
CompanyURL=http://www.cool-xxx.net/
CompanyProductURL=
CompanyPrivacyURL=
Functionality=
Privacy=
Description=
EditDate=20021020
SalisburyID=28
[Duolaimi]
Company=
Product=
Threat=(Unverified) Browser hijacker
CompanyURL=http://www.duolaimi.net/
CompanyProductURL=
CompanyPrivacyURL=
Functionality=
Privacy=
Description=According to the CEXX forum, resets start page to use duolaimi.net as a forwarder to the real start page, and locks the start page settings. Clicking on a category on duolaimi.net also opens a hidden window doing some very memory-intensive script operations.
Description=Sets IE start page, uses an unidentified ActiveX component to uninstall settings.
EditDate=20021020
SalisburyID=30
[PassThisOn]
Company=
Product=
Threat=Browser hijacker
CompanyURL=http://www.passthison.com/
CompanyProductURL=
CompanyPrivacyURL=http://www.passthison.com/
Functionality=
Privacy=
Description=Asks you continously to set your IE start page. More info at http://news.com.com/2100-1023-253074.html?legacy=cnet
EditDate=20021020
SalisburyID=31
[RocketSearch]
Company=
Product=
Threat=Browser hijacker
CompanyURL=
CompanyProductURL=
CompanyPrivacyURL=
Functionality=
Privacy=
Description=Asks to be set as start page when visiting http://www.netperception.com/ , currently for sale.
EditDate=20021020
SalisburyID=32
[UnderageHost]
Company=
Product=
Threat=Browser hijacker
CompanyURL=
CompanyProductURL=http://www.loading-lolita.com/
CompanyPrivacyURL=
Functionality=
Privacy=
Description=Silently sets itself as IE start- and search pages (furthermore done by a file on every system start), and adds some favourites. Anyone visiting the site that installs it is sick!
EditDate=20021020
SalisburyID=33
[SuperSexPass]
Company=
Product=
Threat=(Unverified) Browser hijacker
CompanyURL=
CompanyProductURL=
CompanyPrivacyURL=
Functionality=
Privacy=
Description=Redirects MSN search for URLs that could not be resolved.
EditDate=20021020
SalisburyID=34
[NetzAny]
Company=
Product=NetzAny
Threat=Browser Hijacker
CompanyURL=http://www.netzany.com/
CompanyProductURL=
CompanyPrivacyURL=
Functionality=
Privacy=
Description=
EditDate=20021020
SalisburyID=35
[FindTheWebsiteYouNeed]
Company=FindTheWebsiteYouNeed
Product=FindTheWebsiteYouNeed
Threat=Browser Hijacker
CompanyURL=http://www.findthewebsiteyouneed.com/
CompanyProductURL=
CompanyPrivacyURL=
Functionality=
Privacy=
Description=Seems to install using some exploit - user doesn't get asked, but on next IE start, start & search pages are set.
Privacy=From the License Agreement:%0D%0A"You are in full agreement that to gather the information necessary to provide our Information service requires our Software to gather URL and duration information of all web sites visits by the person using your computer while browsing the Internet. This information is then transferred to our database in order to provide you and other users with our 7FaSSt Search (tm) traffic reports. You are in full agreement to the transfer of any and all information necessary to provide the 7FaSSt Search(tm) services to others."
Description=Storing the tracked data in a database is bad enough, but what is meant by the last sentence? Transfer of all data to make the search engine services available to /others/?.%0D%0AAfter installation, the user is asked to enter user name and email address as if that would be necessary for use.
EditDate=20021020
SalisburyID=37
[CnsMin]
Threat=Browser hijacker
CompanyURL=http://www.3721.com/
EditDate=20021020
SalisburyID=38
[System1060]
Threat=Browser hijacker
Description=Set of files that do everything to appear as system files. Named taskmgr.exe and twunk_64.exe, both even have the original Microsoft description in their properties, but they don't have the original functionality. Instead, they begin phoning home on system start.
EditDate=20021020
SalisburyID=39
[Xupiter]
Threat=Browser hijacker/BHO
Description=A hijacker that comes with it's own IE toolbar.
CompanyURL=http://www.xupiter.com/
CompanyProductURL=http://www.xupiter.com/
EditDate=20021020
SalisburyID=40
[RapidBlaster]
Threat=BHO
Functionality=Offers porn
Description=Runs in background and connects in short intervals to the internet.
Privacy=For your convenience, Rapid Blaster auto installs new versions of the download to ensure your software is working to its highest capacity.%0D%0ARapid Blaster is not responsible for the privacy policies or the content of websites that are using the Rapid blaster.%0D%0ARapid Blaster reserves the right to modify this Privacy Policy, as well as the other Terms of Use, from time to time, without notice.
SalisburyID=41
[SearchAndBrowse]
Threat=BHO/Hijacker
Company=WebEnhancement Corp.
companyURL=http://www.searchandbrowse.com/
CompanyProductURL=http://www.gtawarehouse.com/
Description=Installs a new toolbar upon leaving page. %0D%0ASee more information here: http://and.doxdesk.com/parasite/SearchAndBrowse.html
Description=The browser start page gets reset to this page if you install Ultimate Popup Killer from their homepage for free. To get rid of it, you have to uninstall Ultimate Popup Killer.
EditDate=20021109
SalisburyID=44
[FreeHQMovies]
EditDate=20021109
CompanyProductURL=http://www.freehqmovies.com/
Description=Pages installs dialer and hijacks IE to itself.
SalisburyID=45
[Jethomepage]
EditDate=20021113
Threat=Hijacker
CompanyURL=http://www.jethomepage.com/
Privacy=No privacy policy
SalisburyID=46
[PlanColumbia]
Threat=Hijacker
EditDate=20021113
Description=Replaces startup and shutdown screen. See additional information here:%0D%0Ahttp://www.symantec.com/avcenter/venc/data/vbs.plan.a.html
SalisburyID=47
[StartSurfing]
EditDate=20021114
Functionality=Popup blocker.
Description=Blocks all internet access. An effective way to block popup, yes. After removal, you need to adjust your IE proxy settings. Should work as a local proxy. Danger because installed directly by found404.com popunder ads.
Privacy=To insure you always have the latest version and for your convenience this software will automatically update itself from time to time once installed. Also we will download other companies programs to your computer which you will have the choice to install or not install once downloaded.%0D%0ATo prevent your browser from becoming cluttered when our toolbar is installed, any other toolbars you currently have visible will be deactivated. They can be restored manually through the Internet Explorer "View" menu.%0D%0AOnce installed if you decide to change your start or search page this information will be sent back to our server. Also information in regards to your browsing will be sent to our servers, such as how long you surf for, and your surfing habits.
SalisburyID=49
[XRenoder]
Threat=Hijacker
EditDate=20021120
Description=Detected as 'Common hijacker', hijacks MSN pages.
SalisburyID=50
[Anal-Oral]
Threat=Hijacker
EditDate=20021120
CompanyProductURL=http://www.anal-oral.net
Description=Hijacks thehun.net and thehun.com pages.
SalisburyID=51
[QcBar]
Threat=Hijacker
EditDate=20021121
Description=Hijacker that adds tons of favorites and its own toolbar to display them.
Privacy=Why we need to obtain personal information ABOUT YOU%0D%0AYour personal information is used to enable us to deliver our online products and services to you.[...]%0D%0AWhat we do with your personal information%0D%0AYour email address and other personal information may be used to enable us to send you marketing or promotional material (such as promotional offers) on other products and services that we consider may be of interest to you.[...] The information you provide to Roar is also shared among our subsidiaries and the operators of our affiliated websites.
Description=Even personal information is collected and shared.
EditDate=20021123
Threat=Hijacker/Spyware
SalisburyID=53
[SearchAccurate]
Threat=BHO/Hijacker
EditDate=20021126
Description=Toolbar for IE with some advertisement links. Resets IE start page on each system start.
SalisburyID=54
[MSN Messenger Polygamy]
Company=Asdfuae
Product=MSN Messenger Polygamy
Threat=Browser hijacker
CompanyURL=http://www.asdfuae.tk/
CompanyProductURL=
CompanyPrivacyURL=
Functionality=IE menu extension
Privacy=
Description=Adds an IE menu extension linking to Asdfuae's Messenger related website
Description=No privacy violation (except keywords are stored in combination with your IP), but installation removes all other installed BHOs. In addition, it hijacks the MS search pages to their own homepage.
Privavy=Our use of your personal or financial information or other information gathered by cookies is used for the limited purpose of fulfilling your requests for service, securing your internet experience, and realizing the demographic which we are serving so that we can continue to serve you better. The information that we collect directly from you includes IP Address, Browser Type, Time Stamps, Operating System, ISP (internet service provider), transactions placed, products and services used, and some banner ads that you may view. All of these are used solely for our internal benefit to create a better operational product and a record of your transaction in case of some failure immediately thereafter.
Description=HotPhrase seems to be a more harmless variant of SpeedPrhase.
SalisburyID=57
[SpeedPhrase]
Company=SpeedPhrase Corporation
CompanyURL=http://www.speedphrase.com/
CompanyProductURL=http://www.speedphrase.com/
Threat=Possible spyware/Malware
Description=Contrary to HotPhrase, the SpeedPhrase homepage contains no privacy policy at all, and installation of SpeedPhrase deletes all other registered Browser Helper Objects!
SalisburyID=58
[I-Lookup]
CompanyURL=http://www.i-lookup.com/
SalisburyID=59
[BandObjects]
ProductName=Bandobjects aka Go aka EStart.
CompanyProductURL=http://topsitez.us
EditDate=20030122
Description=Hijacks Internet Explorer start and search site, deleted Microsoft links from Favorites, and adds its own. That it creates log files in the root may hint that it'sin development and new versions may be coming.
[SearchEx]
Threat=Adware/Trojan
Description=The newest form of this is documented by McAfee: http://vil.mcafee.com/dispVirus.asp?virus_k=100052